Keenadu is an Android backdoor and multi-stage malware platform associated with supply-chain compromise of device firmware and, in some cases, malicious or trojanized applications. It has been observed embedded during the firmware build process on Android tablets and other low-cost devices, including placement inside core Android components so that its code executes from the Zygote process and is inherited by newly launched apps. This architecture gives operators broad control over the device, enables persistence that can survive normal user remediation, and allows the malware to bypass ordinary Android permission boundaries.
Keenadu has been described as masquerading as legitimate system functionality and hiding inside system applications and libraries. Reported behavior includes delayed activation followed by retrieval of additional modules from remote infrastructure. Observed modules support ad fraud, hidden app deployment, browser and search hijacking, and broader remote-control functionality. High-confidence reporting also indicates data-harvesting potential affecting sensitive user information such as banking data, personal messages, and biometric-related data when embedded in relevant system apps. Some analyses characterize Keenadu as a multi-stage loader in addition to a backdoor because it fetches and executes follow-on payloads after initial compromise.
Distribution has been tied primarily to compromised Android firmware, including preinstalled infections on new devices and tainted over-the-air updates, indicating compromise somewhere in the manufacturing or firmware supply chain. Separate reporting also states that Keenadu-related components have appeared in apps distributed through Google Play and in modified applications from unofficial sources, though the firmware-level supply-chain vector is the defining characteristic. The malware has been linked by researchers to the broader ecosystem of Android firmware threats and botnet activity associated with Triada, BADBOX, Vo1d, and similar preinstalled Android compromises, based on code, infrastructure, or tradecraft similarities. It has been used in ad-fraud monetization campaigns and has also been described as capable of unrestricted remote control of infected Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
plusieurs applications distribuées via Google Play, notamment des applications destinées aux caméras domestiques intelligentes, ont été identifiées comme vecteurs d’infection. Ces applications, téléchargées plus de 300 000 fois, permettaient l’ouverture de navigateurs invisibles au sein même de l’application afin de générer du trafic frauduleux.
“Keenadu” est un backdoor Android sophistiqué qui se distingue par sa capacité à s’implanter à différents niveaux de l’écosystème Android, allant d’applications téléchargées sur Google Play jusqu’à une intégration directe dans le micrologiciel (firmware) de certains appareils via la chaîne d’approvisionnement.
“Android backdoor embedded directly in device firmware… inserted during the firmware build process, not after devices reached users.”
Dans les cas les plus graves, notamment lorsqu’il est préinstallé dans le firmware, le malware peut exécuter des commandes à distance
“Keenadu was integrated directly into critical system utilities, including the facial recognition service, the launcher app… loader was found within various system apps in the firmware…”
“Once active on the device, the malware injected itself into the Zygote process… A copy of the backdoor is loaded into the address space of every app upon launch.”
"The Keenadu variant embedded in system apps is more limited in functionality. However, its elevated privileges allow it to install any app without alerting the user."
“decrypted data… using RC4… payload… loaded via DexClassLoader… C2 server addresses… Base64… gzip… AES-128… Another backdoor… single-byte XOR and executes it…”
Keenadu masquerades as legitimate system components, embedding itself even into facial-recognition unlock apps, potentially granting attackers access to biometrics, banking data, and personal messages.
“Once active on the device, the malware injected itself into the Zygote process… A copy of the backdoor is loaded into the address space of every app upon launch.”
“Upon initialization, it runs an environment check for virtual machine artifacts. If none are detected…”
“To avoid detection, the server waits about 2.5 months after activation before delivering payloads.”
“Keenadu was integrated directly into critical system utilities, including the facial recognition service, the launcher app… loader was found within various system apps in the firmware…”
Les appareils infectés sont exploités comme des bots capables d’ouvrir des pages web invisibles et de générer des clics sur des publicités... Ces applications ... permettaient l’ouverture de navigateurs invisibles au sein même de l’application afin de générer du trafic frauduleux.
le malware peut exécuter des commandes à distance, installer des applications supplémentaires, collecter des données sensibles et surveiller l’activité de l’utilisateur. Les informations exposées peuvent inclure les messages, les fichiers multimédias, les identifiants bancaires, la localisation et d’autres données personnelles.
"establishes a client-server architecture"; "queries C2 servers"; "Domain keepgo123.com, gsonx.com"; "Path /ak/api/pts/v4"
“encrypted data is sent to the C2 server via a POST request to the path /ak/api/pts/v4… /ota/api/tasks/v3… response… encrypted JSON object…”
97 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android backdoor family appearing in Q2 2026 top mobile malware detections.
Android backdoor family listed among the most prevalent mobile malware detections in the quarter.
Android backdoor family listed among the most frequently detected mobile malware in Q2 2026.
Firmware-level Android malware that disguises itself as legitimate system components, including facial-recognition unlock apps, enabling access to biometrics, banking data, and personal messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.