They warn about Keenadu, the ‘malware’ preinstalled on some new Android devices for advertising fraud

Cybersecurity experts have warned about Bring ita new ‘malware’ identified on Android devices, Spain being one of the countries with the highest number of detections, which can come pre-installed directly in the ‘firmware’ of the device, be integrated into system applications or downloaded from official stores such as Google Play.

Malicious actors use this ‘malware’ to carry out advertising fraud, using infected devices as bots that generate ad clicks. However, it can also be used for more harmful purposes, as in some variants it has been identified as allowing full control of the victim’s device.

This has been announced by the cybersecurity company Kaspersky, which, through its mobile security solutions, has detected more than 13,000 infected devices with Keenadu globally, until February 2026.

Specifically, the largest number of affected users was registered in Russia, Japan, Germany, Brazil and the Netherlands. Nevertheless, Spain is also among the ten countries with the highest number of detections of this threat, together with Türkiye, the United Kingdom, France and Italy.

As the experts explained in a statement, like the Triada Trojan, which was detected in 2025 on more than 2,600 counterfeit Android smartphones, this Keenadu malware has been integrated into the ‘filmware’ of certain Android tablet models in “some phase of the supply chain.

This identified variant acts as a acceso ‘backdoor’ for cybercriminals, allowing them to gain unlimited control over the device in question. As a result, Keenadu can infect any application that is installed on the device, as well as install new ‘apps’ from APK files and control the settings to grant them all permissions.

All this means that the Device information may be compromisedincluding multimedia files, messages, banking credentials or location data, as Kaspersky has warned. So much so, that even cybercriminals can monitor the searches that the user enters in the Chrome browser in incognito mode.

Likewise, it must be taken into account that, when the ‘malware’ is integrated into the ‘firmware’ it can behave differently depending on various factors. For example, the company has assured that it will not be activated if the language configured on the device corresponds to Chinese dialects or if the time zone is set to China. It will also not run if the device does not have Google Play Store or Google Play Services installed.

INTEGRATED INTO ‘APPS’ OF THE SYSTEM OR DISTRIBUTED IN OFFICIAL ‘APPS’

However, experts have specified that the threat is also distributed integrating into system applications o downloading from official stores like Google Play.

In the in-app variant of the system, Keenadu is more limited, as cannot infect all applications on the device. However, it does have some elevated privileges, for example it can be used to install other applications without the user knowing.

In one of the cases analyzed, the experts detected Keenadu integrated into an application of the system responsible for the device face unlockwhich could allow cybercriminals to access user biometric data. In other cases, the malware was integrated into the system home screen app.

For its part, for the version distributed through applications in the store oficial Google Play, infected with Keenadu, cybercriminals have targeted smart home camera apps that had been downloaded more than 300,000 times. Although, currently, They have already been removed.

Thus, when users run these applications, cybercriminals can open invisible browser tabs within the application itself, visiting web pages in a hidden way. Some of these applications were Ziicam, Eyeplus-Your home in your eyes or Eoolii.

With all this, the identification of Keenadu highlights how pre-installed ‘malwares’ continue to be a major issue on multiple android devices since, “without the user taking any action” the device can be committed “from the first moment”, as detailed by Kaspersky security researcher, Dmitry Kalinin.

“It is likely that the manufacturers were unaware of the supply chain manipulation that allowed Keenadu to infiltrate the devices, as the malware imitated legitimate system components“, he concluded, while emphasizing that it is “essential to review all phases of the production process to ensure that the firmware is not infected.”

It has also recommended that users use a reliable security solution on mobile devices, check if there are updates available and, after installing them, scan the computer with a security solution to examine the ‘firmware’. In case a system application is infected, it is recommended to stop using it and disable it.

By Editor

One thought on “They warn about Keenadu, the ‘malware’ preinstalled on some new Android devices for advertising fraud”
  1. https://zenspotting.com/spinmacho-casino-combina-ritmo-visual-y-sonido-envolvente/
    https://www.getsoil.com/news-2/jugar-con-cabeza-la-psicologia-detras-del-entretenimiento/
    https://halalstreet.co.uk/digitale-trends-verandern-die-dynamik-des-glucksspiels/
    https://francteh.hr/uncategorized/verantwortungsbewusst-spielen-fokus-und-balance-online/
    https://elescondite.pe/digitale-entwicklungen-formen-neue-spielkonzepte-online/
    https://ccomsa.com.mx/design-trifft-klang-bet-on-red-casino-setzt-akzente/
    https://www.roktools.ca/bewusst-spielen-die-psychologische-seite-des-glucks/
    https://finepriser.dk/felixspin-klare-marke-mit-moderner-seele/
    https://coloradosfinestagency.com/emotionen-verstehen-hilft-beim-verantwortungsvollen-spielen/
    https://www.sarda-revisioni.it/2026/02/16/felixspin-entfesselt-spannung-im-live-casino-moment/
    https://zomagazine.com/im-cocoa-casino-wird-live-gaming-zur-echten-begegnung/
    https://normapro.es/markenidentitat-mit-herz-cocoa-casino-setzt-akzente/
    https://dissolvingillusions.com/2026/02/16/uberall-spielen-mit-stil-mobiles-casino-erlebnis-pur/
    https://sdarrstudios.com/tendencias-tecnologicas-alimentan-la-evolucion-del-casino/
    https://www.albertamusic.org/2026/02/nine-casino-desliza-arte-sonoro-y-visual-en-cada-partida/
    https://emmerced.ai/cada-sesion-live-bulle-con-energia-dentro-de-nine-casino/
    https://brandstardigital.com/el-pulso-del-directo-se-enciende-dentro-de-nine-casino/
    https://www.uilscuolamodena.it/el-juego-movil-da-ritmo-a-la-nueva-era-del-casino/
    https://hippiehome.se/diversion-movil-sin-limites-juega-en-linea-donde-quieras/
    https://www.forzazzurri.net/vive-la-emocion-en-directo-con-nine-casino-y-sus-crupieres-reales/
    https://clinicarangelpereira.com/2026/02/16/la-experiencia-nine-casino-mas-real-llega-con-su-modo-en-vivo/

Leave a Reply