Android Hooking Revisited

Nikolaos Totosis, Constantinos Patsakis · 2018

Android malware is continuously growing in terms of numbers and evolving in terms of evasion techniques as well as scope and methods to penetrate. To address these threats many approaches have been proposed leading to an arms race between malware and analysts. Trying to dissect a malware is by no means an easy task as benign code is coupled with malicious one, which in turn might be obfuscated etc. All the above clearly hinder the analysis, therefore, dynamic analysis often comes to the rescue. Nonetheless, since malware often manage to detect it, they stop their activity, preventing their analysis. To break this loop hooking methods can be used, yet their majority either depends on modified environments or they cannot provide a lot of functionality to the analyst. In this work we introduce Ronin which facilitates app analysis by allowing the analyst to easily create hooks in apps in stock Android devices. This way, the underlying mechanisms can be easier understood and modified to analyse an app in more depth.

Read the paper · More papers on PaperTik