Konfety Android Malware: Evasion Techniques and Threat Analysis

Alan V Gutnov
Alan V Gutnov

Director of Strategy

 
July 17, 2025
3 min read

Android Malware Konfety

Android malware Konfety uses malformed APKs to evade detection

Image courtesy of Zimperium

A new variant of the Konfety Android malware has emerged, utilizing a malformed ZIP structure and several obfuscation techniques to evade detection and analysis. This malware masquerades as legitimate applications available on Google Play, despite lacking the intended functionalities of these apps.

Malware Capabilities

The Konfety malware can redirect users to malicious websites, initiate unwanted app installs, and generate fake browser notifications. It harnesses the CaramelAds SDK to display hidden advertisements and exfiltrate sensitive information such as installed applications, network configurations, and system details.

Unwanted ads and redirects triggered by Konfety

Image courtesy of Zimperium

Although Konfety is not classified as spyware or a remote access tool (RAT), it includes an encrypted secondary DEX file within its APK, which is decrypted and executed at runtime. This file contains clandestine services declared in the AndroidManifest file, enabling the malware to install additional modules dynamically.

Evasion Techniques

Researchers at Zimperium identified several methods employed by Konfety to enhance its evasion tactics:

  1. Evil Twin Applications: The malware uses branding and names of legitimate apps to trick users into installing it, often distributed through third-party stores.
  2. Dynamic Code Loading: This technique hides malicious logic in an encrypted DEX file that only gets decrypted and executed during runtime.
  3. Static Analysis Manipulation: Konfety alters APK files to confuse static analysis tools. For example, it sets the General Purpose Bit Flag to signal encryption, triggering false password prompts that delay or block access to the APK contents.

Analysis tools crashing when trying to parse the malicious APK

Image courtesy of Zimperium

  1. APK File Manipulation: Critical files in the APK are declared using unsupported BZIP compression, which is not recognized by many analysis tools, leading to parsing failures. Android's fallback mechanism allows the app to install and run seamlessly on devices.

User Impact

Once installed, Konfety hides its icon and name, employing geofencing to modify its behavior based on the user's location. This malware's ability to redirect users to harmful sites and generate persistent spam notifications poses significant risks to Android users.

Mitigation Strategies

To protect against Konfety and similar threats, it is advisable to:

  • Avoid installing APK files from third-party stores.
  • Enable Google Play Protect on Android devices for malware scanning.
  • Consider additional security measures such as installing reputable Android antivirus applications.

For comprehensive protection against sophisticated malware like Konfety, explore the solutions offered by Gopher Security.

Indicators of Compromise (IOCs)

Zimperium has compiled a list of IOCs for detecting this malware variant. For detailed detection and analysis, refer to the Zimperium repository.


Unsupported Compression Methods in Android Malware

Unsupported Compression Methods Enable Android Malware to Bypass Detection

Image courtesy of Zimperium

Research from Zimperium has revealed that 3,300 Android malware samples utilize unsupported compression methods to evade detection. This technique significantly hampers the ability of decompilation tools to analyze these applications.

Techniques Employed

  1. Unsupported Compression Methods: Android APK files, which are ZIP archives, support only two compression methods: STORED (0x0000) and DEFLATED (0x0008). Malware developers exploit this limitation by using unsupported compression methods, leading to analysis failures in tools like APKTool and JADX.

APKtool

Image courtesy of Zimperium

  1. File Manipulation: Techniques such as long filenames exceeding 256 bytes can cause crashes in analysis tools. Additionally, malformed AndroidManifest.xml files can prevent correct parsing by these tools.
  2. Increased Complexity: Malware authors continuously tweak their applications to avoid detection. Many samples are so corrupted that they cannot be loaded by the Android OS, yet 71 malicious samples were identified that can still be executed.

Protection Against Such Threats

Zimperium's solutions, such as Mobile Threat Defense, provide on-device detection to mitigate risks associated with these sophisticated malware tactics.

For a robust defense against Android malware, consider the offerings from Gopher Security.

Explore our services or contact us for more information on how we can help secure your mobile devices.

Alan V Gutnov
Alan V Gutnov

Director of Strategy

 

MBA-credentialed cybersecurity expert specializing in Post-Quantum Cybersecurity solutions with proven capability to reduce attack surfaces by 90%.

Related News

New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats
Harvest Now Decrypt Later threat

New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats

Discover why the 'Harvest Now, Decrypt Later' threat demands immediate quantum-resistant encryption. Learn how to protect sensitive data from future quantum attacks.

By Alan V Gutnov June 17, 2026 3 min read
common.read_full_article
Critical LangGraph Vulnerability Chain Allows Unauthorized Server Control in AI Agent Frameworks
LangGraph vulnerabilities

Critical LangGraph Vulnerability Chain Allows Unauthorized Server Control in AI Agent Frameworks

Discover how a chain of vulnerabilities in LangGraph allows unauthorized server control. Learn the risks to self-hosted AI agents and how to secure your framework.

By Divyansh Ingle June 16, 2026 4 min read
common.read_full_article
New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats
Harvest Now Decrypt Later threat mitigation

New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats

Are your secrets safe? Learn why 'Harvest Now, Decrypt Later' attacks are a critical threat and how to implement quantum-resistant encryption today.

By Brandon Woo June 15, 2026 5 min read
common.read_full_article
Active Directory Certificate Services Now Supports Post-Quantum Cryptography for Windows Environments
Post-Quantum Cryptography AD CS

Active Directory Certificate Services Now Supports Post-Quantum Cryptography for Windows Environments

Microsoft adds Post-Quantum Cryptography (PQC) to AD CS. Learn how ML-DSA and hybrid key exchanges protect Windows environments against Harvest Now, Decrypt Later.

By Edward Zhou June 12, 2026 4 min read
common.read_full_article