InstruMate: A Systematic Framework for Assessing Android App Repackaging Resilience
Repackaging is a widely used technique for modifying existing Android applications by introducing targeted changes to their code and resources. Malicious actors exploit it to distribute malware, commit plagiarism, and exfiltrate sensitive data. Although often described as a straightforward process, requiring only that an app be downloaded, decompiled, modified, and redistributed, its practical use in research contexts reveals a more complex reality. Existing work frequently overlooks why certain repackaging attempts fail, as well as the potential impact of repackage-proofing mechanisms embedded within apps. To address this gap, we present InstruMate, a novel approach for systematically assessing the repackaging resilience of Android applications. InstruMate progressively escalates from simple modifications—such as altering the app’s signature—to more complex interventions targeting code instrumentation. Each modified version is rigorously assessed against the original using novel health-check procedures that reveal discrepancies in the user interface and execution behavior. We demonstrate this approach, by evaluating the resilience to repackaging of 156 highly popular apps obtained from the Google Play Store (including WhatsApp Messenger, LinkedIn, Roblox, TikTok, among others), each exceeding one billion installations worldwide. The results reveal that 86% of the analyzed apps are non-resilient to the most basic form of repackaging involving only a signature change; 81% can be modified to enable execution in debug mode; and 83% exhibit no resistance to superficial appearance modifications. Beyond these surface-level changes, more sophisticated transformations using black-box static and dynamic instrumentation show that 65% of the apps remain susceptible to code tampering. In contrast, 11% of the apps in our dataset actively resist repackaging through explicit user warnings or runtime exceptions that abruptly terminate execution. We further trace several of these defenses to specific anti-repackaging mechanisms integrated within the analyzed applications.
Wed 18 MarDisplayed time zone: Athens change
16:00 - 17:30 | Session 3B - Evolution and Security of Mobile SystemsResearch Track / Short Papers and Posters Track at Megaron Beta Chair(s): Vadim Zaytsev University of Twente | ||
16:00 15mTalk | Relocate and Emulate: Re-Hosting Android’s Application Layer Research Track Thomas Sutter University of Bern, Timo Kehrer University of Bern, Marc Rennhard Zurich University of Applied Sciences, Bernhard Tellenbach Armasuisse Cyber-Defence Campus | ||
16:15 15mTalk | Scratching the Iceberg: Unveiling the Outdated Third-Party Native Libraries in Android Apps Research Track Shiyang Zhang Tianjin University, Chengwei Liu Nankai University, Sen Chen Nankai University, Lyuye Zhang Nanyang Technological University, Yang Liu Nanyang Technological University | ||
16:30 15mTalk | Dialing Danger: Large-Scale Mining and Risk Assessment of Android Secret Codes in OEM Firmware Research Track Ruoyan Lin Shandong University, Shishuai Yang Zhengzhou University of Aeronautics, Fenghao Xu Southeast University, Wenrui Diao Shandong University | ||
16:45 15mTalk | InstruMate: A Systematic Framework for Assessing Android App Repackaging Resilience Research Track Leandro de Souza Oliveira , Rodrigo Bonifácio Informatics Center - CIn/UFPE and Computer Science Department / University of Brasília, Joanna C. S. Santos University of Notre Dame, Rui Rua New York University Abu Dhabi | ||
17:00 15mTalk | An Empirical Study of Privacy Leakage Vulnerability in Third-Party Android Logs Libraries Research Track Yixi Zhao University of Waterloo, Kundi Yao Ontario Tech University, Yiming Tang Rochester Institute of Technology, Weiyi Shang University of Waterloo | ||
17:15 7mTalk | AMF-GR: Adaptive Matrix Factorization and Graph Fusion for Android Library Recommendation Short Papers and Posters Track Abhinav Jamwal Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India, Sandeep Kumar Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India | ||
17:22 7mTalk | BUPLinker: Bridging Users and Developers in Mobile Application Evolution Short Papers and Posters Track Ayana Uematsu Waseda University, Hironori Washizaki Waseda University, Naoyasu Ubayashi Waseda University, Masanari Kondo Kyushu University, Juichi Takahashi AGEST, Inc, Yohei Takagi AGEST Inc. | ||