logo

APK Malformation Found in Thousands of Android Malware Samples

ID: 704abeed-778b-544f-9020-0379366b32d0

STIX ID: report--704abeed-778b-544f-9020-0379366b32d0

Feed Name: Infosecurity Magazine (News)

Threat Score
68/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

...
...

Cleafy researchers reported a widespread Android malware evasion technique—APK malformation—found in over 3,000 samples across families including Teabot, TrickMo, Godfather, and SpyNote; attackers deliberately create inconsistent ZIP/APK structures (directory-file collisions, unsupported compression, mismatched headers, manifest corruption, and filenames with non‑ASCII/control characters) that crash static analysis tools while still installing on devices, and Cleafy released Malfixer to detect and repair these malformed APKs to aid analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.