<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

New Android Malware Infects 13,000 Devices Through Supply Chain Attack

Kaspersky finds "Keenadu" malware in Android firmware, affecting 13,000 devices worldwide and linked to major botnets.
Content Team

Kaspersky discovered "Keenadu" malware embedded in Android device firmware from multiple small manufacturers, affecting 13,000 devices globally as of February. The malware infiltrates every app on infected devices through Android's core Zygote process, giving attackers complete remote access.

The supply chain attack occurred when compromised firmware reached devices either pre-installed or through legitimate security updates. Russia has the most affected users, followed by Japan, Germany, Brazil, and the Netherlands.

Currently used for ad fraud, Keenadu can hijack browser searches, monitor Chrome queries, and manipulate shopping carts on Amazon, Shein, and Temu. Worryingly, researchers found connections between Keenadu and three major Android botnets: BADBOX, Triada, and Vo1d.

For firmware-level infections, complete firmware replacement is the only solution. Users should stop using infected devices until fixed.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo