logo

Beware of BadPack: One Weird Trick Being Used Against Android Devices

ID: ad46a5ef-1192-590a-a0be-4675101e94be

STIX ID: report--ad46a5ef-1192-590a-a0be-4675101e94be

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-07-16

Date Updated: 2026-04-28

Author: Lee Wei Yeong

...
...

This Unit 42 report analyzes 'BadPack' Android APK samples that intentionally tamper ZIP/PKZip headers to prevent extraction and static analysis (breaking tools like Apktool, Jadx, 7-Zip, jar, unzip, and apksigner) while still installing on Android because the runtime relies on central directory fields. The paper documents three manipulation methods, provides representative SHA-256 indicators, reviews detection telemetry (~9,200 samples observed in Advanced WildFire from June 2023–June 2024), and highlights apkInspector as a useful extractor and recommended mitigations and protections for users and Palo Alto Networks customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.