Rotten Apples Spoil the Bunch: An Anatomy of Google Play Malware
Michael Cao, Khaled Ahmed, Julia Rubin
Abstract
This paper provides an in-depth analysis of Android malware that bypassed the strictest defenses of the Google Play application store and penetrated the official Android market between January 2016 and July 2021. We systematically identified 1,238 such malicious applications, grouped them into 134 families, and manually analyzed one application from 105 distinct families. During our manual analysis, we identified malicious payloads the applications execute, conditions guarding execution of the payloads, hiding techniques applications employ to evade detection by the user, and other implementation-level properties relevant for automated malware detection. As most applications in our dataset contain multiple payloads, each triggered via its own complex activation logic, we also contribute a graph-based representation showing activation paths for all application payloads in form of a control-and data-flow graph. Furthermore, we discuss the capabilities of existing malware detection tools, put them in context of the properties observed in the analyzed malware, and identify gaps and future research directions. We believe that our detailed analysis of the recent, evasive malware will be of interest to researchers and practitioners and will help further improve malware detection tools. CCS CONCEPTS • Software and its engineering → Software testing and debugging; • Security and privacy → Software reverse engineering; Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bb06932b-53d5-4ab4-8392-0571fd2b97c5Cited by top-tier papers2
- ViaLin: Path-Aware Dynamic Taint Analysis for AndroidKhaled Ahmed, Yingying Wang, Mieszko Lis, Julia RubinFSE 2023 · 7 citations
- Intent-aware Fuzzing for Android Hardened ApplicationSeongyun Jeong, Minseong Choi, Haehyun Cho, Seokwoo Choi et al.CCS 2025 · 1 citation
Builds on10
- MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral ModelsEnrico Mariconti, Lucky Onwuzurike, Panagiotis Andriotis, Emiliano De Cristofaro et al.NDSS 2017 · 471 citations
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder et al.USENIX Security 2019 · 441 citations
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 253 citations
- Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android MalwareXiaohan Zhang, Yuan Zhang, Ming Zhong, Daizong Ding et al.CCS 2020 · 173 citations
- TriggerScope: Towards Detecting Logic Bombs in Android ApplicationsYanick Fratantonio, Antonio Bianchi, William K. Robertson, Engin Kirda et al.S&P 2016 · 161 citations
Related papers
- Automated Synthesis of Semantic Malware Signatures using Maximum SatisfiabilityYu Feng, Osbert Bastani, Ruben Martins, Isil Dillig et al.NDSS 2017 · 104 citations
- LAMDA: A Longitudinal Android Malware Benchmark for Concept Drift AnalysisMd Ahsanul Haque, Ismail Hossain, Md Mahmuduzzaman Kamol, Md Jahangir Alam et al.ICLR 2026 · 14 citations
- HomDroid: detecting Android covert malware by social-network homophily analysisYueming Wu, Deqing Zou, Wei Yang, Xiang Li et al.ISSTA 2021 · 22 citations
- The Illusion of Success: Learning-Based Android Malware Detectors (Replicability Study)Michael Tegegn, Julia RubinISSTA 2026
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin et al.NDSS 2018 · 87 citations
