logo

Using capa Rules for Android Malware Detection

ID: fd9e6c08-9367-569e-a94e-15bf437a34bb

STIX ID: report--fd9e6c08-9367-569e-a94e-15bf437a34bb

Feed Name: Google Cloud Threat Intelligence

Threat Score
60/100

Date Published: 2025-02-06

Date Updated: 2026-04-27

Author: Lin Chen

...
...

This report analyzes an Android app that conceals illegal gambling functionality inside a seemingly benign music app by loading a stripped, native ARM ELF library at runtime to evade detection; Android Security and Privacy Team and Mandiant FLARE extended capa rules to detect behaviors in native ELF files and used Gemini to summarize highlighted code for faster security reviews.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.