Sophos Keenadu Backdoor Infects Android Devices via Firmware Compromise
Article Content
- •Keenadu backdoor infects Android devices via firmware-level compromise.
- •Over 500 unique devices affected globally, primarily low-cost models.
- •Malware targets popular apps for ad fraud and data exfiltration.
In late February 2026, SophosLabs identified the Keenadu backdoor affecting Android devices, which is embedded in the libandroid_runtime.so library. This firmware-level malware injects itself into the Zygote process, allowing attackers total control over infected devices. Keenadu functions as a downloader for additional malware modules targeting various applications, including popular storefronts like Shein and Amazon, and ad fraud modules targeting YouTube. The malware is integrated into the firmware during the build phase, indicating a supply chain compromise rather than installation via OTA updates. As of March 4, over 500 unique compromised devices across nearly 50 models have been detected, primarily low-cost devices from manufacturers like Allview and DOOGEE. The infections span 40 countries, raising concerns for organizations allowing personal device access to corporate resources. The malware's persistence is facilitated by trojanized system-level APK files, which are not blocked by standard security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Keenadu and Amazon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…