logo

'BadPack' APK Files Make Android Malware Hard to Detect

ID: 642d93db-2156-5453-94e2-c0e33df57a0a

STIX ID: report--642d93db-2156-5453-94e2-c0e33df57a0a

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-07-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Unit 42 researchers disclosed "BadPack", a technique that maliciously manipulates ZIP header data in Android APKs to prevent static-analysis tools (e.g., Apktool, Jadx) from extracting AndroidManifest.xml and other content while still being tolerated by the Android runtime; this evasion has been observed in banking trojans such as TeaBot, BianLian, and Cerberus with about 9,200 BadPack samples detected. The report explains how BadPack works, why analysis tools fail, detection and remediation methods (including restoring header values and using APK Inspector), and recommends defensive measures such as avoiding third-party app sources and scrutinizing unusual permission requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.