Threat reportSupply ChainTL-2026-0251
Keenadu: Firmware-Level Android Supply Chain Backdoor via Zygote Process Injection
Keenadu: Firmware-Level Android Supply Chain Backdoor via (TL-2026-0251), also tracked as Keenadu, is a high-severity supply-chain compromise scored CVSS 7.8, first published 2026-03-19. It is attributed to Hangzhou Denghong Technology Co. (China) with medium confidence, affects Alldocube iPlay 50 mini Pro (T811M), maps to 23 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 50 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1Hangzhou Denghong Technology Co.
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 50Indicators of compromise
Key facts for TL-2026-0251
- Threat ID
- TL-2026-0251
- Also known as
- Keenadu, Andr/Bckdr-SBS, Backdoor.AndroidOS.Keenadu
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Hangzhou Denghong Technology Co.
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- consumer-electronics, enterprise-byod, e-commerce, telecommunications, government, education
- Target regions
- Russia, Japan, Germany, Brazil, Netherlands, North America, Europe, Asia-Pacific, South America
- Detection rules
- 9
- Indicators of compromise
- 50
Malware and tooling in Keenadu: Firmware-Level Android Supply Chain Backdoor via
Malware and tooling: Andr/Bckdr-SBS, HEUR:Backdoor.AndroidOS.Keenadu, Keenadu
How Keenadu: Firmware-Level Android Supply Chain Backdoor via works
Keenadu is a sophisticated firmware-level backdoor embedded in libandroid_runtime.so during the Android device build phase, injecting into the Zygote process to gain total control over every application on the device. Pre-installed on 500+ devices across approximately 50 models from manufacturers including Alldocube, BLU, Ulefone, DOOGEE, and Gigaset, affecting 13,715+ users in 40 countries. Primarily used for ad fraud, search hijacking, and credential theft, with confirmed operational links to the Triada, BADBOX, and Vo1d botnet ecosystems.
Keenadu represents a deeply sophisticated Android supply chain compromise that operates at the firmware level, making it extraordinarily difficult to detect and remove through conventional mobile security tools.
INFECTION MECHANISM: The backdoor is embedded during the firmware build phase through a malicious static library (libVndxUtils.a, MD5: ca98ae7ab25ce144927a46b7fee6bd21) that is linked with libandroid_runtime.so — a critical Android shared library loaded at boot time. The malicious library masquerades as legitimate MediaTek code, targeting MediaTek chipset devices via build paths vendor/mediatek/proprietary/external/libutils/arm/libVndxUtils.a and vendor/mediatek/proprietary/external/libutils/arm64/libVndxUtils.a. In several confirmed cases, the compromised firmware was delivered through digitally signed OTA updates, meaning even users who update their devices may receive the backdoor.
ZYGOTE INJECTION: Once active, the malicious code injects itself into the Zygote process — the parent process for all Android applications. This architectural positioning means a copy of the backdoor is loaded into the address space of every application upon launch. The entry point function __log_check_tag_tag_count hooks the println_native method to execute the malicious payload.
MULTI-STAGE ARCHITECTURE: The backdoor operates as a multi-stage loader. Stage 1 uses RC4 decryption to extract an embedded payload, outputting it to /data/dalvik-cache/arm[64]/system@framework@vndx_10x.jar@classes.jar. Stage 2 uses DexClassLoader to execute the payload via com.ak.test.Main. Stage 3 branches based on process context: in the system_server process, it creates AKServer (a malicious system service with full privilege escalation capabilities); in all other processes, it creates AKClient (a client interface for targeted payload delivery).
PRIVILEGE ESCALATION: The AKServer component can grant arbitrary permissions to apps, revoke any permission, retrieve geolocation data, and exfiltrate device information — all without user interaction. It exposes malicious Binder interfaces (com.action.SystemOptimizeService and com.action.SystemProtectService) for inter-process communication.
PAYLOAD MODULES: Keenadu downloads and deploys multiple second-stage modules targeting specific applications: - Keenadu Loader: Targets Amazon, Shein, and Temu for shopping cart manipulation and fraud - Clicker Loader: Targets YouTube, Facebook, and Digital Wellbeing for ad element interaction - Chrome Module: Monitors the URL bar, intercepts search queries and autocomplete suggestions, redirects to attacker-controlled search engines - Nova (Phantom) Clicker: Uses machine learning-based ad detection and WebRTC for automated ad fraud - Install Monetization: Hijacks the system launcher to track app installations and spoof ad attribution clicks - Google Play Module: Harvests Advertising IDs - BADBOX Variant Loader: Secondary dropper connecting to the BADBOX botnet infrastructure - Credential Stealer: Targets Telegram and Instagram authentication data, with WhatsApp support prepared but unused
EVASION TECHNIQUES: The malware implements multiple evasion mechanisms including a 2.5-month delay before accepting C2 payloads, termination when running in Google services or carrier apps (Sprint, T-Mobile), abortion in Chinese language/timezone environments, and multi-layer encryption using RC4, AES-128-CFB, and XOR with DSA code signing for module authentication.
C2 INFRASTRUCTURE: Command and control communication uses Alibaba Cloud CDN infrastructure, with primary domains keepgo123.com, gsonx.com, and trends.search-hub.cn. The C2 protocol uses encrypted JSON payloads containing download links, MD5 hashes, and target package names, communicating via API endpoints /ak/api/pts/v4 (device registration), /ota/api/tasks/v3 (task retrieval), and /terminal/client/register (BADBOX registration).
DISTRIBUTION VECTORS: Beyond firmware pre-installation, Keenadu spreads through trojanized Google Play apps published by Hangzhou Denghong Technology Co., Ltd. — including Eoolii (com.taismart.global), Ziicam (com.ziicam.aws), and Eyeplus (com.closeli.eyeplus), each with 100,000+ downloads. Third-party app stores including Xiaomi GetApps are also used as distribution channels.
BOTNET ECOSYSTEM LINKS: Kaspersky confirmed operational links between Keenadu and three major Android botnet families. Keenadu and BADBOX share Binder interfaces, with BADBOX capable of downloading Keenadu modules. BADBOX and Triada share C2 domain zcnewy.com and were involved in joint WhatsApp modification attacks. Vo1d and BADBOX overlap was previously identified by HUMAN Security. While no direct Triada-Keenadu connection has been confirmed, the mutual BADBOX links suggest a cooperative threat ecosystem.
ENTERPRISE RISK: The BYOD implications are severe — any employee bringing an affected tablet into a corporate environment introduces a fully compromised device with capabilities for network sniffing, credential theft, and data exfiltration. The firmware-level persistence means factory resets do not remove the threat.
MITRE ATT&CK techniques used in TL-2026-0251
collection
T1005 Data from Local System; T1056 Input Capture
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1542 Pre-OS Boot
exfiltration
T1041 Exfiltration Over C2 Channel
command-and-control
T1071 Application Layer Protocol; T1571 Non-Standard Port; T1573 Encrypted Channel
discovery
T1082 System Information Discovery; T1518 Software Discovery
execution
T1106 Native API; T1129 Shared Modules
initial-access
impact
persistence
T1547 Boot or Logon Autostart Execution
privilege-escalation
T1548 Abuse Elevation Control Mechanism
defense-impairment
T1553 Subvert Trust Controls; T1601 Modify System Image
resource-development
T1584 Compromise Infrastructure
reconnaissance
Affected products and versions in Keenadu: Firmware-Level Android Supply Chain Backdoor via
- Alldocube — iPlay 50 mini Pro (T811M)
Vulnerable versions: Firmware from 2023-08-18 onwards - Alldocube — iPlay 50 mini Pro NFE
Vulnerable versions: Firmware from 2023-11-07 onwards - BLU — Bold K50
Vulnerable versions: All known firmware versions - BLU — G84
Vulnerable versions: All known firmware versions - Ulefone — Armor 22
Vulnerable versions: All known firmware versions - Ulefone — X13
Vulnerable versions: All known firmware versions - Ulefone — Armor 24
Vulnerable versions: All known firmware versions - DOOGEE — Multiple models
Vulnerable versions: Unspecified - Gigaset — Multiple models
Vulnerable versions: Unspecified - Allview — Multiple models
Vulnerable versions: Unspecified
Remediation for Keenadu: Firmware-Level Android Supply Chain Backdoor via
Patches
- Check device manufacturer for clean firmware updates
- Flash verified clean firmware from manufacturer if available
- For Alldocube devices: verify firmware build date and check for non-compromised versions
Immediate actions
- Block C2 domains at perimeter: keepgo123.com, gsonx.com, trends.search-hub.cn, zcnewy.com
- Block C2 IPs at firewall: 67.198.232.4, 67.198.232.187
- Audit all BYOD Android tablets on corporate networks for affected manufacturers
- Restrict affected device models from corporate network access pending firmware verification
- Deploy network monitoring for connections to /ak/api/pts/v4 and /ota/api/tasks/v3 API endpoints
Workarounds
- Disable compromised system apps via ADB: adb shell pm disable --user 0 <package>
- Remove trojanized Google Play apps: Eoolii, Ziicam, Eyeplus
- Consider device replacement if clean firmware is unavailable
- Isolate affected devices on quarantine network segment
Longer-term hardening
- Implement BYOD device allow-listing based on manufacturer and firmware verification
- Deploy mobile threat defense (MTD) solutions with firmware integrity checking
- Require Google Play Protect certification for all BYOD Android devices
- Establish supply chain security requirements for approved Android device vendors
- Monitor for Keenadu-family detection signatures across endpoint fleet
Weaknesses (CWE) in Keenadu: Firmware-Level Android Supply Chain Backdoor via
Timeline of Keenadu: Firmware-Level Android Supply Chain Backdoor via
- Triada and BADBOX botnets conduct joint attacks on WhatsApp modifications, establishing shared infrastructure later linked to Keenadu
- Earliest known Keenadu-infected firmware detected on Alldocube iPlay 50 mini Pro (T811M) tablets
- Alldocube iPlay 50 mini Pro NFE model begins shipping with Keenadu-infected firmware (initially clean versions existed)
- HUMAN Security identifies operational overlaps between BADBOX and Vo1d botnets, part of the broader ecosystem connected to Keenadu
- Kaspersky publishes report on Triada firmware compromise, revealing similar Zygote injection techniques later linked to Keenadu
- Kaspersky publicly discloses the Keenadu backdoor as a multifaceted Android malware that can come preinstalled on new devices
- Kaspersky publishes comprehensive Securelist analysis detailing Keenadu technical architecture, IOCs, and links to Triada/BADBOX/Vo1d botnet ecosystem
- Multiple security vendors (Zimperium, SecurityWeek, BleepingComputer) publish coverage and detection guidance for Keenadu
- Sophos confirms over 500 compromised devices across approximately 50 models from manufacturers including BLU, Ulefone, and DOOGEE in 40 countries
- Sophos publishes expanded report with detection signature Andr/Bckdr-SBS covering additional affected manufacturers and device models
- As of 2026-05-29, Keenadu remains active: Kaspersky/Securelist confirms a live firmware-level Android supply-chain backdoor with operational C2 (keepgo123[.]com, gsonx[.]com) and only partial vendor patching across ~50 budget-tablet models. No CVE (build-time compromise, so KEV is N/A) and no takedown; vendor-dependent OTA fixes leave most of 13,715+ factory-reset-resistant devices exposed.
Sources cited for Keenadu: Firmware-Level Android Supply Chain Backdoor via
- Sophos: Android devices ship with firmware-level malware
- Kaspersky Securelist: Keenadu the tablet conqueror and the links between major Android botnets
- The Hacker News: Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates
- Zimperium: Rapid Response Coverage of Keenadu
- Help Net Security: Firmware-level Android backdoor found on tablets from multiple manufacturers
- CyberInsider: New Keenadu Android backdoor found pre-installed in tablet firmware
- SecurityWeek: New Keenadu Android Malware Found on Thousands of Devices
- BleepingComputer: New Keenadu backdoor found in Android firmware, Google Play apps
- Kaspersky Press Release: Kaspersky discovers Keenadu multifaceted Android malware
- Security Affairs: Keenadu backdoor found preinstalled on Android devices powers ad fraud campaign
- Risky Business: Supply chain attack plants backdoor on Android tablets
- CybersecurityNews: Keenadu Android Backdoor Infects Firmware Spreads via Google Play
Detection coverage for TL-2026-0251
As of 2026-03-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0251 across Splunk SPL, Microsoft KQL and Sigma, covering 50 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.