logo

BadPack APK Malware Using Wired Trick to Attack Users & Stay Undetected

ID: eace21ae-4f06-522c-b740-8e2ba5482c1e

STIX ID: report--eace21ae-4f06-522c-b740-8e2ba5482c1e

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2024-07-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report describes the BadPack APK technique where attackers intentionally tamper APK (ZIP) local and central directory headers to create mismatches that hinder analysis and extraction, enabling persistent, hidden Android malware—particularly banking trojans like BianLian and Cerberus. WildFire observed roughly 9,200 BadPack samples from June 2023 to June 2024; the document lists four SHA256 sample hashes, notes which analysis tools fail or succeed (apkInspector can extract AndroidManifest.xml), and recommends avoiding untrusted app sources and suspicious permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.