ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Mobile Security

New Mandrake Android Malware Variant Evades Detection on Google Play

Sophisticated Cyber-Espionage Tool Lurked Undetected for Years

Kyle by Kyle
July 29, 2024
in Mobile Security
Reading Time: 2 mins read
Photo of the Google play store card which is hosting the Mandrake Android malware
Share on FacebookShare on Twitter

Security researchers have uncovered a new iteration of Mandrake, a highly advanced Android malware designed for cyber espionage. This latest variant, discovered in April 2024 by Kaspersky, showcases significant improvements in obfuscation and evasion techniques, allowing it to remain undetected on Google Play for up to two years.

Evolution of Mandrake

Mandrake first came to light in May 2020 when Bitdefender analyzed its operations, revealing that it had been active for at least four years. The newly discovered version, detailed in a recent Kaspersky advisory, demonstrates the malware’s continued evolution and the threat actors’ adaptability.

Infiltration of Google Play

The updated Mandrake samples were found hidden within five applications on Google Play, accumulating over 32,000 downloads between 2022 and 2024. The most popular app, AirFS, garnered more than 30,000 installations before its removal in March 2024. This prolonged presence on the official Android app store highlights the sophisticated nature of the malware and the challenges faced by security measures.

You might also like

How Hackers Still Manage to Compromise MFA

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

Enhanced Obfuscation and Evasion Tactics

Key improvements in the latest Mandrake variant include:

  • Relocation of malicious functions to obfuscated native libraries
  • Implementation of certificate pinning for secure C2 communications
  • Deployment of various tests to avoid detection on rooted or emulated devices

These enhancements make it significantly more difficult for cybersecurity experts to detect and analyze the malware.

Multi-Stage Infection Chain

The new Mandrake version employs a sophisticated multi-stage infection process:

  1. Initial malicious activity is concealed within a native library
  2. The first-stage library decrypts and loads the second-stage
  3. The second stage initiates communication with the command-and-control (C2) server
  4. If deemed relevant, the C2 server instructs the device to download and execute the core malware

The core malware is designed to steal user credentials and deploy additional malicious applications, expanding its reach and potential for damage.

Advanced Evasion Techniques

Mandrake’s evasion capabilities have become increasingly sophisticated, incorporating:

  • Checks for emulation environments
  • Detection of rooted devices
  • Identification of analyst tools

These improvements pose significant challenges for cybersecurity professionals attempting to detect and analyze the malware.

Novel Encryption Approach

The threat actors behind Mandrake have also implemented a unique approach to data encryption and decryption, utilizing a combination of custom algorithms and standard AES encryption. This hybrid method further complicates efforts to understand and mitigate the malware’s operations.

Implications for Android Security

The prolonged presence of Mandrake on Google Play underscores the ongoing cat-and-mouse game between malware developers and security measures. As Kaspersky notes, “The Mandrake spyware is evolving dynamically, improving its methods of concealment, sandbox evasion, and bypassing new defense mechanisms.”

This case highlights that stricter controls for applications before publication in official marketplaces may inadvertently lead to developing more sophisticated, harder-to-detect threats. The cybersecurity community and app store operators must remain vigilant and continue to adapt their detection and prevention strategies to combat these evolving threats.

Protecting Against Mandrake and Similar Threats

While Google Play’s security measures continue to improve, users should take additional precautions:

  1. Regularly update devices and applications
  2. Be cautious when granting permissions to new apps
  3. Use reputable mobile security solutions
  4. Avoid downloading apps from unofficial sources

By staying informed and implementing these best practices, Android users can better protect themselves against sophisticated malware like Mandrake and other emerging cybersecurity threats.

Tags: google play
Previous Post

What is this Dolphin Hacking Tool Everyone is Talking About?

Next Post

DigiCert’s Certificate Revocation Crisis: Thousands of Customers Affected

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Discover how the BadBox botnet infects 190,000+ Android devices, compromising smart TVs and smartphones across multiple countries with dangerous malware.

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

September 16, 2024

Cybercriminals Target Mobile Users in the Czech Republic with Phishing Campaigns Leveraging Progressive Web Applications

August 20, 2024

LianSpy: New Android Spyware Targeting Russian Users

August 7, 2024

Exposing the Dark Web Scam: Fake Pegasus Spyware Code Sold for Millions

May 28, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.