Simplify your online presence. Elevate your brand.

Unsupported Compression Methods Enable Android Malware To Bypass Detection

Unsupported Compression Methods Enable Android Malware To Bypass Detection
Unsupported Compression Methods Enable Android Malware To Bypass Detection

Unsupported Compression Methods Enable Android Malware To Bypass Detection However, android’s apk, which uses the zip format, supports only two compression methods. one is without any compression, i.e. the stored method (0x0000), and the other is the deflate (0x0008) compression algorithm. Threat actors are using android package (apk) files with unsupported compression methods to prevent malware analysis.

Unsupported Compression Methods Enable Android Malware To Bypass Detection
Unsupported Compression Methods Enable Android Malware To Bypass Detection

Unsupported Compression Methods Enable Android Malware To Bypass Detection The technique is not new, in 2014 researchers demostrated how the compression algorithm (method) used in an apk could be tampered to remove automatic script analysis and hinder static analysis. “however, android’s apk, which uses the zip format, supports only two compression methods. This sample uses a technique that limits the possibility of decompiling the application for a large number of tools, reducing the possibilities of being analyzed. in order to do that, the apk (which is in essence a zip file), is using an unsupported decompression method. this technique is not new. Threat actors are using android package (apk) files with unknown or unsupported compression methods to elude malware analysis. that's according to findings. Cybersecurity firm zimperium has uncovered threat actors using android package (apk) files with unknown or unsupported compression methods to avoid detection during malware analysis.

Unsupported Compression Methods Enable Android Malware To Bypass Detection
Unsupported Compression Methods Enable Android Malware To Bypass Detection

Unsupported Compression Methods Enable Android Malware To Bypass Detection Threat actors are using android package (apk) files with unknown or unsupported compression methods to elude malware analysis. that's according to findings. Cybersecurity firm zimperium has uncovered threat actors using android package (apk) files with unknown or unsupported compression methods to avoid detection during malware analysis. By using an unknown or unsupported compression method, researchers (and ultimately, av programs) cannot unzip the apk for analysis and thus cannot deem an app malicious. Threat actors increasingly distribute malicious android apks (packaged app installers) that resist decompilation using unsupported, unknown, or heavily tweaked compression algorithms. Threat actors are using android package (apk) files with unsupported compression methods to prevent malware analysis. on june 28th, researchers from zimperium zlab researchers observed that joe sandbox announced the availability of an android apk. While this sample prevents the decompilation by employing a decompression method that is entirely unsupported within its apk, a zip file makes the complete analysis difficult for many tools.

Unsupported Compression Methods Enable Android Malware To Bypass Detection
Unsupported Compression Methods Enable Android Malware To Bypass Detection

Unsupported Compression Methods Enable Android Malware To Bypass Detection By using an unknown or unsupported compression method, researchers (and ultimately, av programs) cannot unzip the apk for analysis and thus cannot deem an app malicious. Threat actors increasingly distribute malicious android apks (packaged app installers) that resist decompilation using unsupported, unknown, or heavily tweaked compression algorithms. Threat actors are using android package (apk) files with unsupported compression methods to prevent malware analysis. on june 28th, researchers from zimperium zlab researchers observed that joe sandbox announced the availability of an android apk. While this sample prevents the decompilation by employing a decompression method that is entirely unsupported within its apk, a zip file makes the complete analysis difficult for many tools.

Comments are closed.