A sophisticated new variant of the Triada trojan has been discovered preinstalled on thousands of new Android smartphones, enabling cybercriminals to steal sensitive data immediately after device setup. Kaspersky researchers have identified at least 2,600 infections between March 13-27, 2025, primarily affecting Russian users.
The malware was found on counterfeit versions of popular smartphone models sold at discounted prices through online stores, targeting budget-conscious consumers.
## Advanced Evasion Techniques
First discovered in 2016, Triada was revolutionary for operating almost entirely in device RAM to avoid detection. The latest version continues this evasive approach by:
– Hiding within Android’s system framework
– Copying itself to every process on the infected smartphone
– Persisting in device firmware, making removal nearly impossible without reflashing
## Extensive Malicious Capabilities
The new Triada variant can:
– Steal social media and messaging accounts
– Send and delete WhatsApp and Telegram messages to impersonate users
– Hijack cryptocurrency by replacing wallet addresses
– Track browsing activity and manipulate links
– Spoof phone numbers during calls
– Intercept and manipulate SMS messages
– Enable premium SMS services for fraudulent charges
– Download and execute additional malware
– Block network connections to evade detection
## Financial Impact
Transaction analysis reveals the trojan has stolen at least $270,000 in cryptocurrency, though the total amount is likely higher due to thefts involving hard-to-trace Monero cryptocurrency.
## Supply Chain Compromise
Kaspersky researcher Dmitry Kalinin notes: “Its new version is embedded into smartphone firmware before the devices even reach users. It is likely that the supply chain is compromised at some point, so even the stores may not realize they’re selling phones with Triada.”
## Protection Recommendations
To avoid this threat:
– Purchase smartphones only from authorized distributors
– When suspicious, reflash devices using clean system images from Google or trusted third-party ROMs like LineageOS or GrapheneOS
