Proprietary · · 914 days

Android tablet firmware embedded Keenadu

Kaspersky found Keenadu embedded in signed Android tablet firmware, including Alldocube images, after a malicious library entered the firmware build chain.

Keenadu is a firmware-level Android backdoor. Kaspersky traced one public example through Alldocube tablet firmware images, including iPlay 50 mini Pro releases, and found validly signed images containing the malicious changes.

The insertion point was libandroid_runtime.so, a core Android framework library. A malicious static library, libVndxUtils.a, was linked during the build and added code that loaded Keenadu inside Zygote, the parent process for Android applications.

That placement broke the normal app boundary. Keenadu could run in the context of installed apps, collect device metadata, install additional APKs, inject modules into apps such as Chrome and YouTube, hijack search traffic, and simulate ad clicks or app installs.

Kaspersky concluded that a stage of the firmware supply chain was compromised, not merely an OTA download server. The signed images and build artifacts point to malicious code entering before firmware release, so affected tablets could arrive already compromised.

Appendix · Affected releases

  • Kaspersky identified Alldocube as one investigated example and said telemetry also showed infected tablet firmware from other manufacturers.
  • Kaspersky reported more than 13,000 infected endpoints, with firmware-level Keenadu mostly used for ad fraud but capable of broader device control.
  • Affected models: iPlay 50 mini Pro, iPlay 50 mini Pro NFE, iPlay 60 mini Pro, iPlay 60 Pro, iPlay 50 Pro. These name hardware or product variants, not releases.

References

  1. Keenadu the tablet conqueror and the links between major Android botnetssecurelist.com
  2. Security Alert: Trojan detected on iPlay 50 Mini Pro / NFEalldocube.com
  3. Keenadu Firmware Backdoor Hijacks Android Tablets via Supply Chain Attackthehackernews.com
  4. Android tablets infected with Keenadu malware firmware backdoorandroidauthority.com
  5. Keenadu Android Malware Pre-Installed On Cheap Devicescybersecuritynews.com

Source record: proprietary/keenadu/meta.yaml