Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Toy Story 5 Review: Hilarious, provocative, and destined to go on forever

She says she’s “regaining her glow”

Zendaya and Tom Holland are married, actor confirms

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Triada malware preloaded on counterfeit products infects more than 2,600 devices
Celebrities

Triada malware preloaded on counterfeit products infects more than 2,600 devices

By April 3, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 3, 2025Ravi LakshmananThreat Intelligence/Mobile Security

Preloaded malware on Android

It has been found that the counterfeit versions of popular smartphone models, which are sold at low prices, are preloaded with a fixed version of Android malware called Triada.

“More than 2,600 users from various countries have come across new versions of Triada, the majority of Russia,” Kaspersky said in the report. The infection was recorded between March 13th and 27th, 2025.

Triada is the name given to the modular Android malware family, first discovered by a Russian cybersecurity company in March 2016. Remote Access Trojans (RATs) are equipped to not only steal a wide range of confidential information, but also to enlist infected devices into botnets for other malicious activities.

Malware had previously been observed, but was distributed via root access to compromised phones via intermediary apps published on the Google Play Store (and elsewhere), but subsequent campaigns used WhatsApp mods such as FMWhatsApp and YowhatsApp as propagation vectors.

Cybersecurity

Over the years, the modified version of Triada has found its way to unbranded Android tablets, TV boxes and digital projectors as part of a wide range of fraud schemes called Badbox, which leverages the third-party market for compromise in the hardware supply chain and early access.

This behavior was first observed in 2017 when malware evolved into a pre-installed Android framework backdoor, allowing threat actors to remotely control the device, inject more malware and exploit it for a variety of illegal activities.

Google said in June 2019. “OEMs may include features that are not part of Android open source projects, such as Face Unlock. OEMs may partner with third parties where the OEM can develop the functionality they want and send the entire system to the vendor for development,” Google said.

At the time, the tech giant pointed his finger at a vendor named Yehuo or Blazefire who thought it was responsible for infecting the Returned System Image with Triada.

The latest samples of malware analyzed by Kaspersky show that they are in the system framework, so they can be copied into all the processes on your smartphone and provide free access and control to attackers to perform various activities.

Steal user accounts that steal user accounts associated with instant messengers, such as Telegram and Tiktok, send whatsapp and Telegram messages to other contacts on behalf of the victim, delete them, hijack the clipboard content to remove clipper content, hijack the Criptocurrency Wallet address and replace it with call call exchanges via Cliptocurrency Wallet address. Download other programs to subscribe to Premium SMS Victims, block network connections and interfere with the normal functioning of the anti-fulard system

It is worth noting that it is not just malware preloaded on Android devices during the manufacturing stage. In May 2018, Avast revealed that hundreds of Android models, including those like ZTE and Archos, were pre-installed with another adware called Cosiloon.

“The Triadatrojan horse has been known for a long time, but it is still one of the most complicated and dangerous threats for androids,” said Dmitry Kalinin, a researcher at Kaspersky. “Perhaps one of the phases is that the supply chain is being breached, so stores may not even suspect that they are selling smartphones on Triada.”

Cybersecurity

“At the same time, the authors of the newer version of Triada are actively monetizing their efforts. Judging from the analysis of the transactions, they were able to transfer around $270,000 to the cryptocurrency into the cryptocurrency. [between June 13, 2024, to March 27, 2025]. ”

The emergence of an updated version of Triada follows the discovery of two different Android banking Trojans called Crocodilus and Tsarbot, the latter covering over 750 banking, financial and cryptocurrency applications.

Both malware families are distributed via Dropper apps that are impersonating legal Google services. It also exploits Android accessibility services to remotely control infected devices and overlay attacks on Siphon Banking credentials and credit card details.

The disclosure also details a new Android malware strain (package name: “com.indusvalley.appinstall”) called Salvador Steeler, which disguises as a banking application that corresponds to Indian users, allowing you to harvest sensitive user information.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFive important takeaways from Trump’s “liberation day” mutual tariffs | Donald Trump News
Next Article AI breakthrough predicts the spread of antibiotic-resistant bacteria

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Toy Story 5 Review: Hilarious, provocative, and destined to go on forever

She says she’s “regaining her glow”

Zendaya and Tom Holland are married, actor confirms

Prime Day Early Kitchen Sale: Ninja, Keurig, Breville, Calphalon on sale

Trending Posts

She says she’s “regaining her glow”

June 16, 2026

Zendaya and Tom Holland are married, actor confirms

June 16, 2026

Sheryl Crow calls Trump’s UFC B-Day brawl on the White House lawn ‘disgraceful’

June 16, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.