Analysis and detection of android stegomalware: the impact of the loading stage

Soi, Diego;Sanna, Silvia Lucia
;
Regano, Leonardo;Giacinto, Giorgio
2025-01-01

Abstract

Due to the increasing use of advanced offensive techniques, the mitigation of Android malware is an urgent need. An emerging attack trend exploits steganography to conceal malicious payloads within applications to make attacks stealthier. Even if works on “stegomalware” are starting to emerge, they primarily focus on the multimedia part of the attack chain, i.e., on how to detect hidden data in images or videos. Therefore, this work aims at understanding whether the loading stage required for the extraction of cloaked information can generate detection signatures. To this aim, we develop a proof-of-concept implementation, which has been repacked within a real Android application and tested against several malware detection engines provided by VirusTotal. To anticipate possible offensive campaigns, we also performed tests by considering threat actors able to obfuscate the bytecode of the loader or the entire APK. Results indicate that standard tools are not ready to face stegomalware targeting Android applications. Therefore, we provide indications on how to improve forensics and attribution phases for Android malware endowed with information hiding capabilities.
2025
Inglese
IH&MMSEC '25: Proceedings of the ACM Workshop on Information Hiding and Multimedia Security
979-8-4007-1887-8
ACM
New York
STATI UNITI D'AMERICA
Shruti Agarwal, Scott Craver, Shan Jia,Chau-Wai Wong, Benedetta Tondi
35
45
11
https://dl.acm.org/doi/10.1145/3733102.3733122
ACM Workshop on Information Hiding and Multimedia Security
Comitato scientifico
18-20 Giugno 2025
San Jose (CA, USA)
internazionale
scientifica
Information Hiding; Stegomalware; Mobile Security; Android
no
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Soi, Diego; Sanna, Silvia Lucia; Benedetti, Giacomo; Liguori, Angelica; Regano, Leonardo; Caviglione, Luca; Giacinto, Giorgio
273
7
4.1 Contributo in Atti di convegno
open
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
3733102.3733122.pdf

open access

Description: VoR
Type: versione editoriale
Size 712 kB
Format Adobe PDF
712 kB Adobe PDF View/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie