Nullcon Goa 2023 | Android-SigMorph: Covert Communication Exploiting Android Signing Schemes
About this talk
This talk explores the intricacies of Android binaries, focusing on Signature Schemes (v1, v2, v3) used in Android APKs and the potential misuse of their vulnerabilities. The speaker demonstrates how to modify an Android APK binary without invalidating its signature, highlighting both malicious and non-malicious use cases. A significant point of discussion includes how malicious data can evade detection by antivirus systems when embedded in legitimate applications downloaded from the Play Store, all while maintaining the signing signature. The session also examines techniques for creating variations of malware, citing the Pegasus malware as a key example.
More from this event
See all 25 talks →
Nullcon Goa 2023 | Aftermovie
2:10
Nullcon Goa 2023 | Keynote: Multiplying Threat Intelligence by John Lambert
33:51
Nullcon Goa 2023 | Smashing The State Machine: The True Potential Of Web Race Conditions by James
43:52
Nullcon Goa 2023 | How I Hacked Your Bank Account: A Detailed Look At UPI Security by Nemo
21:08