In the interest of sharing VB2014 conference papers and presentations the editor ofVirus Bulletin magazine has blogged about Gregory Panakkal’s paper titled “Leaving our ZIP undone: How to Abuse ZIP to Deliver Malware Apps” on VB’s information portal on recent security trends.
This paper explores the ZIP file format, specifically as an APK as handled by the Android OS and details the new malformations that can be imposed on the APK file format to bypass AV engine unarchiving and scanning, whilst keeping the APK valid for the Android OS. This paper also describes the concept of a “chameleon ZIP” that is application specific, and the challenges for the AV engine components that scan
A Chameleon Zip Example
Archana Sangili, Content Writer
If you wish to subscribe to our blog, please add the URL provided below to your blog reader: https://labs.k7computing.com/feed/