TF-MAL-apk.keenadu
📛 Threat Title
Malware family: Keenadu
Description
ThreatFox malware family `apk.keenadu`. Printable name: Keenadu.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.keenadu
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.keenadu
IOC database
- Type
- domain
- Value
apk.keenadu- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.keenadu
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.keenadu
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
A sophisticated new Android backdoor that infects device firmware at the build stage and spreads through Google Play apps, enabling attackers to seize remote control over victims' tablets and phones.
-
web:imtr.net
Kaspersky experts have uncovered Keenadu , a sophisticated new backdoor targeting tablet firmware as well as system-level and Google Play apps. They also revealed connections between the world's mos...
-
web:malwaretips.com
It's here! The full Keenadu research is now live! Keenadu is a firmware-level Android backdoor that injects into Zygote via a malicious libandroid_runtime.so, enabling plug-and-play modules to exfiltrate data, hijack ads, and control devices across multiple botnets including Triada, BADBOX, and Vo1d. This Android malware spreads through 3 vectors: preinstalled on new devices, hidden in system ...
-
web:partner.gurucul.com
Divide and Conquer: How the New Keenadu Backdoor Exposed Links Between Major Android Botnets outlines the discovery of Keenadu , a firmware-level Android backdoor embedded during the build process via a malicious library linked to libandroid_runtime.so.
-
web:thehackernews.com
Keenadu firmware backdoor infects Android tablets via signed OTA updates, enabling remote control, ad fraud, and data theft across 13,715 devices.
-
web:www.ainvest.com
- Keenadu is a firmware-level Android malware embedding in libandroid_runtime.so to hijack Zygote processes, enabling persistent remote control across all apps. - It spreads via preinstalled firmware (e.g., Alldocube tablets) and OTA updates, using valid digital signatures to evade detection while infecting 13,000+ devices globally. - The malware monetizes through ad fraud, hijacking browser ...
-
web:www.bleepingcomputer.com
A newly discovered and sophisticated Android malware called Keenadu has been found embedded in firmware from multiple device brands, enabling it to compromise all installed applications and gain ...
-
web:www.csoonline.com
Keenadu infiltrated devices by posing as legitimate system components, prompting calls for tighter controls on firmware integrity across manufacturing and supply‑chain pipelines.
-
web:www.cybersecurity-review.com
In April 2025, Kaspersky reported on a then-new iteration of the Triada backdoor that had compromised the firmware of counterfeit Android devices sold across major marketplaces. The malware was deployed to the system partitions and hooked into Zygote - the parent process for all Android apps - to infect any app on the device. This allowed the Trojan to exfiltrate credentials from messaging ...
-
web:www.sophos.com
Based on artifacts associated with Keenadu's deployment, Kaspersky concluded that it was "integrated into the firmware during the build phase" in a supply chain compromise rather than subsequently installed through a compromised OTA (over-the-air) server. The apps the malware targets depends on the modules the attacker chooses to download.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.