AndroWasm: an Empirical Study on Android Malware Obfuscation through WebAssembly

Diego Soi
;
Silvia Lucia Sanna;Lorenzo Pisu;Leonardo Regano;Giorgio Giacinto
2026-01-01

Abstract

In recent years, stealthy Android malware has increasingly adopted sophisticated techniques to bypass automatic detection mechanisms and harden manual analysis. Adversaries typically rely on obfuscation, anti-repacking, steganography, poisoning, and evasion techniques to AI-based tools, and in-memory execution to conceal malicious functionality. In this paper, we investigate WebAssembly (Wasm) as a novel technique for hiding malicious payloads and evading traditional static analysis and signature-matching mechanisms. While Wasm is typically employed to render specific gaming activities and interact with the native components in web browsers, we provide an in-depth analysis on the mechanisms Android may employ to include Wasm modules in its execution pipeline. Additionally, we provide Proofs-of-Concept to demonstrate a threat model in which an attacker embeds and executes malicious routines, effectively bypassing IoC detection by industrial state-of-the-art tools, like VirusTotal and MobSF.
2026
Inglese
Proceedings of the Joint National Conference on Cybersecurity (ITASEC & SERICS 2026)
4198
20
https://ceur-ws.org/Vol-4198/paper36.pdf
Joint National Conference on Cybersecurity (ITASEC & SERICS 2026)
Comitato scientifico
9-13 Febbraio 2026
Cagliari
nazionale
scientifica
Android, WebAssembly, Obfuscation, Malware
no
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Soi, Diego; Sanna, Silvia Lucia; Pisu, Lorenzo; Regano, Leonardo; Giacinto, Giorgio
273
5
4.1 Contributo in Atti di convegno
open
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
paper36.pdf

open access

Size 1.44 MB
Format Adobe PDF
1.44 MB Adobe PDF View/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie