Reverse Engineering Android Malware With Jadx
Overview
Cybersecurity skill for reverse engineering android malware with jadx. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"reverse engineering android malware with jadx"
"reverseing engineering android malware with jadx"
"Reverse engineers malicious Android APK files using JADX decompiler to analyze J"
A suspicious Android APK has been reported as malicious or flagged by mobile threat detection
Analyzing Android banking trojans, spyware, SMS stealers, or adware samples
Determining what data an app collects, where it sends it, and what permissions it abuses
Extracting C2 server addresses, encryption keys, and configuration data from Android malware
Understanding overlay attack mechanisms used by banking trojans
Do not use for analyzing obfuscated native (.so) libraries within APKs; use Ghidra or IDA for native ARM binary analysis.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- JADX 1.5+ installed (download from https://github.com/skylot/jadx/releases)
- Android SDK with
aapt2 and adb tools for APK inspection
- apktool for full APK disassembly including smali code and resources
- Python 3.8+ with
androguard library for automated APK analysis
- Frida for dynamic instrumentation (optional, for runtime analysis)
- Isolated Android emulator (Genymotion or Android Studio AVD) without Google services
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for engineering android malware.
- Gather Resources — Collect tools, data, and access needed for engineering android malware.
- Execute Process — Carry out engineering android malware operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- jadx — Primary tool for this skill
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: reverse-engineering-android-malware-with-jadx3description: Use when reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis. '.4license: Apache-2.05---67# Reverse Engineering Android Malware With Jadx89## Overview1011Cybersecurity skill for reverse engineering android malware with jadx. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "reverse engineering android malware with jadx"16- "reverseing engineering android malware with jadx"17- "Reverse engineers malicious Android APK files using JADX decompiler to analyze J"181920- A suspicious Android APK has been reported as malicious or flagged by mobile threat detection21- Analyzing Android banking trojans, spyware, SMS stealers, or adware samples22- Determining what data an app collects, where it sends it, and what permissions it abuses23- Extracting C2 server addresses, encryption keys, and configuration data from Android malware24- Understanding overlay attack mechanisms used by banking trojans2526**Do not use** for analyzing obfuscated native (.so) libraries within APKs; use Ghidra or IDA for native ARM binary analysis.272829## When NOT to Use3031- When you lack proper authorization for testing32- For production systems without change management33- When the task requires legal or compliance expertise beyond technical scope343536## Prerequisites3738- JADX 1.5+ installed (download from https://github.com/skylot/jadx/releases)39- Android SDK with `aapt2` and `adb` tools for APK inspection40- apktool for full APK disassembly including smali code and resources41- Python 3.8+ with `androguard` library for automated APK analysis42- Frida for dynamic instrumentation (optional, for runtime analysis)43- Isolated Android emulator (Genymotion or Android Studio AVD) without Google services4445## Workflow4647```python48# Example: IOC detection49import re5051IOC_PATTERNS = {52 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",53 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",54 "hash_md5": r"\b[a-f0-9]{32}\b",55 "hash_sha256": r"\b[a-f0-9]{64}\b",56}5758def extract_iocs(text: str) -> dict:59 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}60```61621. **Define Objectives** — Clarify the goals and scope for engineering android malware.632. **Gather Resources** — Collect tools, data, and access needed for engineering android malware.643. **Execute Process** — Carry out engineering android malware operations methodically.654. **Verify Quality** — Check results against acceptance criteria.665. **Document Outcomes** — Record findings, decisions, and next steps.6768## Tools6970- **jadx** — Primary tool for this skill71- **Analysis Platform** — Data processing and visualization72- **Collaboration Tools** — Team coordination and knowledge sharing737475## Process76771. **Reconnaissance** — Gather target information, identify attack surface, enumerate services781. **Analysis/Exploitation** — Execute the technique, analyze results, document findings791. **Reporting** — Document IOCs, write findings, provide remediation recommendations8081## Verification8283- [ ] All engineering android malware procedures executed completely and documented84- [ ] Findings validated against multiple data sources85- [ ] False positives identified and filtered86- [ ] Results documented with evidence and timestamps87- [ ] Recommendations provided with risk-based prioritization8889## Anti-Rationalization Table9091| Rationalization | Reality |92|---|---|93| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |94| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |95| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |