Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets
ID: eabfabdd-b7a1-513a-bde3-e6a2afe5ab93
STIX ID: report--eabfabdd-b7a1-513a-bde3-e6a2afe5ab93
Feed Name: Securelist by Kaspersky
This report analyzes Keenadu, a sophisticated firmware-level Android backdoor found embedded in libandroid_runtime.so and various system apps across multiple tablet vendors; the malware hooks into Zygote to inject into every app, implements a binder-based AKServer/AKClient architecture to load signed AES-encrypted modules (clickers, search-hijackers, monetizers, and credential-stealers), employs supply-chain compromise during firmware build for distribution, and is linked operationally to other large botnets such as Triada, BADBOX and Vo1d; the report includes technical behavior, IoCs, distribution vectors, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
