- Kaspersky reveals forged Android -SmartPhones preloaded with Triada Malware
- The researchers speculate in the supply chain may have been compromised
- More than $ 270,000 in crypto is already stolen
Forged versions of popular Android smartphones sold with malware pre-installed, experts have revealed.
CyberSecurity scientists Kaspersky have warned users to buy heavily reduced Android smartphones from shady online stores after it observed at least 2,600 victims, mostly located in Russia who received their brand new smartphones with Triada Trojan.
“The new version of Malware is found in the Firmware on infected Android devices,” reads the machine-translated message. “It’s located in system frames, which means a copy of Triada is running into any process on your smartphone.”
Targeting journalists
It is said that malware had a wide range of functionalities and can give the striker “almost unlimited options” to control the compromised devices.
Triada can, among other things, steal user accounts in messenger and social networks, stealthily send messages on behalf of the victim, steal cryptocurrencies, monitor the victim’s browser activities, replace links, swapn numbers during calls, monitor and intercept SMS messages, download and run apps and block network connections.
Dmitry Kalinine, CyberSecurity expert at Kaspersky Lab, said Triada remains “one of the most sophisticated and dangerous threats to Android,” but added that scientists do not really know how the devices were infected.
“It is possible that one of the stages of the supply chain is compromised,” he said, “so the stores that sell the units may not even suspect that they are selling Triada-infected devices.”
These thousands of victims have already suffered hundreds of thousands of dollars in losses, the researchers concluded.
Kaspersky claims that about $ 270,000 in cryptocurrency had already been delayed, suggesting that the number could be even greater as some of the transactions were made in difficult to track Monero.
The best way to avoid this risk is to buy smartphones from authorized sellers only. Alternatively, users could reflect their device using a clean system image from Google.
Via Bleeping computer