BadPack APK Malware Using Wired Trick to Attack Users & Stay Undetected
ID: eace21ae-4f06-522c-b740-8e2ba5482c1e
STIX ID: report--eace21ae-4f06-522c-b740-8e2ba5482c1e
Feed Name: cybersecurityNews.com
The report describes the BadPack APK technique where attackers intentionally tamper APK (ZIP) local and central directory headers to create mismatches that hinder analysis and extraction, enabling persistent, hidden Android malware—particularly banking trojans like BianLian and Cerberus. WildFire observed roughly 9,200 BadPack samples from June 2023 to June 2024; the document lists four SHA256 sample hashes, notes which analysis tools fail or succeed (apkInspector can extract AndroidManifest.xml), and recommends avoiding untrusted app sources and suspicious permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
