'Criminals in 2017 managed to get an advanced backdoor preinstalled on Android devices before they left the factories of manufacturers, Google researchers confirmed on Thursday.
Triada first came to light in 2016 in articles published by Kaspersky here and here, the first of which said the malware was "one of the most advanced mobile Trojans" the security firm's analysts had ever encountered. Once installed, Triada's chief purpose was to install apps that could be used to send spam and display ads. It employed an impressive kit of tools, including rooting exploits that bypassed security protections built into Android and the means to modify the Android OS' all-powerful Zygote process. That meant the malware could directly tamper with every installed app. Triada also connected to no fewer than 17 command and control servers.
In July 2017, security firm Dr. Web reported that its researchers had found Triada built into the firmware of several Android devices, including the Leagoo M5 Plus, Leagoo M8, Nomu S10, and Nomu S20. The attackers used the backdoor to surreptitiously download and install modules. Because the backdoor was embedded into one of the OS libraries and located in the system section, it couldn't be deleted using standard methods, the report said.
On Thursday, Google confirmed the Dr. Web report, although it stopped short of naming the manufacturers. Thursday's report also said the supply chain attack was pulled off by one or more partners the manufacturers used in preparing the final firmware image used in the affected devices. Lukasz Siewierski, a member of Google's Android Security & Privacy Team, wrote:'
Read more: Google confirms that advanced backdoor came preinstalled on Android devices
Did you like this article?
Thank you for your vote!
4 October 2019
The Open Letter from the Governments of US, UK, and Australia to Facebook is An All-Out Attack on Encryption
24 July 2019
The ultimate disguise? New concept glasses make the wearer undetectable to facial recognition software and could help protect privacy from prying cameras
19 July 2019
Google and Facebook are tracking users as they watch PORN with almost half of adult sites exposing details of YOUR private sexual fantasies, study claims
From our advertisers
From our advertisers