Home / Solutions / App security & malware analysis
Solution · Malware analysis & threat intel

Android malware analysis sandbox with automated C2 recovery.

Anti-analysis is standard in modern mobile malware: a sample that spots an emulator doesn't crash — it behaves, and your report says "benign". Privara Unmask detonates the sample on a device it can't tell is virtual, drives it past its activation gates, and recovers the command-and-control automatically. You get the real behaviour and the indicators — not the polite version.

The false-negative problem

A dynamic-analysis run that comes back clean is only useful if the sample was actually trying. Modern Android malware routinely checks a long list of environment signals before it does anything interesting: ro.kernel.qemu and friends, /dev/goldfish* and QEMU pipe devices, emulator-shaped build fingerprints, a GPU string no phone has ever reported, four CPU cores where a flagship has eight, sensors that return the same value forever, and an x86 CPU under an app that shipped arm64.

Each one is cheap to check and decisive. The result is a queue of samples marked benign that are anything but — and the same problem shows up in AppSec work, where a hardened client-side SDK refuses to run so the assessment stalls before it starts.

Meet Privara Unmask

Privara Unmask is the automated analysis engine that runs on top of a de-emulated Android 17 (API 37) device. You submit an APK (single or split); it does the rest and hands back a structured report with ranked C2 candidates, extracted config, a stage tree, and copy-paste IOCs.

Detonate what actually runs

Environment checks come back looking like a real handset, so anti-analysis logic takes the branch you need to see — no "benign" false negative.

Drives past activation gates

Works samples past accessibility-service, locale/region, target-app-installed, SMS/OTP and push triggers that keep them dormant in ordinary sandboxes.

Unpacks packed & dropper malware

Recovers in-memory and dropped second-stage payloads from packed and dropper families, then analyses the real code — not just the loader stub.

Automated C2 & IOC extraction

Recovers command-and-control endpoints, dead-drop resolvers and config from the running sample, ranked by evidence, with STIX/MISP-ready output.

arm64 samples, x86 hardware

Built-in ARM translation runs arm64-v8a native libraries on ordinary cloud CPUs — no ARM server fleet to buy or maintain.

Root for instrumentation, hidden from the target

Instrument freely while the app under test sees an unrooted device and common root detectors report clean.

Clean device per sample

Reproducible instances from a signed golden image. Roll back between samples so nothing carries over into the next analysis.

Network you control

Each device has its own egress and configurable location for traffic capture, C2 observation, and region-gated behaviour.

Proven on real banking trojans

Unmask has been run against a corpus of modern Android banking trojans and RATs sourced from MalwareBazaar, recovering command-and-control indicators from the majority — and we publish each analysis and contribute the indicators to the abuse.ch ThreatFox community feed under our verified account. This is checkable intelligence, not a claim: read the per-family write-ups.

Hook ERMAC TrickMo Godfather BingoMod Fluhorse SoumniBot Coper Cerberus Mamont Brokewell
Read the threat research → Our ThreatFox contributor profile

Passive TLS Recovery — read encrypted C2 without breaking TLS

Endpoints and SNI aren't enough when the payload is encrypted. Privara recovers the sample's TLS session keys straight from device memory at the hypervisor layer and hands you a standard keylog next to the packet capture — so the same pcap becomes readable C2.

This is passive key recovery, not "SSL inspection" — MITM is exactly the thing it avoids.

A device the sample can't tell is virtual

The reason all of the above works is the environment underneath it. The emulator signatures are removed rather than papered over: the device presents a realistic flagship profile with eight cores and a modern GPU, sensors carry live motion instead of constants, kernel and property tells are gone, and arm64 native code runs on commodity x86. We don't publish how the de-emulation is built — that's the moat — but the effect is measurable: software-based emulator and root detection reports a real handset.

Beyond malware: everyday AppSec work

Acceptable use. Licensed B2B to KYC-verified organisations under an acceptable-use policy: analyse and test only apps you own, are authorised to assess, or are handling as part of legitimate security research and incident response. Not sold for fraud, fake-account creation, ad fraud, or ban evasion.

What it doesn't do

It is not a hardware-attestation bypass. The strong and device verdicts in Play Integrity are anchored in a physical secure element, and no virtual machine has one — a sample or app that hard-requires hardware attestation still needs a physical handset. Privara defeats software-based emulator and root detection, which is the layer nearly all anti-analysis code actually relies on. It also isn't a static-analysis product; it's the runtime environment and automated engine your existing tooling drives. And we report honestly: a recovered C2 identity from a dead/offline sample is labelled as such, and environmental noise is excluded rather than reported as a finding.

Bring a sample that goes quiet

The fastest evaluation is an APK your current sandbox reports as clean. We'll run it on a live Privara Unmask instance and you can see whether it behaves differently — and what C2 it gives up.

Request a demo →