s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.keenadu

📛 Threat Title

Malware family: Keenadu

Category: Keenadu First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.keenadu`. Printable name: Keenadu.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.keenadu VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.keenadu

IOC database

Type
domain
Value
apk.keenadu
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.keenadu

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.keenadu

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    A sophisticated new Android backdoor that infects device firmware at the build stage and spreads through Google Play apps, enabling attackers to seize remote control over victims' tablets and phones.

  • web:imtr.net

    Kaspersky experts have uncovered Keenadu , a sophisticated new backdoor targeting tablet firmware as well as system-level and Google Play apps. They also revealed connections between the world's mos...

  • web:malwaretips.com

    It's here! The full Keenadu research is now live! Keenadu is a firmware-level Android backdoor that injects into Zygote via a malicious libandroid_runtime.so, enabling plug-and-play modules to exfiltrate data, hijack ads, and control devices across multiple botnets including Triada, BADBOX, and Vo1d. This Android malware spreads through 3 vectors: preinstalled on new devices, hidden in system ...

  • web:partner.gurucul.com

    Divide and Conquer: How the New Keenadu Backdoor Exposed Links Between Major Android Botnets outlines the discovery of Keenadu , a firmware-level Android backdoor embedded during the build process via a malicious library linked to libandroid_runtime.so.

  • web:thehackernews.com

    Keenadu firmware backdoor infects Android tablets via signed OTA updates, enabling remote control, ad fraud, and data theft across 13,715 devices.

  • web:www.ainvest.com

    - Keenadu is a firmware-level Android malware embedding in libandroid_runtime.so to hijack Zygote processes, enabling persistent remote control across all apps. - It spreads via preinstalled firmware (e.g., Alldocube tablets) and OTA updates, using valid digital signatures to evade detection while infecting 13,000+ devices globally. - The malware monetizes through ad fraud, hijacking browser ...

  • web:www.bleepingcomputer.com

    A newly discovered and sophisticated Android malware called Keenadu has been found embedded in firmware from multiple device brands, enabling it to compromise all installed applications and gain ...

  • web:www.csoonline.com

    Keenadu infiltrated devices by posing as legitimate system components, prompting calls for tighter controls on firmware integrity across manufacturing and supply‑chain pipelines.

  • web:www.cybersecurity-review.com

    In April 2025, Kaspersky reported on a then-new iteration of the Triada backdoor that had compromised the firmware of counterfeit Android devices sold across major marketplaces. The malware was deployed to the system partitions and hooked into Zygote - the parent process for all Android apps - to infect any app on the device. This allowed the Trojan to exfiltrate credentials from messaging ...

  • web:www.sophos.com

    Based on artifacts associated with Keenadu's deployment, Kaspersky concluded that it was "integrated into the firmware during the build phase" in a supply chain compromise rather than subsequently installed through a compromised OTA (over-the-air) server. The apps the malware targets depends on the modules the attacker chooses to download.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.