A new version of the Triada trojan has been found pre-installed on thousands of new Android devices. Once the devices are set up, the malware begins stealing data.

Kaspersky researchers observed that the malicious campaign primarily affects Russian users , with at least 2,600 confirmed infections from March 13 to 27, 2025.
The Triada trojan was found in counterfeit versions of popular smartphone models sold in online stores at low prices. The goal of the scammers is to attract buyers with the lowest cost.
See also: Beware! New attacks with Outlaw malware
Triada is a modular Android malware that was first discovered in 2016. At the time, it was considered very advanced because it ran almost entirely in the device's RAM (to avoid detection). Since then, there have been several reports of Triada being introduced into the firmware Android phones sold through dubious unofficial retail channels.
Kaspersky's latest report shows that the newest version of Triada manages to evade detection to a large extent. It hides in the Android system framework and copies itself to every process on the smartphone.
The latest variant of the malware performs the following actions on infected devices:
- It steals accounts from messenger and social media
- Sends and deletes messages via WhatsApp and Telegram
- Tracks, sends and deletes SMS messages
- Activates premium SMS to charge victims
- Steals cryptocurrencies by replacing wallet addresses in apps
- Monitors browsing activity and switches links
- Spoofs phone numbers during calls to redirect conversations
- Downloads and runs additional applications remotely
- Blocks network connections to avoid detection or disrupt defenses
See also: Crocodilus malware gains access to users' crypto wallets

Researchers have found that the Triada trojan has stolen at least $270,000 worth of cryptocurrencies from the malicious Android devices . However, the exact amount is unknown, as it also includes the hard-to-detect cryptocurrency Monero
Kaspersky has not concluded how the devices were infected by Triada, but assumes it is the result of a supply chain attack.
“The new version is embedded in the firmware of smartphones before the devices even reach users,” commented Dmitry Kalinin of Kaspersky. “It is possible that the supply chain was compromised at some point, so even stores may not realize that they are selling phones with Triada.”
To reduce this risk, buy smartphones only from authorized distributors. Opt for devices from well-known companies with a good reputation for security. Check the manufacturer's security guarantees and update policies.
See also: New RESURGE malware exploits Ivanti vulnerability
Also, after purchase, check for updates (Settings → System → Software Update) and install the latest security patches.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Install reliable software antivirus to detect and remove potential malware in a timely manner.
Proactive action and constant monitoring can prevent your data from being compromised by malware like the Triada trojan.
Source: www.bleepingcomputer.com
