Abstract:
The rapid adoption of Android devices has been paralleled by a significant rise in Android malware, leveraging sophisticated techniques to evade detection and execute malicious activi ties. This research investigates the use of proxy-based covert channels, such as Tor, VPNs, and proxies, in Android malware for purposes like command-and-control (C2) communication and botnet orchestration. Employing a combination of static and dynamic analysis, the study identi fies malicious APKs and examines their communication patterns. A novel static analysis-based classification model is proposed, offering high accuracy in malware detection and explainability, thus overcoming the ”black box” nature of machine learning models in security. The project also explores the operational methods of covert channel exploitation and presents a unified dataset spanning multiple years, contributing to a deeper understanding of covert communication threats in the Android ecosystem. This research lays the groundwork for more robust detection mechanisms while addressing the dual-use challenge of preserving user privacy.