216.73.216.6

Beware of BadPack: One Weird Trick Being Used Against Android Devices

· Published 16/07/2024 13:03 · Modified 16/07/2024 13:26

Export JSON

Essential information

Published
16/07/2024 13:03
Modified
16/07/2024 13:26
Tags
2024-07-16 android apk badpack
Related entities
4 observables, 20 techniques (mitre), 3 malware

Description

The report examines the recent trend of malware, which utilizes tampered headers to obstruct analysis tools. It explores the effectiveness of various freely available utilities for analyzing Package Kit () files. The report dissects the structure of files and how malware authors manipulate local and central directory headers to evade detection. Additionally, it traces the codebase implementation responsible for the discrepancy between analysis tools and the runtime regarding extraction. The analysis provides insights into the manifestation of the technique and its impact on popular reverse engineering tools.

External references