logo

Konfety Returns: Classic Mobile Threat with New Evasion Techniques

ID: 0d566037-2da2-5ca0-b477-ef82e5bcc92c

STIX ID: report--0d566037-2da2-5ca0-b477-ef82e5bcc92c

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2025-07-15

Date Updated: 2026-05-01

...
...

This report analyzes the Konfety Android ad-fraud campaign, describing two variants that use the same package name (benign decoy vs malicious), APK/ZIP-level tampering (fake encryption flags and unsupported compression) to break analysis tools, and encrypted assets that dynamically load hidden DEX payloads at runtime. The malware hides its icon, applies geofencing, leverages the CaramelAds SDK for ad delivery and sideloading, and redirects users to deceptive websites that prompt unwanted installs or persistent browser notifications; Zimperium reports protections, provides MITRE ATT&CK mappings and links to IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.