Security researchers have discovered counterfeit versions of popular smartphones being sold at discounted prices with a modified version of the Triada Android malware preinstalled. According to Kaspersky, over 2,600 users across multiple countries have encountered this new variant, with the majority of infections detected in Russia between March 13-27, 2025.
## What is Triada?
First identified in 2016, Triada is a sophisticated modular Android malware that functions as a remote access trojan (RAT). Initially distributed through malicious apps that gained root access to compromised devices, the malware has evolved significantly over time.
By 2017, Triada had transformed into a pre-installed framework backdoor, infiltrating device system images during the production process. Google previously identified a vendor named Yehuo (or Blazefire) as likely responsible for compromising system images with the malware.
## Extensive Capabilities
The latest Triada variant is embedded directly in the system framework, allowing it to be copied to every process on infected smartphones. This grants attackers comprehensive control to:
– Steal user accounts from messaging apps and social networks like Telegram and TikTok
– Send and delete messages on WhatsApp and Telegram without user knowledge
– Replace cryptocurrency wallet addresses in clipboard content
– Monitor web browsing activity and modify links
– Substitute phone numbers during calls
– Intercept SMS messages and subscribe victims to premium services
– Download additional malicious programs
– Block network connections to bypass anti-fraud systems
## Financial Impact
The malware operators have successfully monetized their campaign, transferring approximately $270,000 in various cryptocurrencies to their wallets between June 2024 and March 2025.
## Broader Threat Landscape
This discovery comes amid reports of other Android banking trojans like Crocodilus, TsarBot, and Salvador Stealer targeting financial applications. These threats typically disguise themselves as legitimate Google services and exploit accessibility features to steal banking credentials and financial information.
Security experts emphasize that Triada remains one of the most complex and dangerous threats to Android devices, highlighting ongoing vulnerabilities in mobile device supply chains.
