Oct 07, 2026

Crypters and the Mobile Malware Blind Spot: What a New Australian Government Advisory Means for Mobile Security

A joint advisory from the Australian Signals Directorate (ASD), Australian Federal Police (AFP), New Zealand Police, Google, and the UK's National Crime Agency (NCA) warns that "crypters," commercial obfuscation-as-a-service tools priced from as little as $25 a file, let attackers scramble malware so it evades antivirus and endpoint detection. The advisory is written for traditional endpoints, but the same commercial model already exists for mobile. Android-specific obfuscation-as-a-service platforms have been documented since at least 2020, offering the same pay-per-file scrambling to evade mobile antivirus and app-store scanning.

The advisory was not triggered by a single incident but by a trend as endpoint detection and platform protections have improved, cybercriminals have increasingly turned to crypters as a countermeasure, creating what the agencies describe as a constant race between detection services and attackers adapting their software. That same race is playing out on mobile.

Zimperium's own zLabs research on the RecruitRat, SaferRat, Astrinox, and Massiv campaigns, together targeting more than 800 banking, cryptocurrency, and social media apps, found advanced APK tampering, encrypted payloads, dynamic code loading, and environment-aware execution driving detection rates on traditional signature-based mobile security tools down to near zero.

While the advisory originates in Australia, crypter services operate without borders. The malware they enable targets organisations across every region, and the evasion techniques they exploit are equally effective against mobile security tools deployed anywhere in the world.

Static, signature-based mobile security tools are just as blind to it as traditional endpoint Anit-Virus (AV) is to crypted files. On-device, AI and behavior-based detection, not signature matching, is the countermeasure for both.

What is a Crypter?

A crypter is a paid obfuscation service that takes existing malware and scrambles its code so antivirus and endpoint tools can no longer recognise it by signature. It requires no development skill on the buyer's end: some operators run the entire process through automated Telegram bots or simple upload websites. According to threat intelligence research published by Recorded Future's Insikt Group in August 2026, which analysed 24 active crypter vendors, entry-level services start at as little as $30 per crypt, while mid-tier monthly subscriptions run between $500 and $3,000 per month, and premium tiers reach $12,000 to $20,000 per month with near-instant re-obfuscation guarantees. According to the joint government advisory, if a security vendor catches and flags a crypted file, the operator will simply re-crypt it and deliver a fresh, undetectable version.

Both the advisory and the Insikt Group research describe this ecosystem in Windows and endpoint terms, but the same commercial pattern already exists for mobile.

Android-specific obfuscation-as-a-service platforms have been documented since at least 2020, and Zimperium's own zLabs research has found this in active use: banking trojan campaigns using APK tampering, encrypted payloads, dynamic code loading, and environment-aware execution specifically to stay undetected by signature-based mobile security tools, and, more recently, malware using an LLM to regenerate its own code on every run so it never carries the same signature twice.

This lowers the skill barrier for cybercrime and extends the working lifespan of malware that would otherwise get caught quickly, whether that malware is designed to steal employee credentials for corporate network access or to steal customer credentials and drive account-takeover fraud, and whether it runs on a laptop or a phone.

Does Mobile Malware Use the Same Evasion Techniques?

Yes, and the data makes that clear.

Mobile malware authors have relied on functionally equivalent evasion techniques for years: code packers, native-code obfuscation, dynamic and delayed payload loading, and anti-emulation or anti-analysis checks that all serve the same purpose as a crypter, defeating detection that depends on recognising a known signature or pattern. The same Recorded Future report that documented 24 active crypter vendors found that at least two of them explicitly advertise APK crypting for Android apps, including one vendor claiming Google Play Protect evasion, which confirms this is not solely a desktop or server problem.

Zimperium's 2026 Mobile Banking Heist report documents these evasion capabilities as standard features across the malware families it tracked, not edge cases. Zimperium's publicly available IOC repository on GitHub puts that research on the record: years of mobile malware indicators of compromise tracked and published by zLabs researchers, predating this advisory by a significant margin.

The scale of the mobile malware problem is more significant than most enterprises realize.

On the employee side, Android spyware has grown steadily over four years and is now present on nearly one in ten devices. This category of malware depends entirely on evasion and persistence to remain undetected and operational. On the customer and fraud side, the 2026 Zimperium Mobile Banking Heist report tracked 34 active malware families targeting 1,243 financial brands across 90 countries, with three families alone targeting more than 60% of banking and fintech apps.

(Source: Zimperium Global Mobile Threat Report 2026; Zimperium Mobile Banking Heist Report 2026; Recorded Future Insikt Group, August 2026)

Why Can't Signature-Based Security Catch Crypted Mobile Malware?

Antivirus and endpoint tools identify malware by matching files against a library of known signatures: cryptographic hashes that uniquely fingerprint a file, byte sequences that appear consistently across a malware family, and heuristic rules that flag suspicious code structures. A crypter defeats all three simultaneously by encrypting the malicious payload inside a clean-looking wrapper, producing a file with a new hash, scrambled byte sequences, and a surface structure that triggers none of the heuristic rules, even though the malware inside is completely unchanged.

Mobile malware threats that use packing or dynamic loading create the same blind spot. If a threat has never been seen in that exact form before, a static scanner has nothing to match it against, no matter how many previous versions of the same malware family it has already caught.

What Does Effective Detection Against Crypted Mobile Malware Actually Look Like?

Closing that blind spot requires a fundamentally different detection model, one that does not rely on having seen a threat before.

Zimperium's approach combines three layers: deterministic detection that identifies known threat indicators with certainty and no false positives, behavioural analysis that flags what a threat does rather than what it looks like, and AI models that identify anomalies and novel threat patterns even when no prior signature or behaviour rule exists. Together these layers cover the full spectrum, from known threats to zero-days to threats that have been deliberately engineered to look new, which is precisely what a crypter or polymorphic mobile malware is designed to produce.

For enterprises managing both employee devices and the apps they build and ship to customers, that layered model needs to address two distinct attack surfaces with two distinct but connected layers of protection.

How Does Zimperium Protect Against Undetectable Mobile Threats?

Zimperium's AI-Empowered Mobile Security approach addresses both sides of this problem.

Secure the Device — Mobile Threat Defense (MTD)

Zimperium's MTD leverages On-Device AI to protect fully managed and BYOD employee devices against mobile phishing (mishing), malware, device compromise, network threats, shadow AI, and unvetted apps. AI-powered agents in the MTD console correlate threat events, confirm incidents, and deliver response guidance to SOC and fraud teams.

Unlike traditional mobile antivirus that relies on static signature lists, MTD protections are powered by an on-device model that operates in real time with no cloud dependency required. That model combines three layers: deterministic detection for known threats, behavioural analysis that flags what a threat does rather than what it looks like, and AI models that identify novel and anomalous patterns even when no prior signature or rule exists.

Most malware campaigns start with a phishing link delivered to a mobile device. That makes mobile phishing (mishing) protection critical. Mishing protection follows the same layered logic as the rest of MTD. It covers all three channels where mishing actually arrives, which are SMS, the browser, and other apps on the device, not just the corporate inbox. URL-based detection catches known bad links and domains. Non-URL-based detection analyzes the content, structure, and intent of a message itself, so it catches phishing attempts that have no known bad link.

Employees inadvertently download malware from app stores as they often masquerade as productivity and utility apps. That is why malware protection on the device has to cover the full lifecycle of an app, not just one moment. MTD relies on the same three-layer detection. It flags a malicious app at download, at install, or post-install the moment it carries out any malicious behavior.

The Mobile App Vetting capability assesses third-party apps managed and personal apps installed on employee devices before they become a risk to the enterprise.It flags apps that carry malware, embed shadow AI, collect excessive data, or request risky permissions. It also flags apps that show signs of being repackaged or tampered with, including apps run through a crypter to evade detection.

For Australian government agencies and organisations in highly regulated industries, Zimperium's sovereign-hosted Mobile Threat Defense solution has achieved the Australian Government security classification of PROTECTED following a successful assessment by the Information Security Registered Assessors Program (IRAP), assessed to the standards set by the Australian Signals Directorate, the same authority that issued this advisory. Full details of the assessment are available here.

Secure the App — Mobile Application Protection Suite (MAPS)

Where MTD secures the devices employees carry, MAPS secures the apps an organisation builds and ships to customers. The threat profile is different but the evasion dynamic is the same: attackers use obfuscation and repackaging to make malicious versions of legitimate apps unrecognisable to static scanners, then deploy them to steal customer credentials, hijack transactions, and commit fraud at scale.

MAPS addresses this across the full app lifecycle through four integrated, AI-powered capabilities:

    • Mobile App Security Testing — static, dynamic, and interactive analysis of the app binary before release, identifying security weaknesses, compliance gaps, and supply chain risks from third-party libraries and SDKs.
    • App Shielding— code obfuscation and integrity controls that make the app's architecture unreadable to reverse engineering, applied through no-code and low-code options that do not slow the release cycle.
    • Advanced Runtime Protection — AI-driven, on-device detection that continuously attests the device, app, network, and OS environment, blocking tampering, hooking, overlay attacks, emulator abuse, and repackaged app variants in real time, with new detections deployable over the air without an app re-release.
    • Key Protection — whitebox cryptography that keeps cryptographic keys and sensitive data protected at rest, in transit, and in memory.

For SOC and fraud teams, the Mobile App Response Agent adds an AI layer that automatically correlates mobile threat events into a full attack chain narrative, delivers a clear verdict on whether a fraud incident occurred, and provides step-by-step response guidance without requiring mobile security expertise from the analyst.

For Australian organisations subject to the ISM framework, which includes 44 mobile-specific security controls spanning device hardening, app security, and secure mobility policy, MAPS directly addresses the app development and runtime controls.

Next Steps

The ASD advisory is a clear signal that obfuscation-as-a-service has crossed a threshold that warrants a coordinated government response. If your organisation wants to assess whether its mobile device fleet and customer-facing apps have the same blind spot the advisory describes, Zimperium can help. We offer a mobile risk assessment covering both devices and apps, so you know exactly where you stand.

 

Frequently Asked Questions

Is the ASD/AFP crypter advisory specifically about mobile malware? No. The advisory addresses traditional endpoint and server malware. The connection to mobile is a pattern parallel: mobile malware has used equivalent obfuscation and evasion techniques (packing, dynamic loading, anti-analysis checks) for years. It is not a claim that this specific advisory covers phones.

What makes mobile app protection different from traditional antivirus? Traditional antivirus relies primarily on known signatures. Mobile-specific protection needs to also account for app tampering, repackaging, sideloading, and runtime manipulation, threats that do not have a fixed file signature to check against, which is why behaviour-based, on-device detection is a necessary complement to static scanning.

What is the difference between MTD and MAPS? Mobile Threat Defense (MTD) protects the devices employees use, detecting mobile phishing (mishing), malware, network attacks, and device compromise. Mobile Application Protection Suite (MAPS) protects the apps an organisation builds and ships, through security testing, code hardening, key protection, and runtime protection.

How many enterprises rely on Zimperium for mobile security? Zimperium protects 1,500+ global enterprises, including 109 banking and insurance institutions across 36 countries, and scans more than 100 million unique apps annually.


Sources: Joint advisory from the Australian Signals Directorate, Australian Federal Police, New Zealand Police, Google, and the UK National Crime Agency, "Digital camouflage: crypters make malware undetectable," cyber.gov.au. Mobile threat statistics from Zimperium zLabs and the Zimperium Global Mobile Threat Report.