Cyber Security News

New Trinda Malware Targets Android Devices by Replacing Phone Numbers During Calls

Kaspersky Lab has uncovered a new version of the Triada Trojan, a sophisticated malware targeting Android devices.

This variant has been found pre-installed in the firmware of counterfeit smartphones mimicking popular models, often sold at discounted prices through unauthorized online stores.

The malware poses significant risks to users, with more than 2,600 cases reported globally, primarily in Russia.

The Trojan infiltrates the system framework of infected devices, embedding itself into every process on the smartphone.

This enables attackers to exert nearly unlimited control over the device.

The malware’s capabilities include stealing user accounts from messaging apps like Telegram and TikTok, intercepting and manipulating SMS messages, and replacing cryptocurrency wallet addresses to divert funds during transactions.

It can also monitor browser activity, redirect links, and replace phone numbers during calls to reroute communications to attackers’ desired contacts.

Supply Chain Compromise and Financial Impact

Experts believe the malware enters devices during manufacturing or supply chain processes before reaching consumers.

Dmitry Kalinin, a cybersecurity expert at Kaspersky Lab, noted that unauthorized retailers may unknowingly distribute infected smartphones.

Analysis of financial transactions linked to the malware revealed that attackers have transferred approximately $270,000 in various cryptocurrencies to their wallets.

This figure may be higher due to their use of Monero, a privacy-focused cryptocurrency that is difficult to trace.

The Triada Trojan has long been recognized as one of the most complex threats to Android devices.

Its latest iteration demonstrates advanced monetization strategies by targeting cryptocurrency transactions and premium SMS services.

Additionally, it can download and execute other malicious software on compromised devices while blocking network connections to disrupt anti-fraud systems.

Recommendations for Users

To mitigate risks associated with pre-installed malware like Triada, Kaspersky Lab advises consumers to purchase smartphones exclusively from authorized distributors.

Installing robust security solutions immediately after purchase is also recommended. Tools such as Kaspersky for Android can help detect and neutralize threats on infected devices.

The discovery highlights ongoing vulnerabilities in supply chains and underscores the importance of cybersecurity measures for mobile devices.

As cyber threats evolve, users must remain vigilant against risks posed by counterfeit hardware and pre-installed malware.

Kaspersky Lab continues to monitor developments related to Triada and other mobile threats, leveraging its expertise in cybersecurity to protect users worldwide.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a premier…

4 hours ago

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by empowering…

4 hours ago

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…

9 hours ago

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…

2 days ago

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…

2 days ago

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…

2 days ago