As cited
Copy frozen at (site build).
threat intel
Risky Bulletin: Supply chain attack plants backdoor on Android tablets
A supply chain attack has compromised firmware updates for multiple Android tablet makers since at least August 2023, injecting a backdoor called Keenadu into the Zygote core process. Kaspersky discovered and analyzed the malware, which persists at the system level and requires a complete device flash to remove. The attack demonstrates the persistence risk when threats are embedded in firmware rather than the application layer.
Why it matters: This requires immediate investigation of affected tablet inventory and firmware audit procedures, as the backdoor operates at the OS kernel level beyond standard removal methods.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Risky Bulletin: Supply chain attack plants backdoor on Android tablets
A supply chain attack has compromised firmware updates for multiple Android tablet makers since at least August 2023, injecting a backdoor called Keenadu into the Zygote core process. Kaspersky discovered and analyzed the malware, which persists at the system level and requires a complete device flash to remove. The attack demonstrates the persistence risk when threats are embedded in firmware rather than the application layer.
Why it matters: This requires immediate investigation of affected tablet inventory and firmware audit procedures, as the backdoor operates at the OS kernel level beyond standard removal methods.
- Source published
- First seen by Cybersecurity Tracker