Executive Summary
In 2025, Kaspersky's analysis revealed a significant surge in mobile malware attacks, with over 14 million incidents involving malicious, advertising, or unwanted software targeting mobile devices. Notably, adware constituted 62% of these detections, while the number of new Trojan banker installation packages for Android escalated to 255,090, marking a 271% increase from the previous year. This sharp rise underscores the growing profitability of such attacks for cybercriminals. (kaspersky.com)
The proliferation of preinstalled backdoors like Triada and Keenadu, embedded during device manufacturing, presents a formidable challenge, granting attackers extensive control over compromised devices. Additionally, the emergence of the Kimwolf IoT botnet, which exploits Android TV boxes for DDoS attacks and as reverse proxies, highlights the expanding threat landscape. These developments necessitate heightened vigilance and robust security measures to safeguard mobile users. (kaspersky.com)
Why This Matters Now
The exponential growth in mobile malware, particularly banking Trojans and preinstalled backdoors, signifies an urgent need for enhanced mobile security protocols. As cybercriminals refine their tactics and exploit new vectors, individuals and organizations must prioritize comprehensive security solutions and user education to mitigate these evolving threats.
Attack Path Analysis
The Keenadu backdoor was embedded into Android device firmware during manufacturing, allowing attackers to gain initial access. This deep integration enabled the malware to escalate privileges by injecting itself into the Zygote process, affecting all applications. The backdoor facilitated lateral movement by compromising system applications and spreading through official app stores. It established command and control channels via a client-server architecture, enabling remote execution of malicious payloads. The malware exfiltrated sensitive user data, including credentials and biometric information. The impact included unauthorized access, data theft, and potential device control by attackers.
Kill Chain Progression
Initial Compromise
Description
Keenadu was embedded into Android device firmware during manufacturing, providing attackers with initial access upon device activation.
MITRE ATT&CK® Techniques
Deliver Malicious App via Authorized App Store
Deliver Malicious App via Other Means
Download New Code at Runtime
Application Discovery
Audio Capture
Video Capture
Standard Application Layer Protocol
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: Pillar 2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Mobile banking Trojans like Mamont and Coper pose critical threats to financial institutions, compromising customer credentials and enabling fraudulent transactions through infected devices.
Financial Services
Surge in mobile malware targeting payment systems creates significant risks for financial service providers, requiring enhanced mobile security and zero-trust segmentation capabilities.
Telecommunications
Android TV box botnets and preinstalled backdoors threaten telecom infrastructure integrity, enabling DDoS attacks and unauthorized proxy operations through compromised consumer devices.
Consumer Electronics
Preinstalled firmware backdoors like Keenadu compromise device manufacturing security, requiring enhanced supply chain controls and runtime policy enforcement for consumer protection.
Sources
- Mobile malware evolution in 2025https://securelist.com/mobile-threat-report-2025/119076/Verified
- Kaspersky discovers Keenadu – a multifaceted Android malware that can come preinstalled on new deviceshttps://me-en.kaspersky.com/about/press-releases/kaspersky-discovers-keenadu-a-multifaceted-android-malware-that-can-come-preinstalled-on-new-devicesVerified
- Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attackshttps://thehackernews.com/2025/12/kimwolf-botnet-hijacks-18-million.htmlVerified
- Kimwolf Botnet: Massive Android TV Box and IoT Malware Threat Exploiting Global Networkshttps://www.rescana.com/post/kimwolf-botnet-massive-android-tv-box-and-iot-malware-threat-exploiting-global-networksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the malware's ability to escalate privileges, move laterally, establish command channels, and exfiltrate data, thereby reducing the attacker's operational scope.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF primarily secures cloud workloads, its principles could inform strategies to limit the impact of firmware-level compromises by enforcing strict segmentation and access controls.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the malware's ability to escalate privileges by enforcing strict identity-based access controls, reducing the scope of compromised processes.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely restrict the malware's lateral movement by monitoring and controlling internal traffic flows, thereby reducing the spread of infection.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and limit unauthorized command and control communications by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit data exfiltration by controlling and monitoring outbound traffic, reducing unauthorized data transfers.
While Aviatrix CNSF cannot prevent initial compromises, its controls could likely reduce the overall impact by limiting unauthorized access and data theft within cloud environments.
Impact at a Glance
Affected Business Functions
- Mobile Device Security
- Ad Revenue Integrity
- Network Infrastructure Stability
- User Data Privacy
Estimated downtime: 7 days
Estimated loss: $5,000,000
Potential compromise of user data including media files, messages, banking credentials, and location information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized lateral movement within the network.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to unusual activities promptly.
- • Utilize Multicloud Visibility & Control to monitor and manage security policies across all cloud environments.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.



