Why Android apps from third-party stores sneak malware into your phone: Study

A new study suggests threat actors are using unconventional compression algorithms to distribute Android APKs infected by malware and evade detection by antivirus programs.

According to a report by BleepingComputer, a mobile security firm named Zimperium found that malicious files are being injected using unsupported or modified compression algorithms. Since cybersecurity researchers and antivirus software are currently unable to decompile the APK files, threat actors are injecting malware into APKs and are able to easily bypass security measures.

Zimperium started diving into the issue after a Switzerland-based security firm named ‘Joe Security’, which analyzes malware on Windows, Linux, macOS and Android posted on X showcasing how some APKs were able to evade security analysis by experts using unusual compression techniques.

A recently published study by zLab claims more than 3,000 Android apps are currently using these untraditional anti-analysis methods. Even though many apps crash due to this very reason, researchers found out that more than 71 APKs are running without any issues on Android Pie (Android 9) and newer versions.

While none of these apps were listed on the Play Store, Zimperium suggests they were distributed by third-party app stores or sideloaded. For the uninitiated, sideloading refers to the installation of apps via unofficial sources like APKs sent over WhatsApp, Telegram or Google Play Store alternatives like F-Droid and Aptoide.

If you want to protect your Android device against such threats, the best way is to avoid sideloading apps until necessary and stick to apps found on Google Play Store. In case you have to sideload an app, make sure you scan it using reputed antivirus tools before installing it. Users should also keep track of the permissions the app requests during or after installation.

Static analysis

Static analysis encompasses a broad range of methods that seek to discern the runtime behavior of a software prior to its execution. In a security context, the purpose is naturally to weed out potentially malicious apps before they are installed and executed. Static analysis is considered as coarse, since it flags an app as malicious according to an over-approximation of its possible runtime behavior. As a consequence, any static analysis method must maximize effective detection while

Dynamic analysis

Dynamic analysis is an alternative approach to malware detection, which requires running the program to study its behavior and its effects on its environment. Unlike static analysis, it is late in that it only detects a violation right at the moment when it is about to occur. It also suffers from coverage limitations, since it only considers a single execution, rather than all possible program executions.

As we did in the previous section, we organize dynamic tools in four broad categories,

Discussion

Researchers have long realized that traditional malware detection techniques, such as signature-based anti-viruses, are inadequate to provide effective protection against new malware. Consequently, in recent years, several techniques and tools based on behavioral analysis (static or dynamic) have been at the core of malware identification. Table 5 summarizes the existing approaches surveyed in the previous two sections, and Table 2 gives a summary of the recommendations listed throughout the

Conclusion

In this paper, we survey malware detection methods for Android, focusing on the advantages and drawbacks of each and made recommendations for future research on the topic.

Despite the fact that a large number of solutions that have been proposed, several challenges remains to be addressed, especially because of the rapidly evolving nature of malware. We cite difficulties related to code obfuscation, the unavailability of source code and the emerging problem of malware collusion as problems that

Declaration of Competing Interest

The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author

DTP OPPERATOR AND JOB TYPING WORKER