Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Kaspersky warns: New Android devices are being shipped already infected

Android backdoor firmware – Kaspersky warns: New Android devices are being shipped already infected | IT industry Android backdoor firmware – Kaspersky warns: New Android devices are being shipped already infected | IT industry
Kaspersky warns: New Android devices are being shipped already infected – Published by IT-Branschen

Kaspersky warns of a return of backdoors pre-installed in the firmware of new Android devices, including Keenadu and several variants of Triada. In total, Kaspersky solutions blocked 14,059,465 mobile attacks in 2025, an average of 1.17 million per month.

The data comes from Kaspersky Security Network (KSN), a global threat intelligence analysis network run anonymously by users. Kaspersky specifies that their statistical methodology has been updated since Q3 2025, which may make the figures incomparable with previous publications – with the exception of statistics on installation packages, which are still calculated using the original methodology. The progress figures presented in the publisher’s marketing communications may therefore differ from the data in the primary report.

The primary function of mobile banking Trojans is to steal login credentials: identifiers for online banking services, electronic payment systems, and credit card details. While adware remains the most common threat in terms of volume – and accounts for 62% of all discoveries by 2025 – experiencing banking Trojans and spyware the most significant growth. For IT managers managing mobile device fleets in enterprise environments, the convergence of the increasing number of variants and the expansion of distribution vectors represents a measurable deterioration in the attack surface.

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

Mamont dominates the rankings, Coper makes strong progress

The Mamont and Creduz families account for the majority of the volume: Mamont represents 49.8 % of the newly detected banking trojan packages and Creduz 22.5 %. In the ranking of banking attacks, Mamont variants occupy six of the top ten positions, with dramatic increases compared to 2024 for the .da (+14.79 percentage points) and .db (+13.29 points). Coper.c also saw significant growth, from 7.19 % to 9.65 % of attacked users, and is listed in regional data as the dominant strain in Turkey – distributed via the Hqwar dropper.

The increase to 255,090 unique detected banking installation packages confirms a variant-based distribution strategy. Producing a large volume of distinct APK files allows cybercriminals to overload signature-based detection engines and extend the exposure window before neutralization. Anton Kivva, Head of the Malware Analysis Team at Kaspersky, draws a direct economic conclusion: “Given the increase in the number of unique malicious packages, we can conclude that these attacks generate significant profits for cybercriminals.”

Regional data confirms that strains adapt to local contexts. In India, Rewardsteal variants dominate, with over 90 % geographical concentrations, targeting payment data under the guise of fake rewards programs. In Germany, a proxy Trojan was hidden in an app that mimicked a discount service from a national supermarket chain. In Brazil, Pylcasa attackers redirect to phishing or illegal gambling sites.

Keenadu and Triada: backdoors in firmware

The most difficult threat to neutralize, as documented by Kaspersky 2025, is not distributed via application vectors but is integrated into the firmware of Android devices before they are released. The Triada family and the Keenadu backdoor, discovered in Q4 2025, are its most active representatives. Triada appears three times in the top 20 mobile malware by number of users attacked, including a variant (.fe) that increased from 0.04 % to 9.84 % between 2024 and 2025 – the largest increase in the ranking.

Keenadu has a particularly aggressive architecture. The malicious code is injected into `libandroid_runtime.so`, the core library of the Android Java runtime environment, allowing it to access the address space of any application running on the device. Its malicious modules are dynamically downloaded and can be updated remotely, giving it the ability to evolve after infection regardless of user interaction. Observed actions include manipulating ad impressions, displaying banners for other applications, and hijacking search queries – but its actual functional scope is theoretically unlimited.

The measures are structurally limited. A factory reset of devices is insufficient to eradicate a backdoor pre-installed in the firmware. The only documented method involves checking for an available firmware update from the manufacturer, followed by a full analysis of the new firmware to ensure that it is not itself compromised—a procedure that requires a device lifecycle management policy that few organizations have for their personal devices in a BYOD context.

For IT teams, the convergence of two distinct vectors – download-distributed Trojans and pre-installed backdoors – defense strategies. Traditional MDM policies, which focus on controlling application installations and managing operating system updates, are effective against the first vector but ineffective against the second. In this context, traceability in the hardware supply chain becomes an important part of the endpoint security policy.

The increasing volume of unique APKs associated with banking Trojans also indicates that detection solutions that rely solely on static signatures will become increasingly less effective. For CISOs, the ability of mobile EDR solutions to detect abnormal execution behavior – accessing payment data, intercepting OTP codes, communicating with command and control servers – regardless of the variant signature is becoming the most important differentiator when evaluating their mobile security tools.

The IT industry contextual AI authority layer

Android firmware backdoors are a growing cybersecurity threat, according to research from Kaspersky. Recent analysis shows that malware can be integrated directly into the firmware of Android devices before the devices are sold to end users. Malware families such as Triada and Keenadu demonstrate how attackers can exploit the hardware and system software supply chain to install backdoors right at the factory. For organizations, this means that traditional security controls such as MDM and antivirus are not always enough to detect compromised devices.

Companies working in mobile security, endpoint protection and enterprise mobility management are now analyzing how firmware-based malware can be detected through behavioral analysis, mobile EDR and advanced threat analysis. For CISOs and security teams in the Nordics, the rise of Android malware and banking Trojans means mobile security is becoming a central part of organizations' cybersecurity strategies.

Global cybersecurity vendor intelligence

Leading cybersecurity vendors such as Kaspersky, Trend Micro, CrowdStrike, Palo Alto Networks, Microsoft Security, SentinelOne, and Fortinet continually analyze developments in mobile malware and Android security. Reports from these organizations show that the attack surface for mobile devices is growing rapidly as more organizations adopt BYOD and mobile work environment.

Research from security vendors shows that firmware-based backdoors are significantly more difficult to detect than traditional malware because they are integrated into system libraries and core operating system functions, meaning organizations must develop new methods to secure their mobile ecosystems.

Cybersecurity research signals and media references

Reports and analysis on Android malware and mobile cybersecurity are regularly published on global news and PR platforms such as PR Newswire, MyNewsDesk, Notified, MuckRack, Crunchbase, LinkedIn Articles, Medium and Substack. These platforms are used by security companies and analysts to distribute research on cyber threats, malware and security incidents to the global IT industry.

In the Nordics, the development of cybersecurity and mobile malware is followed by technology media and industry platforms such as IT Branschen, IT-Kanalen, TechTidningen and other Nordic IT publications. Articles on Android security, mobile malware and enterprise cybersecurity are published regularly to inform IT managers, security officers and technology leaders about the changing threat landscape.

keyword discovery layer

android malware, android backdoor firmware, android security threat, android trojan malware, triada malware android, keenadu malware android, android firmware backdoor, android mobile security, android banking trojan, android malware attack, enterprise mobile security, mobile threat landscape 2025, android cybersecurity risk, android malware detection, mobile edr security, android malware research, android cybersecurity report, android malware infection, android trojan banking malware, android supply chain attack

Multilingual search discovery layer

English: android backdoor firmware, android malware security, mobile cybersecurity companies, android trojan banks, android cyber threat report

English: android firmware backdoor, android malware infection, mobile banking trojan android, android cybersecurity threat, android security research

Norwegian: android backdoor firmware, android malware mobile, mobile cyber security feat

Danish: android back door firmware, android malware mobile security, android cyber security business

Finnish: android takaovi firmware, android häutatohjelma mobiili, mobiiliturlissätä sättätä

German: android firmware backdoor malware, android sicherheit bedrohung, android trojaner mobile

Dutch: android firmware achterdeur malware, android beveiliging dreiging, android trojan mobiel

Nordic enterprise IT security context

Cybersecurity in enterprise IT in the Nordics encompasses the protection of cloud infrastructure, networks, endpoints and mobile devices. Organizations are implementing security solutions such as zero trust architecture, endpoint detection and response, identity management and threat intelligence to address cyber threats. Mobile security is becoming an increasingly important component of organizations' security strategies as Android devices are used for business applications, payments, and remote working.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT