The tablet conqueror and the links between major Android botnets
A new Android backdoor called Keenadu has been discovered embedded in the firmware of several tablet brands. It infects the libandroid_runtime.so library during firmware building, injecting itself into every app launched on the device. Keenadu provides attackers unrestricted control over victims' devices, primarily for ad fraud purposes. The investigation revealed connections between Keenadu and other major Android botnets like Triada, BADBOX, and Vo1d. The malware was found in system apps, Google Play apps, and modified versions of popular apps. Over 13,000 users worldwide have been affected, with Russia, Japan, Germany, Brazil and the Netherlands seeing the highest number of infections.
Pulse ID: 6994616c344268c9e9708b53
Pulse Link: https://otx.alienvault.com/pulse/6994616c344268c9e9708b53
Pulse Author: AlienVault
Created: 2026-02-17 12:39:08
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #BADBOX #BackDoor #Brazil #CyberSecurity #ELF #Germany #Google #GooglePlay #InfoSec #Japan #Malware #OTX #OpenThreatExchange #Russia #TheNetherlands #bot #botnet #AlienVault



