Malware researchers at the Russian anti-virus firm Dr.Web have spotted the Triada Trojan in the firmware of several low-cost Android smartphones. The malware was found inside the Android OS Zygote core process, the component used to launch programs on mobile devices. The main function of Android.Triada.231 is to secretly run additional malicious modules that can download other Trojan components. The Trojan cannot be deleted using standard methods because it is hidden into one of the libraries of the operating system. To eradicate the threat, it is necessary to install a clean Android firmware.”]
Source: https://securityaffairs.co/wordpress/61467/malware/triada-trojan-android-smartphones.html