Security News > 2021 > June > Research Shows Many Security Products Fail to Detect Android Malware Variants

A group of academic researchers has created a tool that can be used to clone Android malware and test the resilience of these new variants against anti-malware detection.
Testing against 17 commercial anti-malware engines has shown that half don't detect the clones.
The tool decompiles the APK, carries out the morphing, and then recompiles the modified code and signs the APK. Researchers from the Adana Science and Technology University in Turkey and the National University of Science and Technology in Pakistan worked with a total of 848 samples pertaining to seven Android malware families, namely AnserverBot, BaseBridge, DroidKungFu3, DroidKungFu4, DroidDream, DroidDreamLight, and Geinimi.
They used DroidMorph to generate a total of 1,771 variants of these malware families, and then tested them for detection against 17 anti-malware engines in VirusTotal.
Of these, class morphing had the lowest average detection rate, mainly because it has more variants than all morphing.
"The number of Android malware clones are on the rise and to stop this attack of clones we need to study how these clones are generated. We hope that DroidMorph will be used in future research, to improve Android malware clones analysis and detection, and help stop them," the researchers note.
News URL
Related news
- Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection (source)
- SpyLend Android malware downloaded 100,000 times from Google Play (source)
- Qualcomm pledges 8 years of security updates for Android kit using its chips (YMMV) (source)
- Vo1d malware botnet grows to 1.6 million Android TVs worldwide (source)
- Google's March 2025 Android Security Update Fixes Two Actively Exploited Vulnerabilities (source)
- BadBox malware disrupted on 500K infected Android devices (source)
- Hetty: Open-source HTTP toolkit for security research (source)
- North Korea’s ScarCruft Deploys KoSpy Malware, Spying on Android Users via Fake Utility Apps (source)
- Is Security Human Factors Research Skewed Towards Western Ideas and Habits? (source)
- New Android malware uses Microsoft’s .NET MAUI to evade detection (source)