Many Android users prefer to ignore the official Google store and get the APKs of their favorite apps by alternative means. That results in more freedom, but malicious elements are always ready to infect apps with malware or cryptominers in the background. Therefore, the best action is to verify them before they end up on our smartphones. That is where Droidy from VirusTotal comes in, a tool that analyzes the content and behavior of each APK.
The number one recommendation when getting mobile apps is and will continue to be downloading them through the official stores. While we understand that there are plenty of reasons to question the Apple and Google ecosystems, the truth is that they provide an extra layer of security that is critical in the vast majority of cases (and by that I mean the average user, who does not have the technical knowledge to recognize a malicious app).
Now, advanced users believe that their common sense will never fail and they will not take risks if they manually download APKs, but we must not forget that there are developers working to deceive us. The ideal thing is to analyze an APK before installing it, and that brings us to VirusTotal.
How to analyze an Android APK
Yes, VirusTotal, the same online malware analysis service that has helped us avoid disasters on more than one occasion. The resource is called Droidy, and it serves as an extension of the old Android reporting system that the service implemented in 2013.
Droidy is an Android sandbox that gives the user details about an APK such as its network communications (HTTP requests and DNS resolutions), permission checks, SMS activity, Java calls, file system interactions, service manipulation, and any action related to cryptocurrency mining.
The amount of data is enormous, but it is enough to know that if there is anything strange in the app, VirusTotal will light up like a Christmas tree.
All we have to do to activate Droidy is drag the APK into the VirusTotal window, or upload it in the same way as a normal exe file. If the application's hash is already in the database, VirusTotal will present the results of the last study performed, but there is always the possibility of forcing a new analysis. It will take a couple of extra minutes, but it is definitely worth the wait.