{"id":11481,"date":"2025-07-18T12:40:24","date_gmt":"2025-07-18T05:40:24","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11481"},"modified":"2026-06-25T10:00:32","modified_gmt":"2026-06-25T03:00:32","slug":"konfety-new-android-malware-with-apk-and-dynamic-code-evasion-tactics","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/18\/konfety-new-android-malware-with-apk-and-dynamic-code-evasion-tactics\/","title":{"rendered":"Konfety \u2013 New Android Malware with APK and dynamic code evasion tactics"},"content":{"rendered":"<div style=\"text-align: justify\"><b>Recently, a new malware called Konfety was discovered by security researchers, which attracted the attention of the cybersecurity community. It is a sophisticated variant of Android malware, using sophisticated concealment tactics to avoid detection and prevention by common security tools.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1752822471458-png.17335\/\" target=\"_blank\" rel=\"noopener\" data-caption=\"&lt;h4&gt;1752822471458.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;konfety-malware-moi-tren-android-voi-chien-thuat-lan-tranh-qua-apk-va-ma-dong.18578&amp;#x2F;#post-44085&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 18&amp;#x2F;07&amp;#x2F;2025 l\u00fac 2:10 PM&lt;\/a&gt;&lt;\/p&gt;\" data-fancybox=\"lb-thread-18578\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1752822471458.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17670-8ba9a91f9ec0f0c38f1513e539e4aa6b.jpg\" alt=\"1752822471458.png\" width=\"712\" height=\"400\" \/><\/a>\u200b<\/div>\n<div style=\"text-align: justify\">Konfety&#8217;s way of operating is not simply fraudulent advertising but can also pose a major danger to users and businesses if no timely precautions are taken.<\/div>\n<div style=\"text-align: justify\">Konfety&#8217;s sophisticated tactics<\/div>\n<div style=\"text-align: justify\">Konfety operates under the tactic of &#8220;evil twin&#8221;, i.e., using fake apps to trick users. This malware will disguise itself as legitimate apps on Google Play, but in reality it will hide malicious code. When installed, Konfety can perform the following actions:<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Redirect users to harmful websites.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Install unwanted, annoying apps.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Hide malicious ads via the CaramelAds SDK.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Collect personal data, including information about installed applications, system configuration, and geographic location.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1752822486475.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1752822486475-png.17336\/\"><img decoding=\"async\" class=\"bbImage\" title=\"1752822486475.png\" src=\"https:\/\/whitehat.vn\/attachments\/1752822486475-png.17336\/\" alt=\"1752822486475.png\" width=\"728\" height=\"421\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<div style=\"text-align: justify\">Methods of evasion of discovery<\/div>\n<div style=\"text-align: justify\">Konfety&#8217;s speciality lies in his extremely sophisticated strategy of avoiding analysis. To avoid detection, Konfety uses several sophisticated techniques such as:<\/div>\n<ol>\n<li data-xf-list-type=\"ol\">\n<div style=\"text-align: justify\">APK Format Customization: Konfety changed the AP K file structure and used the &#8220;General Purpose Bit&#8221; flag to trick analytic tool. This makes it difficult for tools like APKTool and JADX to extract and analyze malicious code.<\/div>\n<\/li>\n<li data-xf-list-type=\"ol\">\n<div style=\"text-align: justify\">Non-standard BZIP compression: Konfety&#8217;s APK file uses an uncommon compression format, causing analysis tools to crash when attempting to decode.<\/div>\n<\/li>\n<li data-xf-list-type=\"ol\">\n<div style=\"text-align: justify\">Hide app icons: Once installed, Konfety hides the app icon on the home screen, which helps it avoid user attention and reduce the likelihood of being removed.<\/div>\n<\/li>\n<li data-xf-list-type=\"ol\">\n<div style=\"text-align: justify\">Geofencing: Konfety can change its behavior depending on the location of the user, avoiding detection in countries with strict application censorship systems.<\/div>\n<\/li>\n<\/ol>\n<div style=\"text-align: justify\">Attack and distribution methods<\/div>\n<div style=\"text-align: justify\">Unlike traditional malicious codes, Konfety does not appear on the Google Play Store but is usually distributed through third-party app stores or forges popular apps such as browsers, garbage disposals, free VPNs, etc. Users can easily be tricked into downloading these apps without any knowledge of the malicious code inside.<\/div>\n<div style=\"text-align: justify\">Risks and effects<\/div>\n<div style=\"text-align: justify\">Although Konfety has not currently caused serious widespread damage, this software may pave the way for further attacks in the future. Potential risks from Konfety include:<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">System data theft: Includes personal information and sensitive user information.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Corporate impact: If the malicious code device has access to internal systems or important data, it can cause major damage.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Spreading spyware or data encryption tools: Konfety can be used as a platform for downloading spyware or dat encryption tools, thereby demanding ransom.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1752822515273.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1752822515273-png.17337\/\"><img decoding=\"async\" class=\"bbImage\" title=\"1752822515273.png\" src=\"https:\/\/whitehat.vn\/attachments\/1752822515273-png.17337\/\" alt=\"1752822515273.png\" width=\"728\" height=\"380\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<div style=\"text-align: justify\">How to avoid Konfety malicious code<\/div>\n<div style=\"text-align: justify\">To protect themselves from threats such as Konfety, according to WhiteHat experts, personal users and businesses need to take the following precautions:<\/div>\n<div style=\"text-align: justify\">For personal users:<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Do not install an APK from an unknown source, only install the app from the Google Play Store or official source: Avoid downloading apps from websites of unknown origin.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Turn on Play Protect and use mobile AV to detect distorted APKs and runtime malware.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Double check the permissions requirements when installing the app: Make sure the app does not require unnecessary permissions.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Regularly update your operating system and security software: To protect your device from the latest threats.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Block Telegram&#8217;s fraudulent domain using a firewall\/DNS, warn when scanning QR code.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">For business:<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Mobile device monitoring (MDM): Ensuring that devices in the enterprise system are not contaminated with malicious code.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Strict BYOD policy: Ensures that employees who use personal equipment at work must comply with security regulations.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Security Awareness Training for End Users: Helps employees to recognize the risks from malware.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">EDR\/MTD technology integration: For rapid detection and response to terminal threats.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">Konfety malicious code has demonstrated that malware today is increasingly sophisticated and difficult to detect. Protection of devices from these threats requires heightened vigilance from both personal and corporate users. Always be cautious when installing apps, especially from unofficial sources, and maintain strong security measures to protect your device from potential harm.<\/div>\n<div style=\"text-align: right\"><b><i>Synthetic WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/konfety-malware-moi-tren-android-voi-chien-thuat-lan-tranh-qua-apk-va-ma-dong.18578\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/konfety-malware-moi-tren-android-voi-chien-thuat-lan-tranh-qua-apk-va-ma-dong.18578\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Recently, a new malware called Konfety was discovered by security researchers, which attracted the attention of the cybersecurity community. It is a sophisticated variant of Android malware, using sophisticated concealment tactics to avoid detection and prevention by common security tools. \u200b \u200b Konfety&#8217;s way of operating is not simply fraudulent advertising but can also pose [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11481","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11481"}],"version-history":[{"count":1,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11481\/revisions"}],"predecessor-version":[{"id":11482,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11481\/revisions\/11482"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}