| name | reverse-engineering-android-malware-with-jadx |
| description | Use when reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests involving Android malware analysis, APK reverse engineering, mobile malware investigation, or Android threat analysis.
'. |
| domain | cybersecurity |
| tags | ["malware","Android","reverse-engineering","JADX","mobile-malware"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Reverse Engineering Android Malware With Jadx
Overview
Cybersecurity skill for reverse engineering android malware with jadx. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"reverse engineering android malware with jadx"
-
"reverseing engineering android malware with jadx"
-
"Reverse engineers malicious Android APK files using JADX decompiler to analyze J"
-
A suspicious Android APK has been reported as malicious or flagged by mobile threat detection
-
Analyzing Android banking trojans, spyware, SMS stealers, or adware samples
-
Determining what data an app collects, where it sends it, and what permissions it abuses
-
Extracting C2 server addresses, encryption keys, and configuration data from Android malware
-
Understanding overlay attack mechanisms used by banking trojans
Do not use for analyzing obfuscated native (.so) libraries within APKs; use Ghidra or IDA for native ARM binary analysis.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- JADX 1.5+ installed (download from https://github.com/skylot/jadx/releases)
- Android SDK with
aapt2 and adb tools for APK inspection
- apktool for full APK disassembly including smali code and resources
- Python 3.8+ with
androguard library for automated APK analysis
- Frida for dynamic instrumentation (optional, for runtime analysis)
- Isolated Android emulator (Genymotion or Android Studio AVD) without Google services
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": ,
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}