Counterfeit Phones Carrying Hidden Revamped Triada Malware
ID: 1a1dedf5-1b56-53c5-b031-b45ce8120e01
STIX ID: report--1a1dedf5-1b56-53c5-b031-b45ce8120e01
Feed Name: Dark Reading
Date Published: 2025-04-03
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
NEWS BRIEF: Counterfeit Android smartphones have been found with a modified Triada remote-access Trojan embedded in device firmware and system frameworks, resulting in persistent, hard-to-detect infections. Researchers at Kaspersky and Darktrace report the malware targets banking and messaging apps, steals cryptocurrency and accounts, can send messages on behalf of victims, and exfiltrates data to command-and-control servers using algorithmically generated hostnames; over 2,600 users (mostly in Russia) have been affected and a supply-chain compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
