Konfety returns with new tricks to threaten Android users
A new variant of the Konfety malware is attacking Android devices with ultra-sophisticated techniques, bypassing security software and putting millions of people at risk.
Báo Khoa học và Đời sống•25/07/2025
The new variant of Konfety malware is giving Android security experts a headache because of its unprecedented sophistication. According to zLabs, Konfety tampered with APK files by modifying data flags and compression methods, making it undetectable by analysis tools.
Files are declared as encrypted even though nothing is actually encrypted, causing processing errors or system crashes. In addition to simulating APK files, Konfety also uses the "dual application" trick to deceive users and bypass the app store.
One clean version of the app is uploaded to the official repository, while the other version containing malicious code is distributed outside. Once installed, the malicious app hides its icon to avoid detection and automatically triggers a chain of malicious actions. They constantly open browsers, push junk ads, install strange apps, and lead users to fraudulent websites.
Experts warn Android users not to install apps from untrusted sources and to update security software regularly. Dear readers, please watch more videos : The "borrowing face" trick of the gambling and money laundering ring worth thousands of billions of dong | VTV24
Comment (0)