securitylab_n•July 14, 2026•🇷🇺Translated from Russian

Five Minutes and 88 Kopecks: AI Neural Networks Can Now Disassemble, Modify and Reassemble Android Apps at Minimal Cost

Researchers at Positive Technologies have demonstrated that modern large language models can disassemble, modify, reassemble, and maintain the functionality of Android applications in as little as five minutes for a cost of only 88 kopecks. The findings reveal how dramatically artificial intelligence has lowered the barriers for creating altered copies of mobile apps that could be used for malicious purposes.

The experiment was conducted in an isolated laboratory environment using a sample of 90 Android applications from various categories. Specialists avoided adding any malicious functions, working with real users, or accessing user data. Instead, they introduced neutral code changes and verified whether the applications would still launch successfully after repackaging. This methodology allowed the team to measure how easily neural networks can automate the creation of modified application copies.

Performance of Different AI Models

Closed commercial models successfully completed the task in an average of 84 percent of attempts. Models with open weights achieved a lower but still significant success rate of 61 percent. On average, the process required 14 interaction steps with the model for each application. Depending on the chosen model, the entire workflow took between 5 minutes 38 seconds and 9 minutes 9 seconds. The cost of a successful modification ranged from 88 kopecks to 40 rubles 89 kopecks. Researchers estimate that a budget of just several thousand rubles would be sufficient to attempt modifications on approximately one hundred popular Android applications.

Altered APK files can be distributed under the guise of legitimate programs through unofficial app stores, websites, messengers, and catalogs of third-party builds. These modified versions are frequently advertised as improved applications that remove restrictions or add extra features. Services that are unavailable in official stores are especially vulnerable, as users often search for installation files on alternative platforms and risk downloading visually identical but tampered builds.

Implications and Recommendations

Large language models have not created entirely new attack methods; however, they have significantly reduced the cost and complexity of preparing counterfeit applications. Previously, disassembling and repackaging APK files required advanced reverse-engineering skills and manual effort. Today, a substantial portion of these operations can be performed automatically by neural networks.

Developers are advised to protect client-side code against analysis and modification, regularly test applications for resilience to reverse engineering, and monitor the appearance of unofficial APK files. Users should be warned about the risks of installing applications from unverified sources, and protective mechanisms should be integrated during the development phase itself.

Related articles

Habr•AI Security

Do Sandbox Restrictions Actually Work for AI Agents Running in Linux and gVisor?

An in-depth technical analysis examines whether security mechanisms such as Landlock, classic BPF socket filters, and CGROUP_DEVICE programs enforce intended restrictions inside container and VM-based sandboxes used by AI agents. Tests conducted on Linux 6.8 and two gVisor releases (20260817.0 and 20260831.0) revealed that Landlock calls consistently return ENOSYS inside gVisor, rendering the mechanism unavailable. CGROUP_DEVICE programs could be loaded and attached successfully under elevated capabilities, yet they produced no observable effect on device access. Classic BPF filters attached via SO_ATTACH_FILTER were accepted without error even with zero capabilities, but continued to allow UDP datagrams that should have been dropped. The study emphasizes that successful configuration alone does not guarantee enforcement and outlines a verification workflow that must be repeated for each target environment, runtime, and policy change before deploying restricted AI tools.

嘶吼•AI Security

Houlong Security Industry Research Institute Releases 2026 China Cybersecurity Industry Map

The Houlong Security Industry Research Institute has published its comprehensive 2026 Network Security Industry Map following months of research that collected over 400 valid responses from leading Chinese cybersecurity firms. The report documents a structural market shift driven by AI-enabled attacks moving from theory to real-world operations, including automated phishing, deepfake fraud, and dual ransomware-extortion models targeting APIs and supply chains. On the defense side, it highlights the rapid adoption of AI for real-time threat detection, large-scale zero-trust deployments, privacy-preserving computation, and preparations for quantum-safe migration. The study notes that vendors integrating AI capabilities are outperforming peers in customer retention and pricing power while the industry moves away from broad product suites toward specialized, scenario-focused solutions. Overall, the map identifies three irreversible trends: AI becoming mandatory in security products, competition favoring depth over breadth, and sustained growth fueled by digital transformation and geopolitical factors.

AntiMalware•AI Security

Natalia Kaspersky Questions Trustworthiness Criteria for Generative AI

Natalia Kaspersky has expressed serious doubts about applying traditional trust criteria to generative AI systems. She explained that a trusted system must operate within predefined parameters and deliver predictable, repeatable results. Generative AI fails this standard because it produces varying outputs for the same inputs. The enormous scale of modern models makes comprehensive verification practically impossible. Selective testing of individual responses provides no assurance of overall reliability. Kaspersky stressed that creating trusted AI requires joint efforts from AI specialists, information security experts, methodologists, and standards developers rather than discussions alone.

Habr•AI Security

Why 'You Are My Grandmother' Jailbreaks Succeed Against LLMs and How an External Controller Could Fix Them

The article examines why simple role-playing prompts easily bypass safety rules in large language models. It contrasts two possibilities: models that merely reproduce refusal templates versus those that maintain a stable internal representation of prohibited categories. Because competing contextual signals often outweigh safety constraints, jailbreaks succeed by shifting token prediction priorities. The proposed remedy separates the main LLM from an independent controller module that inspects both full input context and generated output against a narrow list of disallowed topics such as fraud, weapons, and child exploitation material. Several efficiency techniques are suggested, including block-wise scanning, embedding-based pre-filters, and two-stage checks that avoid reprocessing entire 100k-token dialogues on every turn. The author stresses that the controller must remain an external, non-LLM component to prevent recursive oversight layers. The discussion concludes that only such architectural separation offers robust resistance to context-based jailbreaks.