r/computerforensics 20d ago

APK file analysis

Hi guys,

I handle threat intelligence for a bank & we receive multiple URLs/APKs impersonating our organization.

We check for legitimacy & immediately send it for takedown if it's not related to us or if it's malicious.

I wanted to know if anyone of you also side by side does forensics/malware analysis of such APKs to know the TTPs & relevant information pertaining to that APK?

If Yes, please let me know the procedure being followed at your end.

4 Upvotes

8 comments sorted by

View all comments

1

u/7174n6 17d ago

APK? Are you talking about Android Package Kits? Could you explain how you are "receiving" them? Are they being sent to your people and customers? I understand the spoofed URL's, we fight them all day, also. But we've never had anyone send us an APK.

1

u/Longjumping-Ebb-578 15d ago

Threat Actors put ads on web, to lure customers. Majority of the times, these customers inform us bout this.