Categories: NewsSecurity

Low-Budget Androids Come Preinstalled With Triada Trojan

Android is and will remain the most popular mobile operating system in the world for the foreseeable future. This means there are quite a few low-budget devices available to consumers all over the world. Not all of the companies behind these cheaper options are taking security very seriously. Some low-budget Android devices come with the Triada Trojan as part of their firmware.

Triada Trojan on Android Is a Bad Sign

According to the researchers who discovered this Trojan, the malware has been found as part of the firmware on several low-budget Android smartphones. Among the models affected are Leagoo’s MN5 Plus and M8, as well as Nomu’s S10 and S20. Only a small portion of the available models in circulation is affected by the Triada Trojan, which hints at a supply chain compromise more than anything else.

It is upsetting to see Android devices coming preinstalled with a well-known mobile Trojan. Although the Android ecosystem is prone to malware of all types, malicious software is often installed after the devices are shipped. The affected models mentioned above have some units having Triada as part of their out-of-the-box firmware, which is disconcerting. It is unclear how this occurred exactly, but an investigation is underway.

Triada is an Android Trojan which goes back all the way to March of 2016 when the malware seemingly operated as the average banking Trojan. It remains unknown how much damage this software caused when everything was said and done. Triada since grew to become an all-around threat which could be used for any type of nefarious activity affecting Android users. In some cases, it was used to steal information or login credentials, whereas in other instances it simply aimed to present backdoor access to criminals.

Related Post

This newer version is designed to automatically receive root access as part of the Zygote core OS process. This means the malware developer could do any type of harm to the infected Android device. This also means the current version is more than capable of stealing credentials or installing additional applications such as malware, ransomware, or other undesirable software.

For the time being, the most logical explanation is that Triada was installed due to a supply chain compromise. It is not the first time such a thing has happened, as we saw a similar compromise in December of 2016. It shows supply chains need to work on becoming a lot more secure in the future.

The bigger question is what can be done to resolve this problem sooner rather than later. It does not appear a patch will be issued to fix the firmware, although that situation may change in the future. Low-budget hardware manufacturers have a reputation to uphold, and they will need to take some course of action to help customers. Leagoo is a well-known brand which has been making waves in the Western world of late. It would be a shame to see companies like it go out of business due to a Trojan.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Velocity Ticket Debuts As The AI-Powered Invoicing Tool Every Service Business Needs in 2026

Velocity Ticket is trying to fix a major gap in businesses, and the approach it…

1 week ago

Axelar Confirms $4.67M Exploit on Secret Network Bridge, Core Protocol Remains Unaffected

Axelar is moving fast to contain damage after identifying a security incident that has resulted…

1 week ago

Sui Synthetic Dollar suiUSDe Gets Its Own Website

suiUSDe now has a dedicated landing page. The token, officially the eSui Dollar, comes out…

1 week ago

Ventuals Winds Down HIP-3 DEX, vHYPE Withdrawals Now Live For All Holders

Ventuals has fully wound down its HIP-3 DEX, and vHYPE withdrawals are now open. The…

1 week ago

Avalanche Launches Payments Collective With Franklin Templeton And 25 Others

Avalanche has launched the Avalanche Payments Collective, bringing together 28 organizations spanning nearly every layer…

1 week ago

ASTER Whale Reopens 5x Long Days After Getting Fully Liquidated On The Same Token

A wallet tracked as 0x5f91 just opened a fresh 5x leveraged long on ASTER, putting…

1 week ago