Android Phone

Android Phones Ship with Malware Preinstalled, Sophos Warns

Sophos researchers say compromised firmware gives attackers persistent, system-level access before users even power on devices.

Sophos researchers have identified Android devices shipping with malware embedded deep in device firmware, giving attackers persistent access to devices even before users power them on for the first time.

Researchers say that the Keenadu malware has been spotted within no less than 500 devices, exfiltrating data from hardware located in at least 40 different countries, according to research released Thursday.

“As of March 4, Sophos X-Intercept telemetry listed over 500 unique compromised Android devices across nearly 50 models. The devices were mostly low-cost models produced by the following manufacturers: Allview, BLU, Dcode, DOOGEE, Gigaset, Gionee, Lava, and Ulefone,” wrote Sophos Counter Threat Unit researchers.

The findings underscore a deeper supply chain problem. Attackers are compromising devices upstream, embedding malware into trusted system components before those devices ever reach users or enterprise networks. As smartphones increasingly serve as MFA authentication tools for corporate system access, a firmware-level compromise undermines that trust entirely.

“Organizations that allow users to access corporate resources from personal devices are at elevated risk. Although data exfiltration is from the device itself, threat actors could access a corporate network via exposed credentials stored in apps on the infected device,” Sophos wrote.

While this is not the first time Keenadu has been spotted in the wild, the latest detections suggest the malware is more broadly distributed than previously understood, pointing to a wider and potentially ongoing supply chain issue rather than isolated infections.

The malware infects devices at the firmware level rather than the application layer. To do this, the attackers disguise their malware not as an app, but as a commonly used library known as libVndxUtils.a, which is loaded by the Android system at runtime.

More critically, Keenadu is injected into libandroid_runtime.so, a core Android library that operates within the Zygote process. The Zygote process is a parent process responsible for launching every application on an Android device. Because every app is launched from the Zygote process, the malware executes within each application instance, giving it system-wide visibility and control without needing to infect individual apps.

The initial infection is believed to be at the supply chain level by an attacker who has access the Android manufacturers’ Android firmware image installed on devices before shipping. In practice, this suggests the malicious code was introduced during the firmware build or integration phase, meaning the devices were compromised before leaving the factory versus tricking a user into downloading the malware.

The Keenadu malware goes to work each time an app is launched on the impacted Android device. Simply opening an app triggers the infected runtime components, allowing the Keenadu malware to execute alongside legitimate processes. Because it operates inside the system runtime rather than as a standalone app, its activity can blend in with normal system behavior and evade many traditional mobile security controls, Sophos said.

While the malware has the capability to function as a backdoor, in practice it has so far only appeared to operate as a modular data harvesting tool. Infected devices have been observed transmitting account credentials and activity data from popular apps and services to infrastructure controlled by the malware operators. Additional modules can be downloaded to expand functionality, including ad fraud operations that silently generate revenue in the background, researchers said.

Because the malware does not run at the application level, but rather as part of the Android system runtime itself, it is capable of monitoring and interacting with any application at launch. This allows for the harvesting of sensitive data in memory and track user activity across the device.

Remediation is difficult. Deleting apps will not remove the infection, and standard mobile security tools may not detect it because it resides within trusted system components. Instead, Sophos recommends users and organizations update device firmware from the device manufacturer to replace the compromised libraries with clean versions.

(Shaun Nichols is an IT news journalist. He has spent nearly 20 years covering the industry with a specialty in the cybersecurity field.)

Image Credit: Denny Müller

Total
0
Shares
Previous Article

DarkSword iPhone Exploit Signals Shift in Stealth Mobile Attacks

Next Article
EggStreme Fileless Malware Illustration

The Impossible Omelette: Chinese APT Delivers 'EggStreme,' a Fileless Malware Invisible to Antivirus

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading