http://t2e66hyc4x5dckvijcok5mgichu4sq6jb7nk7npimkm647tzsgjitmqd.onion/blog/keenadu-the-tablet-conqueror-and-the-links-between-major-android-botnets
Furthermore, we have found a static library, libVndxUtils.a (MD5: ca98ae7ab25ce144927a46b7fee6bd21), containing the Keenadu code, which further supports our hypothesis. This malicious library is written in C++ and was compiled using the CMake build system. Interestingly, the library retained absolute file paths to the source code on the developer’s machine: D:\work\git\zh\os\ak-client\ak-client\loader\src\main\cpp\__log_native_load.cpp: this file contains the dropper...