Android devices ship with firmware-level malware
2026-03-20T08:51:46Z•6004f7dc10d2a4807746ecfd9c12d4bc1d77595d7b4258e483c12b002da2770e
active-exploitationad-fraudandroidcisco-sd-wanclickfixfirmware-malwarehacktivisminfostealerinitial-accessirankeenadumacosoperation-epic-furypatch-tuesdaysocial-engineeringsophos-ctuvulnerability-advisory
What happened
Sophos published multiple threat-research advisories (Mar 2026) covering: Keenadu, a firmware-level Android malware that provides persistent device control and appears used mainly for ad fraud; macOS infostealer campaigns leveraging ClickFix/social‑engineering; analysis of preferred initial-access techniques used by Iran-linked groups; increased (but currently limited-impact) hacktivist activity tied to US–Israel–Iran tensions (Operation Epic Fury); March Patch Tuesday (84 CVEs, eight rated Critical); and active exploitation of Cisco SD‑WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775). The
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 6004f7dc10d2a4807746ecfd9c12d4bc1d77595d7b4258e483c12b002da2770e
- Enrichment time
- 2026-03-20T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.