Dodgy Android smartphones are being preloaded with Triada malware

 Dodgy Android smartphones are being preloaded with Triada malware

Published on April 3, 2025 | Category: tech

Dodgy Android smartphones are being preloaded with Triada malware

News
By Sead Fadilpašić published

Victims have already lost hundreds of thousands of dollars

Android phone malware
Malware kan ställa till med oreda (Image credit: Shutterstock)

  • Kaspersky uncovers counterfeit Android smartphones preloaded with Triada malware
  • The researchers speculate the supply chain might have been compromised
  • More than $270,000 in crypto has already been stolen

Counterfeit versions of popular Android smartphones are being sold with malware pre-installed, experts have revealed.

Cybersecurity researchers Kaspersky have warned users about buying heavily discounted Android smartphones from shady online stores after it observed at least 2,600 victims, located mostly in Russia, who received their brand-new smartphones carrying the Triada Trojan.

“The new version of the malware is found in the firmware of infected Android devices,” reads the machine-translated announcement. “It is located in system framework, meaning a copy of Triada makes its way into every process on your smartphone.”

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Targeting journalists

The malware was said to have a wide range of functionalities and can give the attacker “almost unlimited possibilities” for controlling the compromised devices.

Among other things, Triada can steal user accounts in messengers and social networks, stealthily send messages on behalf of the victim, steal cryptocurrencies, monitor the victim’s browser activities, replace links, swap numbers during calls, monitor and intercept SMS messages, download and run apps, and block network connections.

Dmitry Kalinin, cybersecurity expert at Kaspersky Lab, said Triada remains “one of the most sophisticated and dangerous threats to Android,” but added that the researchers don’t really know how the devices got infected.

“It’s possible that one of the stages in the supply chain is compromised,” he said, “so the stores selling the devices may not even suspect that they’re selling Triada-infected devices.”

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

These thousands of victims have already suffered hundreds of thousands of dollars in losses, the researchers concluded.

Kaspersky claims around $270,000 in cryptocurrency was already siphoned out, suggesting that the number could be even greater since some of the transactions were made in difficult-to-trace Monero.

The best way to avoid this risk is to only buy smartphones from authorized sellers. Alternatively, users could reflash their device using a clean system image from Google.

Via BleepingComputer

You might also like

  • Private API keys and passwords found in AI training dataset - nearly 12,000 details leaked
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
TOPICS
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
Start windows 11 button on computer menu screen close up view

Do I really need antivirus for Windows 11?

big data business ai

GenAI bots could well be scraping your web apps, researchers warn

Latest
Start windows 11 button on computer menu screen close up view

Do I really need antivirus for Windows 11?

See more latest
Most Popular
Start windows 11 button on computer menu screen close up view
Do I really need antivirus for Windows 11?
V-Copter Falcon Mini drone in flight above a road in a forest
This unique bi-copter drone could actually disrupt DJI's drone dominance – and now we know its tempting price tag
Operators battle it out on the Fortnite OG
The Nintendo Switch 2 is backward compatible but a ton of original Switch games have 'start up' and 'compatibility' issues
A smartphone with the Google Keep app open
Google Keep could get a fresh redesign soon – including two features that’ll make it much easier to use
Ralph Fiennes as Cardinal Thomas Lawrence in Conclave
Everything new on Prime Video in April 2025, including Oscar winner Conclave and nominee Nickel Boys
big data business ai
GenAI bots could well be scraping your web apps, researchers warn
A Windows 11 laptop sitting on a desk in front of a window
Microsoft adds hotpatching support for Windows 11 enterprise users as it looks to end unnecessary downtime for work devices
A cape-wearing man stands against a moonlit sky
Upcoming Nintendo Switch 2 exclusives - release schedule for confirmed games including The Duskbloods and Mario Kart World
The Nintendo Switch 2 console on a stand
Furious fans hijack Nintendo Treehouse: Live stream with demands to 'drop the price'
Zotac Gaming RTX 5090 Graphics Card
Amazon adds new benefit to Prime subscription that gives members a better chance of buying an Nvidia RTX 5000 or AMD RX 9070 GPU

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More