Security researchers have identified significant risks stemming from both legitimate and malicious Android applications due to insecure or outdated embedded components. One report highlights that thousands of popular Android apps, including those in travel, weather, and airline categories, still contain the deprecated libmapbox-gl.so library, which statically links to an outdated and vulnerable version of SQLite (3.24.0). This exposes users and enterprises to threats such as credential theft, data exfiltration, and denial-of-service attacks, especially in BYOD environments where employees may unknowingly install these apps on corporate devices.
Separately, advanced malicious Android apps are employing sophisticated evasion techniques to bypass antivirus detection. These apps use strong packing and obfuscation, multi-stage payload delivery, and custom package installers to avoid analysis and facilitate the installation of additional malicious components. The malicious behaviors include information theft and coin mining, with payloads often hidden in encrypted files or triggered only under specific conditions, making detection and remediation more challenging for security teams.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC published an analysis report on malicious apps using advanced detection and evasion techniques, indicating new technical details about Android malware behavior. No more specific event date is available from the reference, so the publication date is used.
Zimperium published a blog post titled "Follow the Map to Enterprise Risk: What’s Inside Popular Android Apps," describing security risks associated with widely used Android applications. No more specific event date is available from the reference, so the publication date is used.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.