Research & Evaluation

Case Studies

Explore in-depth investigations, reproducible workflows, and empirical studies carried out using FirmwareDroid to analyze Android firmware images and pre-installed software.

Malware & Supply Chain October 1, 2026 8 min read

Analysis of Android TV Boxes

Pre-installed Malware, Botnets, and Trojanized Firmware

Low-cost streaming hardware based on AllWinner and Rockchip chipsets often ships with pre-installed malicious software directly in factory ROMs. We use FirmwareDroid to unpack system images, trace trojanized ADB daemons, and catalog malicious APKs communicating with ad-fraud infrastructure.

TV Boxes AllWinner Trojan Click-Fraud Unblob MobSF
Analysis Workflow Unpublished ยท Release Forthcoming

Scanning a Single App with FMD

Multi-Engine Static Inspection & Unified GraphQL Triage

While FMD specializes in full firmware extractions, researchers frequently need to triage suspicious individual APKs. This study demonstrates queuing an app through AndroGuard, MobSF, Exodus-Core, and APKLeaks, aggregating findings into a consolidated GraphQL query.

Static Analysis Multi-Scanner APKLeaks Exodus GraphQL
Forthcoming
Academic Publication May 2023 10 min read

MOBILESoft 2023 Research Paper

Towards Automated Static Analysis of Pre-Installed Android Apps

Published at the 10th IEEE/ACM International Conference on Mobile Software Engineering and Systems (MOBILESoft 2023), this empirical study introduced FMD's architecture and evaluated real-world vendor firmware to uncover structural variance, hidden attack surfaces, and privileged tracker ecosystems.

Empirical Study IEEE Conference OEM Firmware Over-Privileging

Conduct Your Own Research

Run custom studies with FirmwareDroid.

FirmwareDroid is designed for repeatability and automated analysis. Deploy the Docker Compose stack to inspect firmware images and extract pre-installed applications.

Read documentation View GitHub