
The Android Malware Handbook
Using Manual Analysis and ML-Based Detection
Machine-learning researchers and members of Meta's and Google's Android Security teams distill years of research into detecting banking trojans, ransomware, and SMS fraud on Android, combining manual analysis with classification models.
As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.
- Published
- 2023
- Publisher
- No Starch Press
- Pages
- 328
- Language
- English
Read this if
Mobile security engineers and ML practitioners who need to go beyond signature-based Android AV into classification models and feature engineering for malware families. Written by people who actually built detection at Android-scale, not academics theorizing about it.
Skip this if
Readers who want iOS coverage (none here) or who need an introduction to machine learning itself; the book assumes ML fluency and applies it to Android malware specifically, rather than teaching ML from scratch.
Key takeaways
- Walks the history of Android malware in the wild since the OS launched, giving the classification models real evolutionary context instead of a static snapshot.
- Covers both static and dynamic analysis of real specimens before getting to the ML layer, so detection models sit on top of sound manual analysis.
- Breaks down ML strategies by malware category (banking trojans, ransomware, SMS fraud), each with the specific features that actually discriminate it.
Notes
The mobile-malware counterpart to this catalog's Android Security Internals (platform internals) and Practical Malware Analysis (general technique) — this is where the two intersect specifically for Android, with a machine-learning detection layer neither of those books covers. A natural pair with Malware Data Science for the general ML-for-security approach.
What to read before
What to read before The Android Malware Handbook →Intermediate · 2018
Malware Data Science
Saxe and Sanders apply machine-learning techniques (classification, clustering, deep learning) to malware detection and attribution, with working Python code and real corpora.
Intermediate · 2012
Practical Malware Analysis
Still the gold standard textbook for static and dynamic malware analysis on Windows.
Beginner · 2014
Countdown to Zero Day
Kim Zetter's investigative reconstruction of Stuxnet, the joint US/Israeli operation that physically damaged Iranian uranium-enrichment centrifuges via a worm, and what its discovery revealed about state-level cyber capability.
What to read next
What to read after The Android Malware Handbook →Advanced · 2014
The Art of Memory Forensics
Ligh, Case, Levy, and Walters' canonical reference on memory analysis with Volatility — the technique, the tooling, and the operating-system internals it depends on, across Windows, Linux, and macOS.
Advanced · 2014
Android Security Internals
Nikolay Elenkov on the actual implementation of Android's security model: package manager internals, permissions, keystore, SELinux integration, verified boot.
Advanced · 2025
Cybersécurité et Malwares
Now in its 5th edition, the French-language reference for malware analysis by Sébastien Larinier and Paul Rascagnères, a well-known APT threat researcher, running from identification to Threat Intelligence across Windows, macOS, Linux, Android, and iOS.
Explore similar books
Alternatives to The Android Malware Handbook →Intermediate · 2018
Malware Data Science
Saxe and Sanders apply machine-learning techniques (classification, clustering, deep learning) to malware detection and attribution, with working Python code and real corpora.
Advanced · 2014
The Art of Memory Forensics
Ligh, Case, Levy, and Walters' canonical reference on memory analysis with Volatility — the technique, the tooling, and the operating-system internals it depends on, across Windows, Linux, and macOS.
Advanced · 2026
Dissecting the Dark Web
HUMAN Security's VP of Threat Intelligence tears down real malware-as-a-service offerings sold on dark web forums, chapter by chapter, from stealers and loaders to ransomware and living-off-the-land post-exploitation kits.