Keenadu is an Android backdoor and multi-stage loader associated with supply-chain compromise of device firmware and, in some cases, trojanized applications. It has been observed preinstalled on tablets and other Android devices before sale, embedded during the firmware build process, delivered through over-the-air updates, and also propagated through modified apps, including apps distributed via official stores. The malware has been linked by researchers to the broader Android preinstallation and botnet ecosystem surrounding Triada, BADBOX, and Vo1d, with code and infrastructure similarities suggesting a shared or closely related operational cluster.
Technically, Keenadu achieves deep persistence by embedding into core Android components and injecting through the Zygote process, causing malicious code to load into every app started on the device. This placement allows it to survive normal user remediation and, in firmware-level cases, can require full reflashing of the device to remove. Keenadu masquerades as legitimate system functionality and has been found hidden in system components such as launcher and facial-recognition-related apps. Its architecture supports staged payload delivery, delayed activation, encrypted communications, and modular plugin loading.
Observed payloads and modules support remote device control, ad-fraud monetization, stealth installation of additional applications, browser and search hijacking, monitoring of browser activity, shopping-cart manipulation, and broader malicious payload delivery. Researchers have also assessed that its privileged position can expose sensitive user data, including personal messages, banking-related information, and biometric data. Keenadu is currently most strongly associated with ad-fraud and post-compromise device control rather than a single-purpose theft operation, but its access level makes it a high-risk platform for further abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
plusieurs applications distribuées via Google Play, notamment des applications destinées aux caméras domestiques intelligentes, ont été identifiées comme vecteurs d’infection. Ces applications, téléchargées plus de 300 000 fois, permettaient l’ouverture de navigateurs invisibles au sein même de l’application afin de générer du trafic frauduleux.
“Keenadu” est un backdoor Android sophistiqué qui se distingue par sa capacité à s’implanter à différents niveaux de l’écosystème Android, allant d’applications téléchargées sur Google Play jusqu’à une intégration directe dans le micrologiciel (firmware) de certains appareils via la chaîne d’approvisionnement.
“Android backdoor embedded directly in device firmware… inserted during the firmware build process, not after devices reached users.”
Dans les cas les plus graves, notamment lorsqu’il est préinstallé dans le firmware, le malware peut exécuter des commandes à distance
“Keenadu was integrated directly into critical system utilities, including the facial recognition service, the launcher app… loader was found within various system apps in the firmware…”
“Once active on the device, the malware injected itself into the Zygote process… A copy of the backdoor is loaded into the address space of every app upon launch.”
"The Keenadu variant embedded in system apps is more limited in functionality. However, its elevated privileges allow it to install any app without alerting the user."
“decrypted data… using RC4… payload… loaded via DexClassLoader… C2 server addresses… Base64… gzip… AES-128… Another backdoor… single-byte XOR and executes it…”
Keenadu masquerades as legitimate system components, embedding itself even into facial-recognition unlock apps, potentially granting attackers access to biometrics, banking data, and personal messages.
“Once active on the device, the malware injected itself into the Zygote process… A copy of the backdoor is loaded into the address space of every app upon launch.”
“Upon initialization, it runs an environment check for virtual machine artifacts. If none are detected…”
“To avoid detection, the server waits about 2.5 months after activation before delivering payloads.”
“Keenadu was integrated directly into critical system utilities, including the facial recognition service, the launcher app… loader was found within various system apps in the firmware…”
Les appareils infectés sont exploités comme des bots capables d’ouvrir des pages web invisibles et de générer des clics sur des publicités... Ces applications ... permettaient l’ouverture de navigateurs invisibles au sein même de l’application afin de générer du trafic frauduleux.
le malware peut exécuter des commandes à distance, installer des applications supplémentaires, collecter des données sensibles et surveiller l’activité de l’utilisateur. Les informations exposées peuvent inclure les messages, les fichiers multimédias, les identifiants bancaires, la localisation et d’autres données personnelles.
"establishes a client-server architecture"; "queries C2 servers"; "Domain keepgo123.com, gsonx.com"; "Path /ak/api/pts/v4"
“encrypted data is sent to the C2 server via a POST request to the path /ak/api/pts/v4… /ota/api/tasks/v3… response… encrypted JSON object…”
97 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android backdoor family appearing in Q2 2026 top mobile malware detections.
Android backdoor family listed among the most prevalent mobile malware detections in the quarter.
Android backdoor family listed among the most frequently detected mobile malware in Q2 2026.
Firmware-level Android malware that disguises itself as legitimate system components, including facial-recognition unlock apps, enabling access to biometrics, banking data, and personal messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.