Using capa Rules for Android Malware Detection
ID: fd9e6c08-9367-569e-a94e-15bf437a34bb
STIX ID: report--fd9e6c08-9367-569e-a94e-15bf437a34bb
Feed Name: Google Cloud Threat Intelligence
Threat Score
This report analyzes an Android app that conceals illegal gambling functionality inside a seemingly benign music app by loading a stripped, native ARM ELF library at runtime to evade detection; Android Security and Privacy Team and Mandiant FLARE extended capa rules to detect behaviors in native ELF files and used Gemini to summarize highlighted code for faster security reviews.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
