Android devices ship with firmware-level malware

2026-03-20T08:51:46Z6004f7dc10d2a4807746ecfd9c12d4bc1d77595d7b4258e483c12b002da2770e
active-exploitationad-fraudandroidcisco-sd-wanclickfixfirmware-malwarehacktivisminfostealerinitial-accessirankeenadumacosoperation-epic-furypatch-tuesdaysocial-engineeringsophos-ctuvulnerability-advisory

What happened

Sophos published multiple threat-research advisories (Mar 2026) covering: Keenadu, a firmware-level Android malware that provides persistent device control and appears used mainly for ad fraud; macOS infostealer campaigns leveraging ClickFix/social‑engineering; analysis of preferred initial-access techniques used by Iran-linked groups; increased (but currently limited-impact) hacktivist activity tied to US–Israel–Iran tensions (Operation Epic Fury); March Patch Tuesday (84 CVEs, eight rated Critical); and active exploitation of Cisco SD‑WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775). The

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
6004f7dc10d2a4807746ecfd9c12d4bc1d77595d7b4258e483c12b002da2770e
Enrichment time
2026-03-20T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.