PULSE NAME
Android devices ship with firmware-level malware
WHITE PetrP.73 2026-03-24 Modified: 2026-04-23
35
IOCs
MEDIUM VOLUME
Keenadu malware is a significant cyber threat targeting Android devices, identified by SophosLabs analysts in late February 2026. This malware operates as a firmware-level backdoor embedded within the libandroid_runtime.so library, enabling attackers to take full control of infected devices. By injecting itself into the Zygote process, which serves as the parent for all Android applications, Keenadu ensures its presence across all apps on the compromised device. The payload can function as a downloader for various malicious modules aimed at extracting data from applications or facilitating ad fraud.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (5 / 35 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 7db58b72a3493a86e847c3685eca74c690d50b55 2026-03-24
FileHash-SHA1 7eb32a90d556bb9954707014843a67f7039ea7f1 2026-03-24
FileHash-SHA1 b73c94e56932f607108ec1efb74004c763a9e42b 2026-03-24
FileHash-SHA1 c33b025bac789d3742278f784377fc36f83fd1ff 2026-03-24
FileHash-SHA1 dcf2b51bfc43494bb27f5da26f3f706ca878d17e 2026-03-24