Kwetza: Infecting Android Applications
ID: b2b71276-8251-51a8-b278-991f2b127ae9
STIX ID: report--b2b71276-8251-51a8-b278-991f2b127ae9
Feed Name: SensePost Blog
This blog post demonstrates a practical method and an automation tool (Kwetza) for backdooring legitimate Android APKs by embedding an Android Meterpreter payload into target apps. It walks through generating the payload, consolidating payload code, identifying injection points via AndroidManifest and smali, injecting and rebuilding the APK, signing and installing it, and shows that the modified app can evade antivirus detection and provide persistent remote access using the app's existing permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
