Supply Chain Attack Embeds Malware in Android Devices
ID: b2594763-8b4c-5d27-8a8a-38bcf396b896
STIX ID: report--b2594763-8b4c-5d27-8a8a-38bcf396b896
Feed Name: Dark Reading
Kaspersky researchers have identified Keenadu, a firmware-level Android backdoor delivered via a supply-chain compromise or preloaded system apps/OTA updates that hooks into Android's Zygote process to inject malicious code into every application; operators currently use it for large-scale ad fraud (modules for shopping hijack, click fraud, Chrome query monitoring) across ~13,000 devices in multiple countries, but it can enable full remote control, and investigators found operational links to major Android botnets (BADBOX, Triada, Vo1d).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
