Keenadu: Android malware that comes preinstalled and can’t be removed by users
Summary
Keenadu is an Android malware that arrives preinstalled on devices through compromised firmware (the core system software that runs before the operating system), giving attackers deep control before users even finish setup. Because it embeds itself at the firmware level with elevated privileges (high-level system access), standard removal methods don't work, and it can steal biometric data, messages, banking credentials, and monitor browser searches. The malware has infected over 13,000 devices across multiple countries and can also spread through seemingly harmless apps in app stores.
Classification
Original source: https://www.csoonline.com/article/4133774/keenadu-android-malware-that-comes-preinstalled-and-cant-be-removed-by-users.html
First tracked: February 18, 2026 at 11:00 AM
Classified by LLM (prompt v3) · confidence: 95%