logo

Embedding Meterpreter in Android APK

ID: d1717240-4dc3-5915-943c-5625e5a9396f

STIX ID: report--d1717240-4dc3-5915-943c-5625e5a9396f

Feed Name: Black Hills Infosec Blog

Date Published: 2018-10-15

Date Updated: 2026-04-27

Author: BHIS

...
...

This post provides a step-by-step guide to embedding a Metasploit Meterpreter payload into an Android APK by disassembling with apktool, editing smali to invoke the payload on app launch, updating AndroidManifest permissions, rebuilding, and re-signing for sideloading and testing (Genymotion or hardware). It highlights practical considerations like entry-point identification, permission alignment, signature handling, and x86/ARM compatibility. The author also releases a Python tool, AndroidEmbedIT, that automates these steps, underscoring the ease of Trojanizing mobile apps and the associated security risks of sideloaded packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.