logo

Dynamic Analysis Technique of Android Malware by Injecting Smali Gadgets

ID: a35944ec-4287-518e-9999-943115c39d0a

STIX ID: report--a35944ec-4287-518e-9999-943115c39d0a

Feed Name: JPCERT Blog

Threat Score
15/100

Date Published: 2024-08-08

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

This article presents a hands-on technique for dynamic analysis of Android malware by injecting a smali gadget into an APK: identify target methods via decompilation, edit the smali (e.g., to log arguments and return values), rebuild and sign the APK, then run it in an offline Android emulator to observe runtime behavior; an example Cerberus sample is referenced.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.