A study by cybersecurity firm Zimperium has found that a new type of Android malware skillfully hides itself from antivirus software using an unusual technique for anti-analyzing Android Package (APK) files, making it virtually invisible to most antivirus software.
Zimperium found that the malicious files were not affected by decompilation (a process that antivirus programs use to detect suspicious code) and used non-standard or heavily modified compression algorithms. Since this method is not yet known to antivirus software, the malware can disguise itself as a normal application, completely bypassing the smartphone's protection.
A Zimperium report published this week identified 3,300 APK files that use this type of compression. Among them, 71 APK files can successfully be installed and run on Android 9 and older operating systems. Zimperium found no evidence that the apps associated with the detected malicious APK files were ever deployed to the Google Play Store.
According to the company, this indicates that they were distributed in other ways, such as through third-party app stores or through manual installation by the user.
The report also states that while this is disturbing news for Android smartphone owners, users who install apps from unofficial stores are mostly at risk.
In May of this year, the information security company Doctor Web had discovered a malicious software module for Android that can spy on users and transfer their files and data to cybercriminals. The module named SpinOk was found in various applications that were downloaded more than 421 million times.






