Drooid Logo
Back to story perspectives

Full Breakdown

Discovery of Keenadu: A Firmware-Level Android Backdoor

2/18/2026, 2:23:57 AM

Overview of the Keenadu Malware

Keenadu is a newly discovered Android backdoor embedded in the firmware of various tablet models, primarily affecting devices from the Chinese manufacturer Alldocube. Kaspersky researchers identified this malware during an investigation into previous Android threats, revealing that it was integrated during the firmware build process rather than through post-purchase infections. The malware has been detected in firmware dating back to August 2023 and has affected over 13,700 users globally, with the highest concentrations of infections reported in Russia, Japan, Germany, Brazil, and the Netherlands.

Mechanism of Infection

The Keenadu malware operates by injecting itself into the Android Zygote process, which is responsible for launching all applications on the device. This allows Keenadu to gain unrestricted access to every app and data on the device, effectively bypassing Android's app sandboxing and permission controls. Once activated, Keenadu can execute a range of malicious activities, including hijacking browser searches, monetizing app installations, and interacting with advertising elements.

Kaspersky's analysis indicates that the malware can also download additional payloads tailored to specific applications, enhancing its capabilities. For instance, it can redirect search queries in Google Chrome and manipulate app behaviors without user consent. The backdoor's architecture includes a server-client model, where the AKServer component operates with maximum privileges, while the AKClient is injected into every app launched.

Supply Chain Compromise

The integration of Keenadu into the firmware suggests a significant supply chain compromise. Kaspersky noted that the malicious code was likely inserted during the firmware build phase, as all affected firmware images carried valid digital signatures. This indicates that the malware was embedded before the devices reached consumers, raising concerns about the integrity of low-cost Android devices. The researchers traced the infection back to Alldocube's firmware, which remained compromised even after the vendor acknowledged malware issues.

Broader Implications and Connections

Keenadu is linked to other major Android malware families, including Triada, BADBOX, and Vo1d. The interconnectedness of these malware platforms suggests a coordinated effort among cybercriminals, sharing infrastructure and code to enhance their operations. Kaspersky's findings highlight the growing sophistication of Android threats, with Keenadu exemplifying how deeply embedded malware can exploit the operating system's architecture.

Official Responses and Recommendations

Kaspersky has notified affected vendors, including Alldocube, which are reportedly working on clean firmware updates. Users are advised to check for official firmware updates and install them promptly. Given the malware's persistence in the system partition, standard removal methods may not suffice, and users should refrain from using infected devices for sensitive activities until confirmed clean.

Conclusion

The discovery of Keenadu underscores the critical need for robust supply chain security in the manufacturing of Android devices. As malware becomes increasingly sophisticated, users must remain vigilant and proactive in safeguarding their devices against potential threats. The situation serves as a reminder that even seemingly innocuous devices can harbor significant security risks, particularly in the budget segment of the market.