Uncovering Automatic Obfuscation-as-a-Service for Malicious Android Applications

Sembera, V., Paquet-Clouston, M., Garcia, S., & Erquiaga, M. J. (2021). Uncovering automatic obfuscation-as-a-service for malicious Android applications.

Abstract

This research provides the first overview of such automatic service, which takes advantage of the whole malware-as-aservice industry, providing medium quality obfuscation for the Android malware market. Although the technical obfuscations are not state-of-the-art, the service succeeds in reducing detection for malicious Android applications. We conclude that the active use of the service highlights the need for the malware market to develop better obfuscation techniques, hence the good job that the security community is doing at quickly detecting changing malware. We also conclude that this service seemed to generate enough revenue for the group, given its automatic nature and purpose. Given that automatic services like this may be a greater problem in the future of malware obfuscation, this research provides a first technical analysis of the details of such obfuscation service and the possible impact in detection results.

Read more: https://vblocalhost.com/uploads/VB2021-Sembera-etal-updated.pdf