Konfety Returns: Classic Mobile Threat with New Evasion Techniques
ID: 0d566037-2da2-5ca0-b477-ef82e5bcc92c
STIX ID: report--0d566037-2da2-5ca0-b477-ef82e5bcc92c
Feed Name: Zimperium Blog
This report analyzes the Konfety Android ad-fraud campaign, describing two variants that use the same package name (benign decoy vs malicious), APK/ZIP-level tampering (fake encryption flags and unsupported compression) to break analysis tools, and encrypted assets that dynamically load hidden DEX payloads at runtime. The malware hides its icon, applies geofencing, leverages the CaramelAds SDK for ad delivery and sideloading, and redirects users to deceptive websites that prompt unwanted installs or persistent browser notifications; Zimperium reports protections, provides MITRE ATT&CK mappings and links to IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
