Researchers reported Keenadu, a multi-stage Android backdoor implanted during the firmware build process by linking a malicious static library into libandroid_runtime.so, then injecting into the Zygote process so its code is mapped into every app at launch—behavior that mirrors the earlier Triada firmware compromise seen in counterfeit devices. The backdoor has been observed across multiple device brands (including tablets) and in several cases the compromised firmware was delivered via OTA updates, giving operators broad, persistent access at the system level.
Technical analysis indicates Keenadu modifies runtime behavior to decrypt and execute additional components, loading payloads dynamically (e.g., via DexClassLoader) and using a client/server-style architecture on-device to enable remote control and data access. Intercepted modules were tailored to the victim’s installed apps and included capabilities such as browser search hijacking, install/monetization fraud, and stealthy interaction with advertising elements; reporting also notes distribution pathways involving apps on Google Play and links between at least one Keenadu payload and code found embedded in numerous standalone apps, suggesting a broader ecosystem of related Android botnet activity.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Kaspersky said telemetry showed 13,715 users had encountered Keenadu or its modules, with the highest counts in Russia, Japan, Germany, Brazil, and the Netherlands. The company also stated it notified affected vendors and advised users to install clean firmware or avoid using infected devices until remediation was available.
Investigators reported technical and operational overlaps between Keenadu and major Android botnets including Triada, BADBOX, and Vo1d, with evidence that BADBOX could deploy a Keenadu loader variant. Kaspersky did not publicly attribute the activity to a specific threat actor.
Technical analysis showed Keenadu operates through an AKClient/AKServer architecture that can load arbitrary DEX payloads into targeted apps. Observed modules performed ad-click fraud, Chrome search hijacking, install attribution abuse, shopping-app manipulation, and collection of device identifiers and search queries.
Kaspersky found additional Keenadu variants hidden in system apps, modified apps from unofficial sources, third-party stores such as Xiaomi GetApps, and some apps distributed through Google Play. These app-borne variants extended distribution beyond preloaded firmware infections.
Researchers confirmed Keenadu in publicly available, digitally signed firmware images for Alldocube tablets, including iPlay 50 mini Pro variants. The backdoor was present across all checked firmware versions, and some infections were also delivered through OTA updates.
Kaspersky determined that the Keenadu backdoor was inserted during Android firmware compilation by linking a malicious static library into libandroid_runtime.so, indicating a supply-chain compromise rather than post-release tampering. The malware was designed to inject into the Zygote process so its code would load into every app on infected devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 109 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourcehelpnetsecurity.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.