Security researchers have uncovered a new Android backdoor called Keenadu that embeds itself deeply into mobile devices. Unlike typical malicious applications, it can hide inside firmware and trusted software components, giving attackers long-term control over infected phones.

The malware does not rely on a single delivery method. Investigators observed infections arriving through compromised firmware updates, modified system apps, third-party programs, and even applications distributed through official stores.

System-level control

The most dangerous variant installs directly within the operating system. At this level, the malware operates with elevated privileges and can interact with all installed applications.

Researchers say Keenadu can:

  • install apps without user interaction
  • automatically grant permissions
  • collect messages, files, and media
  • capture banking information
  • track location and browsing activity

It can also monitor searches performed in private browsing sessions. Because it integrates into core system components, traditional antivirus tools cannot remove it. The only reliable fix is reinstalling clean firmware or replacing the device.

Multiple distribution channels

Investigators identified several infection paths. Some devices received the backdoor through tampered over-the-air updates, while others contained it in preinstalled features such as biometric or system utility apps.

Researchers also found seemingly harmless programs that acted as loaders. These apps silently opened hidden pages in the background and downloaded additional malicious components before being removed from official marketplaces.

Google reports that Play Protect detects and blocks known variants, though compromised firmware remains harder to address.

Activity and impact

More than ten thousand devices have been confirmed infected across multiple regions. Current activity focuses mainly on advertising fraud, but the malware’s capabilities allow broader surveillance and data theft.

The behavior resembles supply-chain attacks where devices are altered before reaching users. This makes detection difficult because the compromise may exist from the first time the phone powers on.

Conclusion

Keenadu shows how mobile threats are shifting toward persistent system-level compromise. By embedding inside firmware and trusted software, attackers gain continuous access that standard security tools cannot easily remove. The discovery underscores the importance of trusted device sources and verified system updates when managing mobile security.


0 responses to “Keenadu Android backdoor hides in firmware and apps”