Kato Collects UI data from apps. Sends UI data to AMS. Transfers data between processes. AMSとデータ送受信可能な抽象クラス An abstract class that interacts with AMS. 17
Dropper: Payloadを対象端末に配置及び実行するアプリ An app that deploys and runs payloads on target devices. DCL(Dynamic Code Loading): 元々存在しないコードを後で外部から取得して実行する仕組み A mechanism allows apps to fetch and run external code that was not implemented in an app. Haruto Kato 23
the stages of an attack, from reconnaissance through actions on objectives. C2 Server: マルウェアに対し指示をするサーバ It gives instructions to malware. Haruto Kato 24
Static analysis : Threat actors abuse the behavioral gap between general analysis tools and analysis implementations of ART. The analysis implementations of ART are called when users install an app. Haruto Kato 29
analysis tools : If they detect incorrect formats, they throw errors and exit. ART: 不正な形式を検出した場合Central Directoryを正として続行 If ART detects incorrect formats, it continues analysis processes and relies on the Central Directory. Source : https://unit42.paloaltonetworks.com/apk-badpack-malware-tampered-headers Haruto Kato 33
fail in the Play Store's static analysis. ARTの静的解析では成功するためインストール可能 Since ART's static analysis succeeds, the app can still be installed on the device. Haruto Kato 34
検出されたのは事実 Google has not disclosed how they handle static analysis failures. However, malware exploiting the gap was found in PlayStore. Source : https://www.malwarebytes.com/blog/news/2025/08/77-malicious-apps-removed-from-go ogle-play-store Haruto Kato 35
そのため、Googleが動的解析で見つけるのは困難 Dynamic analysis : Since apps under review are just droppers, they are benign at this stage. After passing the review, they interact with C2 servers. Therefore, it is extremely difficult to detect malware via dynamic analysis. Haruto Kato 36
psychology: To enable a11y settings, threat actors present messages such as “please grant this permission to optimize your settings” to users. Less tech-savvy users may follow the instructions. Haruto Kato 38
be executed without implementing it in the app. 攻撃者はこの特性を利用してDEXデータでPayloadを注入 Threat actors abuse the feature and inject payloads through DEX data. Haruto Kato 51
apps have the accessibilityDataSensitive attribute. However, reviews of these apps are rigorous. Source : https://support.google.com/googleplay/android-developer/answer/10964491 Haruto Kato 71
of time and effort. If threat actors inject payloads later and get caught, the months they spent waiting go to waste. MFA どうやってユーザーを騙し、そして認証させるか? How to deceive users and make them authenticate? Haruto Kato 83
to mitigate security risks on their own. Therefore, we need to collaborate with other teams such as back-end and product security teams. Haruto Kato 89