The Droid is in the Details: Environment-aware Evasion of Android Sandboxes
Brian Kondracki, Babak Amin Azad, Najmeh Miramirkhani, Nick Nikiforakis
Abstract
—Malware sandboxes have long been a valuable tool for detecting and analyzing malicious software. The proliferation of mobile devices and, subsequently, mobile applications, has led to a surge in the development and use of mobile device sandboxes to ensure the integrity of application marketplaces. In turn, to evade these sandboxes, malware has evolved to suspend its malicious activity when it is executed in a sandbox environment. Sophisticated malware sandboxes attempt to prevent sandbox detection by patching runtime properties indicative of malware-analysis systems. In this paper, we propose a set of novel mobile-sandbox-evasion techniques that we collectively refer to as “environment-aware” sandbox detection. We explore the distribution of artifacts extracted from readily available APIs in order to distinguish real user devices from sandboxes. To that end, we identify Android APIs that can be used to extract environment-related features, such as artifacts of user configurations (e.g. screen brightness), population of files on the device (e.g. number of photos and songs), and hardware sensors (e.g. presence of a step counter). By collecting ground truth data from real users and Android sandboxes, we show that attackers can straightforwardly build a classifier capable of differentiating between real Android devices and well-known mobile sandboxes with 98.54% accuracy. More-over, to demonstrate the inefficacy of patching APIs in sandbox environments individually, we focus on feature inconsistencies between the claimed manufacturer of a sandbox (Samsung, LG, etc.) and real devices from these manufacturers. Our findings emphasize the difficulty of creating robust sandbox environments regardless of their underlying platform being an emulated environment, or an actual mobile device.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cba4bd83-266f-4d69-855d-12c1e53b3252Cited by top-tier papers7
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Sifter: protecting security-critical kernel modules in Android through attack surface reductionHsin-Wei Hung, Yingtong Liu, Ardalan Amiri SaniMobiCom 2022 · 6 citations
- When Ad Networks Misbehave: Understanding Risks of Semi-Drive-By Splash AdsSong Wu, Bo Wang, Yifan Zhang, Yinfeng Cao et al.CCS 2026
- Threat2Traffic: Multi-Agent Environment Synthesis for Malware Traffic Generation from Threat IntelligenceHaoyang Chen, Chang Liu, Zhong Guan, Junzheng Shi et al.ICML 2026
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi et al.USENIX Security 2026
Builds on4
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder et al.USENIX Security 2019 · 441 citations
- Spotless Sandboxes: Evading Malware Analysis Systems Using Wear-and-Tear ArtifactsNajmeh Miramirkhani, Mahathi Priya Appini, Nick Nikiforakis, Michalis PolychronakisS&P 2017 · 134 citations
- An Analysis of Pre-installed Android SoftwareJulien Gamba, Mohammed Rashed, Abbas Razaghpanah, Juan Tapiador et al.S&P 2020 · 105 citations
- Does Every Second Count? Time-based Evolution of Malware Behavior in SandboxesAlexander Küchler, Alessandro Mantovani, Yufei Han, Leyla Bilge et al.NDSS 2021
Related papers
- Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based VirtualizationWenna Song, Jiang Ming, Lin Jiang, Yi Xiang et al.CCS 2021 · 11 citations
- Preventing and Detecting State Inference Attacks on AndroidAndrea Possemato, Dario Nisi, Yanick FratantonioNDSS 2021
- Uncovering Cross-Context Inconsistent Access Control Enforcement in AndroidHao Zhou, Haoyu Wang, Xiapu Luo, Ting Chen et al.NDSS 2022
- Rotten Apples Spoil the Bunch: An Anatomy of Google Play MalwareMichael Cao, Khaled Ahmed, Julia RubinICSE 2022 · 13 citations
- Detecting Android Root Exploits by Learning from Root ProvidersIoannis Gasparis, Zhiyun Qian, Chengyu Song, Srikanth V. KrishnamurthyUSENIX Security 2017 · 27 citations
