logo

‘Keenadu’ Firmware Backdoor Hijacks Android from the Inside Out

ID: 304ce94e-30e4-50d0-a245-21b83781bcbb

STIX ID: report--304ce94e-30e4-50d0-a245-21b83781bcbb

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

Sophos researchers detail Keenadu, a firmware-level Android backdoor embedded in libandroid_runtime.so that infects the Zygote process to persist in every app; it functions as a modular downloader for data-theft and ad-fraud modules targeting shopping and social apps and appears to have been integrated during firmware build, with observed C2 domains including proczone.com, goaimb.com, and aifacecloud.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.