Keenadu Android Malware: A Deep Dive into the Firmware-Level Threat
A new, multifaceted Android malware dubbed Keenadu is raising concerns among cybersecurity experts due to its ability to reach pre-installed on devices, potentially compromising user data from the moment the device is powered on. Discovered by Kaspersky, this malware demonstrates a sophisticated level of persistence and control, extending beyond typical app-based infections.
Keenadu’s Distribution Methods
Keenadu employs several distribution vectors, making it particularly insidious. These include:
- Firmware Integration: Similar to the Triada backdoor discovered in 2025, Keenadu can be embedded directly into the device’s firmware during the manufacturing process. This grants attackers a high level of control, potentially infecting every app installed on the device and allowing for the installation of additional malicious applications with full permissions.
- System App Embedding: Keenadu can also be integrated into pre-installed system applications, turning seemingly safe components into infection vectors.
- Official App Stores: Despite security measures, Keenadu has been found within applications available on official app stores like Google Play, highlighting the ongoing challenge of malware infiltration.
Capabilities and Impact
Initially focused on ad fraud – using infected devices as bots to generate fraudulent ad clicks – Keenadu’s capabilities extend to more malicious activities. As of February 2026, Kaspersky has detected over 13,000 infected devices globally, with a significant concentration in Russia, Japan, Germany, Brazil, and the Netherlands. The malware’s impact includes:
- Complete Device Control: Certain variants of Keenadu function as full backdoors, providing attackers with unrestricted access to the device.
- Data Theft: Attackers can steal sensitive data, including media, messages, banking credentials, and location information.
- Privacy Violation: Keenadu can monitor user activity, even within Chrome’s incognito mode, tracking search queries.
- App Infection & Permission Manipulation: The malware can infect all installed applications and grant them excessive permissions without user consent.
Exploiting System Vulnerabilities
Keenadu demonstrates a degree of intelligence in its operation. It avoids activation on devices using Chinese language dialects or time zones and requires the presence of Google Play Store and Google Play Services to function. Researchers have also identified instances of Keenadu embedded within critical system applications:
- Facial Unlock Systems: Compromising facial unlock systems grants access to sensitive biometric data.
- Home Screen Launchers: Embedding within the home screen launcher provides access to various functions and displayed information.
Recent Discoveries and Affected Devices
Recent investigations have traced Keenadu infections to firmware images for Alldocube iPlay 50 mini Pro tablets, with the malware persisting even in updated firmware releases. A smart home camera app infected with Keenadu was also discovered on the Google Play Store, accumulating over 300,000 downloads before removal. Notably, all analyzed firmware files carrying the malware were digitally signed, suggesting a sophisticated attacker capable of bypassing standard security checks. The Hacker News reported on this issue.
Mitigation and Prevention
Kaspersky recommends the following steps to mitigate the risk of Keenadu infection:
- Utilize Robust Security Solutions: Employ reliable mobile security solutions capable of detecting and neutralizing threats like Keenadu.
- Firmware Updates: Regularly check for and install firmware updates from device manufacturers.
- System App Scrutiny: If infected system applications are suspected, disable or uninstall them if possible.
- Launcher Replacement: If the default launcher is compromised, switch to a trusted third-party launcher.
The Growing Threat of Pre-Installed Malware
The emergence of Keenadu underscores the increasing prevalence of pre-installed malware on Android devices. This poses a significant challenge, as users can be infected from the initial device setup without any direct action on their part. Strengthening security throughout the entire device production chain, from manufacturing to distribution, is crucial to combatting this evolving threat. Kaspersky’s press release details these findings.
Related reading