# Keenadu: Firmware-Level Android Supply Chain Backdoor via Zygote Process Injection

> Keenadu is a sophisticated firmware-level backdoor embedded in libandroid_runtime.so during the Android device build phase, injecting into the Zygote process to gain total control over every application on the device. Pre-installed on 500+ devices across approximately 50 models from manufacturers including Alldocube, BLU, Ulefone, DOOGEE, and Gigaset, affecting 13,715+ users in 40 countries. Primarily used for ad fraud, search hijacking, and credential theft, with confirmed operational links to the Triada, BADBOX, and Vo1d botnet ecosystems.

- **Published:** 2026-03-19T12:00:00Z
- **Last reviewed:** 2026-03-19T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0251
- **ID:** TL-2026-0251
- **Severity:** HIGH (CVSS 7.8)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Actor:** Hangzhou Denghong Technology Co. (China)
- **Detections:** 9 · **IOCs:** 50 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Keenadu represents a deeply sophisticated Android supply chain compromise that operates at the firmware level, making it extraordinarily difficult to detect and remove through conventional mobile security tools.

INFECTION MECHANISM: The backdoor is embedded during the firmware build phase through a malicious static library (libVndxUtils.a, MD5: ca98ae7ab25ce144927a46b7fee6bd21) that is linked with libandroid_runtime.so — a critical Android shared library loaded at boot time. The malicious library masquerades as legitimate MediaTek code, targeting MediaTek chipset devices via build paths vendor/mediatek/proprietary/external/libutils/arm/libVndxUtils.a and vendor/mediatek/proprietary/external/libutils/arm64/libVndxUtils.a. In several confirmed cases, the compromised firmware was delivered through digitally signed OTA updates, meaning even users who update their devices may receive the backdoor.

ZYGOTE INJECTION: Once active, the malicious code injects itself into the Zygote process — the parent process for all Android applications. This architectural positioning means a copy of the backdoor is loaded into the address space of every application upon launch. The entry point function __log_check_tag_tag_count hooks the println_native method to execute the malicious payload.

MULTI-STAGE ARCHITECTURE: The backdoor operates as a multi-stage loader. Stage 1 uses RC4 decryption to extract an embedded payload, outputting it to /data/dalvik-cache/arm[64]/system@framework@vndx_10x.jar@classes.jar. Stage 2 uses DexClassLoader to execute the payload via com.ak.test.Main. Stage 3 branches based on process context: in the system_server process, it creates AKServer (a malicious system service with full privilege escalation capabilities); in all other processes, it creates AKClient (a client interface for targeted payload delivery).

PRIVILEGE ESCALATION: The AKServer component can grant arbitrary permissions to apps, revoke any permission, retrieve geolocation data, and exfiltrate device information — all without user interaction. It exposes malicious Binder interfaces (com.action.SystemOptimizeService and com.action.SystemProtectService) for inter-process communication.

PAYLOAD MODULES: Keenadu downloads and deploys multiple second-stage modules targeting specific applications:
- Keenadu Loader: Targets Amazon, Shein, and Temu for shopping cart manipulation and fraud
- Clicker Loader: Targets YouTube, Facebook, and Digital Wellbeing for ad element interaction
- Chrome Module: Monitors the URL bar, intercepts search queries and autocomplete suggestions, redirects to attacker-controlled search engines
- Nova (Phantom) Clicker: Uses machine learning-based ad detection and WebRTC for automated ad fraud
- Install Monetization: Hijacks the system launcher to track app installations and spoof ad attribution clicks
- Google Play Module: Harvests Advertising IDs
- BADBOX Variant Loader: Secondary dropper connecting to the BADBOX botnet infrastructure
- Credential Stealer: Targets Telegram and Instagram authentication data, with WhatsApp support prepared but unused

EVASION TECHNIQUES: The malware implements multiple evasion mechanisms including a 2.5-month delay before accepting C2 payloads, termination when running in Google services or carrier apps (Sprint, T-Mobile), abortion in Chinese language/timezone environments, and multi-layer encryption using RC4, AES-128-CFB, and XOR with DSA code signing for module authentication.

C2 INFRASTRUCTURE: Command and control communication uses Alibaba Cloud CDN infrastructure, with primary domains keepgo123.com, gsonx.com, and trends.search-hub.cn. The C2 protocol uses encrypted JSON payloads containing download links, MD5 hashes, and target package names, communicating via API endpoints /ak/api/pts/v4 (device registration), /ota/api/tasks/v3 (task retrieval), and /terminal/client/register (BADBOX registration).

DISTRIBUTION VECTORS: Beyond firmware pre-installation, Keenadu spreads through trojanized Google Play apps published by Hangzhou Denghong Technology Co., Ltd. — including Eoolii (com.taismart.global), Ziicam (com.ziicam.aws), and Eyeplus (com.closeli.eyeplus), each with 100,000+ downloads. Third-party app stores including Xiaomi GetApps are also used as distribution channels.

BOTNET ECOSYSTEM LINKS: Kaspersky confirmed operational links between Keenadu and three major Android botnet families. Keenadu and BADBOX share Binder interfaces, with BADBOX capable of downloading Keenadu modules. BADBOX and Triada share C2 domain zcnewy.com and were involved in joint WhatsApp modification attacks. Vo1d and BADBOX overlap was previously identified by HUMAN Security. While no direct Triada-Keenadu connection has been confirmed, the mutual BADBOX links suggest a cooperative threat ecosystem.

ENTERPRISE RISK: The BYOD implications are severe — any employee bringing an affected tablet into a corporate environment introduces a fully compromised device with capabilities for network sniffing, credential theft, and data exfiltration. The firmware-level persistence means factory resets do not remove the threat.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1106 Native API
- T1129 Shared Modules
- T1547 Boot or Logon Autostart Execution
- T1542 Pre-OS Boot
- T1055 Process Injection
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1601 Modify System Image
- T1553 Subvert Trust Controls
- T1056 Input Capture
- T1518 Software Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1571 Non-Standard Port
- T1041 Exfiltration Over C2 Channel
- T1496 Resource Hijacking
- T1592 Gather Victim Host Information
- T1584 Compromise Infrastructure

## Sources

- [Sophos: Android devices ship with firmware-level malware](https://www.sophos.com/en-us/blog/android-devices-ship-with-firmware-level-malware)
- [Kaspersky Securelist: Keenadu the tablet conqueror and the links between major Android botnets](https://securelist.com/keenadu-android-backdoor/118913/)
- [The Hacker News: Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates](https://thehackernews.com/2026/02/keenadu-firmware-backdoor-infects.html)
- [Zimperium: Rapid Response Coverage of Keenadu](https://zimperium.com/blog/rapid-response-keenadu-a-firmware-level-android-backdoor-that-escapes-traditional-defenses)
- [Help Net Security: Firmware-level Android backdoor found on tablets from multiple manufacturers](https://www.helpnetsecurity.com/2026/02/17/firmware-level-android-backdoor-keenadu-tablets/)
- [CyberInsider: New Keenadu Android backdoor found pre-installed in tablet firmware](https://cyberinsider.com/new-keenadu-android-backdoor-found-pre-installed-in-tablet-firmware/)
- [SecurityWeek: New Keenadu Android Malware Found on Thousands of Devices](https://www.securityweek.com/new-keenadu-android-malware-found-on-thousands-of-devices/)
- [BleepingComputer: New Keenadu backdoor found in Android firmware, Google Play apps](https://www.bleepingcomputer.com/news/security/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/)
- [Kaspersky Press Release: Kaspersky discovers Keenadu multifaceted Android malware](https://www.kaspersky.com/about/press-releases/kaspersky-discovers-keenadu-a-multifaceted-android-malware-that-can-come-preinstalled-on-new-devices)
- [Security Affairs: Keenadu backdoor found preinstalled on Android devices powers ad fraud campaign](https://securityaffairs.com/188147/malware/keenadu-backdoor-found-preinstalled-on-android-devices-powers-ad-fraud-campaign.html)
- [Risky Business: Supply chain attack plants backdoor on Android tablets](https://news.risky.biz/risky-bulletin-supply-chain-attack-plants-backdoor-on-android-tablets/)
- [CybersecurityNews: Keenadu Android Backdoor Infects Firmware Spreads via Google Play](https://cybersecuritynews.com/keenadu-android-malware/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0251
