-
-
Sudarshan APK Analysis Dashboard: Upload a suspicious Android application to begin a complete security investigation.
-
Executive Fraud Intelligence View: Deterministic risk scoring, threat indicators, and key findings summarized for analysts.
-
Technical Investigation View: Detailed evidence, detected behaviors, threat intelligence, and analysis results for SOC teams.
Sudarshan: Enterprise Mobile Banking Threat Intelligence
Inspiration
Modern Android banking trojans are no longer simple malicious applications. They can abuse Accessibility Services, intercept SMS and OTPs, create overlays over legitimate banking applications, communicate with remote infrastructure, and use anti-analysis techniques to hide their behavior.
The problem we identified was not only detecting malicious code. Security teams also need to understand what an application can do, what it actually did during execution, who it may be targeting, and what evidence supports the conclusion.
Traditional approaches often separate static analysis, dynamic analysis, threat intelligence, and reporting into different tools. Static analysis can reveal suspicious capabilities but may miss runtime behavior. Dynamic analysis can reveal real behavior but may fail when malware detects an emulator, requires interaction, or keeps important functionality dormant.
This inspired us to build Sudarshan, an enterprise-oriented Android malware and mobile banking threat intelligence platform that combines these capabilities into one evidence-driven investigation workflow.
Our core principle is:
Deterministic engines establish what happened. AI explains why it matters.
What We Built
Sudarshan provides an end-to-end workflow for analyzing suspicious Android applications:
APK → Static Intelligence → Investigation Manifest → Dynamic Sandbox → Deep UI Exploration → Runtime Evidence → Threat Intelligence → Risk Engine → AI Investigation → Analyst Dashboard & Reports
The platform combines multiple analysis layers:
- Static Threat Intelligence using Androguard, APKTool, JADX and optional MobSF integration
- APK Repair for malformed or deliberately corrupted Android manifests
- Dynamic Analysis using Android Virtual Devices and Frida
- Deep UI Exploration using an agentic exploration engine
- Runtime Instrumentation for Accessibility, SMS, overlays, network/C2 and anti-analysis behavior
- Visual Impersonation Detection for identifying potential banking-app impersonation
- Threat Intelligence Correlation using external intelligence sources
- Deterministic Risk Scoring using STEI, BFCI and FRS
- Evidence Store and Runtime Event Bus for structured forensic telemetry
- RAG-grounded AI Investigation for analyst-friendly explanations
- STIX 2.1, PDF, HTML and IOC CSV Reporting
- SOC Dashboard for executive and technical investigation workflows
A major architectural decision was to keep the numerical risk decision outside the LLM.
The deterministic risk engine calculates the security and fraud-related scores from structured evidence. The AI layer is used afterward to explain the evidence, reconstruct the investigation context and assist the analyst.
How We Built It
1. APK Intake
The investigation begins when an analyst uploads an APK.
Sudarshan validates the package and generates a SHA-256 identity that is used throughout the investigation to maintain consistent evidence and analysis tracking.
2. Static Analysis
The APK passes through multiple complementary analysis engines.
Androguard extracts Android manifest information, permissions, DEX structures, strings and application metadata.
APKTool extracts resources, layouts and smali code.
JADX decompiles DEX bytecode into Java-like source and searches for predefined banking and fraud-related signatures.
MobSF can provide additional mobile security analysis.
The platform can also attempt APK and manifest repair when malformed Android XML prevents normal forensic processing.
The resulting findings are normalized into an Investigation Manifest containing capability flags, dynamic hook profiles and exploration priorities.
3. Dynamic Sandbox
The application can then be executed inside an isolated Android environment.
Sudarshan manages device discovery, installation, launch stabilization, process identification and Frida instrumentation.
Frida is used to observe runtime behavior including:
- Accessibility activity
- SMS and OTP-related operations
- Overlay creation
- Network communication
- Command-and-control indicators
- Anti-analysis behavior
4. Deep UI Exploration
Many malicious applications do not reveal their important behavior immediately after launch.
Sudarshan therefore uses an Agentic Explorer to navigate through the application and reach deeper states.
The perception pipeline can combine:
- UI hierarchy information
- Current activity and package information
- Runtime Frida events
- Logcat evidence
- Screenshot-based visual analysis
The explorer maintains a screen graph to identify previously visited states, avoid repetitive loops and recover from unexpected transitions.
5. Evidence and Risk Analysis
Static findings and runtime events are converted into structured evidence.
The deterministic risk engine evaluates signals related to areas such as:
- Credential theft
- Banking targeting
- Permission abuse
- Obfuscation and concealment
- Infrastructure risk
- Dynamic behavioral evidence
- Threat-intelligence correlation
- Banking impact
The resulting risk assessment is generated algorithmically rather than by an LLM.
This creates a clear separation between evidence-based security decisions and AI-assisted explanation.
6. AI Investigation
After deterministic analysis, the verified evidence is passed to the AI investigation layer.
Gemini is used to interpret and explain the collected evidence, reconstruct investigation context and provide analyst-friendly reasoning.
The AI does not independently determine whether an APK is malicious.
Instead:
Evidence → Deterministic Analysis → Risk Assessment → AI Explanation
This helps reduce the risk of an AI-generated security conclusion being treated as evidence without supporting telemetry.
Challenges We Faced
Building a dynamic Android malware analysis platform presented several difficult engineering challenges.
Dynamic Analysis Reliability
Launching an APK is not enough to obtain meaningful runtime evidence.
Android process lifecycles, permissions, emulator behavior, ART/JIT optimizations, Frida attachment and application state can all affect instrumentation.
We had to build mechanisms for device discovery, process resolution, launch stabilization and runtime verification.
Malware That Avoids Analysis
Some applications may detect an emulator or behave differently inside a sandbox.
This creates an important problem:
No observed malicious behavior does not necessarily mean the application is safe.
Sudarshan therefore uses execution assertions and safety floors to identify low-information investigations. If important execution preconditions were never exercised, the platform can mark the analysis as incomplete rather than treating the absence of evidence as evidence of safety.
Deep Application Navigation
Another challenge was reaching functionality hidden behind multiple screens or interactions.
Simple automation that only clicks visible buttons is insufficient for many applications.
We therefore developed an exploration approach that combines UI hierarchy information, runtime events, logcat, screenshots and screen-state tracking.
Combining Multiple Sources of Evidence
Static analysis, dynamic instrumentation, threat intelligence and visual analysis produce different types of data.
A major challenge was creating a common evidence model that could connect these signals into a coherent investigation.
The Runtime Event Bus and Evidence Store were designed to provide this structured foundation.
Keeping AI Grounded
Using an LLM for cybersecurity analysis introduces another challenge: an AI model must not be treated as the source of truth.
We designed Sudarshan so that deterministic analysis establishes the underlying security signals, while the AI layer operates on the collected evidence and helps explain it to the analyst.
What We Learned
One of the biggest lessons we learned is that Android malware analysis is not simply about finding suspicious APIs.
A useful security platform needs to answer several questions:
What can this application do?
What did it actually do?
Who is it targeting?
What evidence proves it?
How complete was the investigation?
What should the analyst investigate next?
Building Sudarshan required us to work across Android internals, reverse engineering, Frida instrumentation, UI automation, threat intelligence, deterministic risk analysis, cybersecurity evidence handling and AI/RAG systems.
We also learned that dynamic analysis is significantly harder than simply launching an APK. Runtime instrumentation, emulator detection, dormant functionality, UI state transitions and application process behavior can all determine whether an investigation produces meaningful evidence.
Why Sudarshan?
Sudarshan is designed around defense in depth.
If static analysis identifies a suspicious capability, it becomes evidence.
If dynamic analysis observes suspicious runtime behavior, it becomes evidence.
If threat intelligence correlates an indicator, it becomes evidence.
If visual analysis identifies potential banking impersonation, it becomes evidence.
The deterministic risk engine combines these signals, while the AI investigation layer helps the human analyst understand them.
The goal is not to replace the analyst.
The goal is to give the analyst a unified investigation workflow where complex Android behavior can be converted into structured, explainable and actionable threat intelligence.
Future Scope
Our next steps include expanding the banking-application baseline corpus, increasing runtime coverage across different Android configurations, improving second-stage payload discovery, expanding malware-family intelligence and integrating Sudarshan more deeply with enterprise SOC and SOAR workflows.
Our long-term goal is to transform Android malware analysis from a fragmented collection of forensic tools into a unified, evidence-driven investigation platform for banking security teams.
Built With
- analysis
- androguard
- android
- apktool
- cybersecurity
- fastapi
- frida
- gemini
- intelligence
- jadx
- malware
- mobsf
- python
- react
- threat
- typescript

Log in or sign up for Devpost to join the conversation.