The Moscow-based security company reported that Keenadu was found in Android tablets sold by several mostly unnamed brands. Similar to Triada, the threat infects the firmware during the binary build phase, when a malicious static library is secretly linked with the libandroid_runtime.so library.
