logo

Keenadu: The Firmware Backdoor That Ships Inside the Box

ID: 0bf5eb13-9661-503d-b322-b39f8b5c8151

STIX ID: report--0bf5eb13-9661-503d-b322-b39f8b5c8151

Feed Name: NoHackie

Threat Score
92/100

Date Published: 2026-02-18

Date Updated: 2026-04-19

...
...

Kaspersky disclosed Keenadu, a firmware-level Android backdoor preinstalled at the firmware build stage that injects into Zygote to compromise every app on affected tablets, persists on the read-only system partition (requiring a full firmware reflash to remove), uses a dormancy period before retrieving modular payloads from cloud CDNs for ad fraud and silent APK installs, and shares infrastructure and code ties with major botnets (BADBOX, Triada, Vo1d), indicating a large-scale supply chain threat ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.