VAHunt: Warding Off New Repackaged Android Malware in App-Virtualization's Clothing
Luman Shi, Jiang Ming, Jianming Fu, Guojun Peng, Dongpeng Xu, Kun Gao, Xuanchen Pan
摘要
Repackaging popular benign apps with malicious payload used to be the most common way to spread Android malware. Nevertheless, since 2016, we have observed an alarming new trend to Android ecosystem: a growing number of Android malware samples abuse recent app-virtualization innovation as a new distribution channel. App-virtualization enables a user to run multiple copies of the same app on a single device, and tens of millions of users are enjoying this convenience. However, cybercriminals repackage various malicious APK files as plugins into an app-virtualization platform, which is flexible to launch arbitrary plugins without the hassle of installation. This new style of repackaging gains the ability to bypass anti-malware scanners by hiding the grafted malicious payload in plugins, and it also defies the basic premise embodied by existing repackaged app detection solutions. As app-virtualization-based apps are not necessarily malware, in this paper, we aim to make a verdict on them prior to run time. Our in-depth study results in two key observations: 1) the proxy layer between plugin apps and the Android framework is the core of app-virtualization mechanism, and it reveals the feature of finite state transitions; 2) malware typically loads plugins stealthily and hides malicious behaviors. These insights motivate us to develop a two-layer detection approach, called VAHunt. First, we design a stateful detection model to identify the existence of an app-virtualization engine in APK files. Second, we perform data flow analysis to extract fingerprinting features to differentiate between malicious and benign loading strategies. Since October 2019, we have tested VAHunt in Antiy AVL Mobile Security, a leading mobile security company, to detect more than 139K app-virtualization-based samples. Compared with the ground truth, VAHunt achieves 0.7% false negatives and zero false positive. Our automated detection frees security analysts from the burden of reverse engineering.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper5
- Structural Attack against Graph Based Android Malware DetectionKaifa Zhao, Hao Zhou, Yulin Zhu, Xian Zhan 等CCS 2021 · 被引用 48 次
- Rotten Apples Spoil the Bunch: An Anatomy of Google Play MalwareMichael Cao, Khaled Ahmed, Julia RubinICSE 2022 · 被引用 13 次
- Cracks in the Walled Garden: Dissecting the Gray-Market of Unauthorized iOS App Distribution via Ad Hoc SideloadingYijing Liu, Yiming Zhang, Baojun Liu, Haixin DuanUSENIX Security 2026
- Understanding Miniapp Malware: Identification, Dissection, and CharacterizationYuqing Yang, Yue Zhang, Zhiqiang LinNDSS 2025
- Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile AppsFannv He, Yan Jia, Jiayu Zhao, Yue Fang 等NDSS 2024
相关 Paper
- Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based VirtualizationWenna Song, Jiang Ming, Lin Jiang, Yi Xiang 等CCS 2021 · 被引用 11 次
- VMHunt: A Verifiable Approach to Partially-Virtualized Binary Code SimplificationDongpeng Xu, Jiang Ming, Yu Fu, Dinghao WuCCS 2018 · 被引用 60 次
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin 等NDSS 2018 · 被引用 87 次
- Careful About What App Promotion Ads Recommend! Detecting and Explaining Malware Promotion via App Promotion GraphShang Ma, Chaoran Chen, Shao Yang, Shifu Hou 等NDSS 2025
- HomDroid: detecting Android covert malware by social-network homophily analysisYueming Wu, Deqing Zou, Wei Yang, Xiang Li 等ISSTA 2021 · 被引用 22 次
