http://t2e66hyc4x5dckvijcok5mgichu4sq6jb7nk7npimkm647tzsgjitmqd.onion/blog/keenadu-the-tablet-conqueror-and-the-links-between-major-android-botnets
Furthermore, once the user finishes typing a query, the Trojan can hijack the search request and redirect it to a different search engine, depending on the configuration received from the C2 server. It is worth noting that the hijacking attempt may fail if the user selects a query from the autocomplete suggestions; in this scenario, the user does not hit Enter or tap the search button in the url_bar , which would signal the malware to trigger the redirect....