Zimperium, the global pioneer in mobile security, announces the discovery of a new, highly evasive variant of the Konfety malware targeting Android devices.

Identified by Zimperium’s zLabs team, this latest version leverages advanced obfuscation and ZIP-level evasion techniques, making it significantly more difficult to detect and analyze than previous iterations.

Konfety malware campaign

The Konfety malware campaign uses a deceptive dual-app strategy—leveraging the same package name for both a benign Play Store app and a malicious version distributed via third-party sources—to trick users and bypass traditional detection methods.

It further evades analysis by tampering with the APK’s structure, including declaring unsupported compression formats and manipulating ZIP headers to confuse security tools.

This isn’t just a recycled threat—it’s a deeply engineered update designed to outsmart analysts and evade automated tools,” said Nico Chiaraviglio, Chief Scientist at Zimperium. “The threat actors are actively modifying their tactics to stay ahead, and Konfety is a prime example of how mobile malware is evolving.”

Alarming tactics

Among the most alarming tactics:

  • Dynamic Code Loading: Malicious code is decrypted and executed only at runtime, hidden from traditional scans.
  • Fake App Behavior: The malware suppresses its icon, mimics legitimate app metadata, and redirects users through ad fraud infrastructure.
  • ZIP-Level Obfuscation: Techniques cause common analysis tools to crash or misinterpret the APK as password-protected or malformed.

Zimperium's analysis

Zimperium's analysis confirmed Konfety leverages the CaramelAds SDK to silently deliver payloads, push persistent spam-like browser notifications, and facilitate fraud.

The campaign uses region-specific behaviors, geofencing European users away from suspicious sites while targeting others more aggressively.

Konfety manipulates Android’s APK ZIP structure in a way that causes popular reverse engineering tools to crash entirely, demonstrating a new level of sophistication in mobile malware evasion.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...