logo

Kwetza: Infecting Android Applications

ID: b2b71276-8251-51a8-b278-991f2b127ae9

STIX ID: report--b2b71276-8251-51a8-b278-991f2b127ae9

Feed Name: SensePost Blog

Threat Score
75/100

Date Published: 2016-10-03

Date Updated: 2026-04-29

...
...

This blog post demonstrates a practical method and an automation tool (Kwetza) for backdooring legitimate Android APKs by embedding an Android Meterpreter payload into target apps. It walks through generating the payload, consolidating payload code, identifying injection points via AndroidManifest and smali, injecting and rebuilding the APK, signing and installing it, and shows that the modified app can evade antivirus detection and provide persistent remote access using the app's existing permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.