Learning Android Malware Analysis

Learning Android Malware Analysis

56mIntermediate2019-10-25

Authors

Kristina Balaam

Kristina Balaam

Security Intelligence Engineer at Lookout

Course details

In response to the exponential growth of mobile device use, malicious apps have increased. Yet the industry is lacking professionals capable of identifying and combating these threats. Adding malware analysis to your skill set can help set you apart to employers and clients—and help you keep your users and organization safe. Security intelligence engineer Kristina Balaam introduces the basic tools and techniques needed to detect and dissect malicious Android apps. Learn how to set up your analysis lab, with tools like APKTool, Dex2Jar, and JD-Project, and find malicious apps to deconstruct. Kristina shows how to search the codebase for indicators of malicious activity, and provides a challenge and solution set that allows you to practice your new skills.

Learning objectives
Installing the analysis tools on Mac and Windows
Viewing app resources
Decompiling applications
Analyzing permissions
Spyware types
Exfiltrated data, C2 servers, and strings

Skills covered

Android DevelopmentAndroidMobile DevelopmentIncident ResponseGoogleCybersecurityLearning

Concepts

Introduction

  • Analyzing malicious Android applications
  • What you should know

Setting Up a Malware Analysis Lab

  • An overview of common analysis tools
  • Installing reverse-engineering tools - Mac
  • Installing reverse-engineering tools - PC
  • Finding malicious mobile applications

Decompiling Android Applications

  • What makes an Android application
  • The manifest, classes, and resource files
  • Viewing app resources with APKTool
  • Decompiling the application

Hunting for Malicious Activity

  • Permissions, permissions, permissions
  • What are spyware applications
  • Common malicious functionality
  • Exfiltrated data, C2 servers, and strings
  • Challenge - StealthMango
  • Solution - StealthMango

Conclusion

  • Next steps
40,000 Toman