logo

Unsupported Compression Methods Enable Android Malware to Bypass Detection

ID: ae2ec0dc-7f4b-5763-8c93-9e6520351104

STIX ID: report--ae2ec0dc-7f4b-5763-8c93-9e6520351104

Feed Name: Zimperium Blog

Threat Score
65/100

Date Published: 2023-08-16

Date Updated: 2026-05-01

...
...

Zimperium zLab analyzed Android APKs that abuse an unsupported ZIP compression method (and additional APK corruptions such as oversized filenames and malformed AndroidManifest/string pools) to evade decompilation and static analysis; a retrohunt found ~3,300 samples using the technique and 71 malicious samples that can load on Android 9+ devices. The report details the technical mechanisms, lists package names and many file hashes as indicators of compromise, and states these apps are not found in Google Play (likely distributed via third-party stores or sideloading).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.