logo

Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets

ID: eabfabdd-b7a1-513a-bde3-e6a2afe5ab93

STIX ID: report--eabfabdd-b7a1-513a-bde3-e6a2afe5ab93

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2026-02-17

Date Updated: 2026-04-29

Author: Dmitry Kalinin

...
...

This report analyzes Keenadu, a sophisticated firmware-level Android backdoor found embedded in libandroid_runtime.so and various system apps across multiple tablet vendors; the malware hooks into Zygote to inject into every app, implements a binder-based AKServer/AKClient architecture to load signed AES-encrypted modules (clickers, search-hijackers, monetizers, and credential-stealers), employs supply-chain compromise during firmware build for distribution, and is linked operationally to other large botnets such as Triada, BADBOX and Vo1d; the report includes technical behavior, IoCs, distribution vectors, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.