'BadPack' APK Files Make Android Malware Hard to Detect
ID: 642d93db-2156-5453-94e2-c0e33df57a0a
STIX ID: report--642d93db-2156-5453-94e2-c0e33df57a0a
Feed Name: Dark Reading
Date Published: 2024-07-17
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Unit 42 researchers disclosed "BadPack", a technique that maliciously manipulates ZIP header data in Android APKs to prevent static-analysis tools (e.g., Apktool, Jadx) from extracting AndroidManifest.xml and other content while still being tolerated by the Android runtime; this evasion has been observed in banking trojans such as TeaBot, BianLian, and Cerberus with about 9,200 BadPack samples detected. The report explains how BadPack works, why analysis tools fail, detection and remediation methods (including restoring header values and using APK Inspector), and recommends defensive measures such as avoiding third-party app sources and scrutinizing unusual permission requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
