Android APK Manifest & Permission Malware Risk Scanner (2026)

Audit AndroidManifest.xml files, dangerous runtime permissions, AccessibilityService abuse vectors, SMS/CallLog stalkerware flags, and exported Activity/Receiver attack surfaces 100% locally in your browser.

Android APK Manifest & Permission Malware Risk Scanner — Interactive Console
Runs locally in your browser • Instant output
APK Manifest Profile Presets
Composite APK Threat Score100 / 100
Android 15/16 Enhanced Confirmation Mode (ECM)

Blocks sideloaded APKs (installed outside Play Store session installer) from enabling BIND_ACCESSIBILITY_SERVICE, SYSTEM_ALERT_WINDOW, REQUEST_INSTALL_PACKAGES, BIND_NOTIFICATION_LISTENER_SERVICE, READ_SMS, RECEIVE_SMS until manually unlocked via App Info → Restricted Settings.

Detected Toxic Permission Chains (3)
Banking Trojan / ATS Auto-Clicker ChainCRITICAL

Combines Accessibility Service screen-reading/clicking with Overlay windows or OTP interception (Cerberus/SharkBot/Xenomorph signature).

Silent Dropper & Self-Granting EscalationCRITICAL

REQUEST_INSTALL_PACKAGES triggers package installer while Accessibility automatically clicks 'Allow' on prompt dialogs.

Legacy targetSdkVersion (28) Bypass AttemptHIGH

Targeting older Android SDKs attempts to evade granular runtime permission prompts and Google Play API 34+ enforcement.

Interactive Android Permission Matrix (9 / 20 Active)
Generated AAPT2 Inspection & ADB AppOps Lockdown Commands
# 1. Inspect compiled binary AndroidManifest.xml without decompiling
aapt2 dump permissions sample.apk
apkanalyzer manifest print sample.apk

# 2. Restrict active AppOps via ADB without root
adb shell appops set com.update.playservice.sec ACCESS_ACCESSIBILITY ignore
adb shell appops set com.update.playservice.sec SYSTEM_ALERT_WINDOW ignore
adb shell appops set com.update.playservice.sec REQUEST_INSTALL_PACKAGES ignore
adb shell appops set com.update.playservice.sec ACCESS_NOTIFICATIONS ignore
adb shell appops set com.update.playservice.sec READ_SMS ignore
adb shell appops set com.update.playservice.sec RECEIVE_SMS ignore
adb shell appops set com.update.playservice.sec BOOT_COMPLETED ignore
adb shell appops set com.update.playservice.sec IGNORE_BATTERY_OPTIMIZATIONS ignore
adb shell appops set com.update.playservice.sec QUERY_ALL_PACKAGES ignore
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Android APK Manifest & Permission Malware Risk Scanner](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/android-apk-manifest-permission-scanner/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/android-apk-manifest-permission-scanner/">Android APK Manifest & Permission Malware Risk Scanner — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Android APK Manifest & Permission Malware Risk Scanner

Quick Answer & 2026 Technical Summary (android apk permission risk scanner)Updated 2026 Standard

Android's AccessibilityService API was designed to assist visually impaired users by reading screen content and performing automated taps. Banking trojans (such as SharkBot, Cerberus, and Xenomorph) abuse this privilege to read 2FA authenticator codes off the screen, capture lock-screen PINs, and auto-approve fraudulent wire transfers without root access. Use this interactive android apk permission risk scanner above to test androidmanifest xml malware analyzer, dangerous android permissions checker, and stalkerware accessibility service detector locally in your browser with zero server uploads.

Target Keyword Spec: android apk permission risk scanner | Modules: Dangerous Permission Combo & Stalkerware Heuristic Engine • Binary ZIP / APK & XML Manifest Signature Extractor • Exported Component & Intent-Filter Attack Surface Audit
Primary Focus: android apk permission risk scanner
Core Capability: androidmanifest xml malware analyzer
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Dangerous Permission Combo & Stalkerware Heuristic Engineandroidmanifest xml malware analyzerCross-reference dangerous Android API level 34/35 permissions (BIND_ACCESSI...Sideloaded APK Pre-Installation Triage
Binary ZIP / APK & XML Manifest Signature Extractordangerous android permissions checkerDrop a raw .apk archive or decoded AndroidManifest.xml to extract declared ...Mobile App Security & MASVS Compliance Auditing
Exported Component & Intent-Filter Attack Surface Auditstalkerware accessibility service detectorIdentify insecurely exported Activities, BroadcastReceivers, ContentProvide...Corporate BYOD & Stalkerware Incident Investigation
Android OS Compatibility TargetAndroid 13 / 14 / 15 / 16 (API 33–36)AOSP + OneUI / HyperOS / Pixel UISupports modern Scoped Storage & ADB Wireless
Privilege & Safety BoundaryNon-Destructive User-Space DiagnosticsReversible via ADB / GSM MMI CodesPreserves OEM warranty & Knox fuse integrity
Telemetry Latency & Sampling60Hz – 240Hz Frame & Sensor Polling< 16.6ms Frame Budget (60 FPS Lock)Calibrated for mobile gaming & hardware triage
In-Depth ZerosUniverse Tutorial

16 Best Antivirus Apps for Android in 2026

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Android APK Manifest & Permission Malware Risk Scanner

01

Paste AndroidManifest.xml or Drop an APK File

Upload an AndroidManifest.xml, paste raw adb shell dumpsys package output, or load one of the built-in Banking Trojan / Legitimate App presets.

02

Review the Weighted Malware Risk Score (0–100)

Inspect the composite risk gauge categorizing Normal, Signature, Privileged, and High-Risk Restricted permissions alongside lethal permission combinations.

03

Audit Exported Receivers & Accessibility Hooks

Check flagged attack vectors such as BIND_ACCESSIBILITY_SERVICE paired with SYSTEM_ALERT_WINDOW (2FA overlay theft) or unguarded exported deep links.

04

Generate ADB Hardening & AppOps Commands

Copy the custom ADB shell script to revoke dangerous runtime permissions or restrict background clipboard and overlay access immediately.

Key Capabilities & Technical Architecture

Dangerous Permission Combo & Stalkerware Heuristic Engine

Cross-reference dangerous Android API level 34/35 permissions (BIND_ACCESSIBILITY_SERVICE, SYSTEM_ALERT_WINDOW, READ_SMS, RECEIVE_BOOT_COMPLETED) to flag banking overlay trojans and spyware.

Binary ZIP / APK & XML Manifest Signature Extractor

Drop a raw .apk archive or decoded AndroidManifest.xml to extract declared uses-permission tags, custom permission protectionLevels, and targetSdkVersion compliance.

Exported Component & Intent-Filter Attack Surface Audit

Identify insecurely exported Activities, BroadcastReceivers, ContentProviders, and Services missing android:permission guards that expose apps to intent spoofing.

ADB Permission Revocation & AppOps CLI Generator

Automatically generate copy-ready adb shell pm revoke and appops set commands to strip invasive permissions from sideloaded or pre-installed bloatware packages.

Practical Use Cases

Sideloaded APK Pre-Installation Triage

Verify whether third-party APK mods, utility apps, or regional builds request hidden screen-recording, keylogging, or SMS-forwarding capabilities before installing them.

Mobile App Security & MASVS Compliance Auditing

Check your own Android builds against OWASP MASVS least-privilege guidelines and verify Android 14/15 restricted settings compliance prior to Play Store submission.

Corporate BYOD & Stalkerware Incident Investigation

Evaluate suspicious package manifests extracted via ADB from employee or executive devices for known spyware persistence and silent receiver hooks.

Frequently Asked Questions (FAQs)

Why is BIND_ACCESSIBILITY_SERVICE the #1 target for Android banking malware?+

Android's AccessibilityService API was designed to assist visually impaired users by reading screen content and performing automated taps. Banking trojans (such as SharkBot, Cerberus, and Xenomorph) abuse this privilege to read 2FA authenticator codes off the screen, capture lock-screen PINs, and auto-approve fraudulent wire transfers without root access.

How does Android 14 and 15 Restricted Settings block sideloaded APK abuse?+

When an APK is sideloaded outside of a session-based package installer (such as Google Play), Android 13+ places a 'Restricted Setting' lock on Accessibility and Notification Listener toggles until the user manually enables unrestricted access in App Info.

Why is combining SYSTEM_ALERT_WINDOW with INTERNET considered high risk?+

SYSTEM_ALERT_WINDOW ('Display over other apps') allows an application to draw an identical phishing login overlay on top of legitimate banking or crypto wallet apps, streaming captured credentials directly over the INTERNET permission.

What does android:exported='true' mean in AndroidManifest.xml?+

When an Activity, Service, Receiver, or ContentProvider sets android:exported='true' without enforcing a custom signature-level permission, any other app installed on the device can launch that component, pass malicious Intent extras, or query private app data.

Are my APK or manifest files uploaded to any external server?+

No. All XML parsing, binary APK string extraction, and permission risk scoring execute 100% client-side in your browser.