Cybersecurity firm Kaspersky has identified a new version of the Triada Trojan, a type of malware that is preinstalled in counterfeit Android phones and can take full control of affected devices without the user’s knowledge.
The Trojan, first discovered in 2016, has now evolved and is embedded in the system firmware of fake smartphones, often sold on online marketplaces. This allows the malware to remain hidden and active even after a factory reset.
More than 2,600 users around the world have been affected. The countries with the highest number of infections include Russia, Brazil, Kazakhstan, Germany, and Indonesia.
“The new version of the Triada Trojan allows attackers to take full control of infected devices,” Sam Yan, head of Sales for Asia Emerging Countries at Kaspersky, said in an email interview with Back End News.
He noted that the Triada Trojan can hijack social media and messaging accounts like Telegram, TikTok, Facebook, and Instagram; replace cryptocurrency wallet addresses to steal funds; intercept and delete SMS messages; redirect and spoof phone calls; monitor browsing activity and inject malicious links; install and run other harmful software; and initiate unauthorized Premium SMS charges.
Kaspersky researchers discovered the Trojan while investigating suspicious behavior in Android devices. They found that the malware was not from a downloaded app, but instead hidden deep in a core part of the system called Zygote. This is the Android component used to launch every app. Once the Trojan is inside Zygote, it becomes a part of all running applications, giving it broad control over the phone.
Triada targets crypto wallets, messages, and accounts
Triada can quietly steal login details, view private content, and even take over social media and messaging accounts. It can also track online activity, send or delete text messages, and subscribe users to paid services without permission. Kaspersky researchers found that Triada uses a crypto-stealing tool that changes copied wallet addresses and even alters QR codes to reroute payments.
Since June 2024, over $264,000 in cryptocurrency has been stolen through these methods. However, Kaspersky said the actual number may be higher, as some losses may not be traceable.
“One of the clearest signs that this is a supply chain attack is the fact that the malware was found embedded in the system firmware of the device,” Yan said. “Meaning, it was already there before the user even turned the phone on. This isn’t something that can happen through a downloaded app after purchase.”
Call for better safeguards in device manufacturing
Triada cannot be removed through normal means, like a factory reset. This makes it a serious concern for people unknowingly using counterfeit devices. Kaspersky urges consumers to buy smartphones only from trusted and official sources.
“It’s a wake-up call for the industry to invest more in securing every step of the production and distribution process,” Yan said. “Manufacturers and suppliers need to strengthen quality control, verify firmware integrity, and audit third-party vendors more closely.”