Skip to main content

Command Palette

Search for a command to run...

Max Messenger - Malware Scoring

Updated
•View as Markdown
Max Messenger - Malware Scoring
M

Hi, I’m Mike Broomfield, an experienced cybersecurity leader with around 20 years of hands-on experience spanning consultancies, global financial institutions, and large-scale enterprises. My career has taken me from penetration testing and security architecture roles at leading consultancies and major banks to my current position as Head of Application Security & Security Testing at Tesco. I have a deep passion for security research and engineering innovation, with a focus on embedding security seamlessly into modern software delivery. Over the years, I’ve led initiatives that integrate security into CI/CD pipelines, automate developer guardrails, and strengthen the resilience of complex, cloud-native systems. My approach blends a developer-first mindset with a curiosity for how systems fail and how they can be built stronger.

Continuing the Max Messenger research series, this next phase of the investigation moves beyond manual code review and into automated behavioral scoring. In the previous post, we identified how the application manages its tracking lifecycle through the z0.java class and exfiltrates data to VK-managed analytics servers. While this behaviour is clearly intrusive, the question remains: does it cross the line into the realm of malware?

To answer this, we need a rigorous, formalised way to evaluate the application's intent. For this task, I’m utilising Quark-Engine, a well-respected and highly specialised Android malware scoring system often bundled with security-focused distributions like Kali Linux and BlackArch.

What makes Quark-Engine unique is its "Order Theory" approach, which is conceptually inspired by criminal law. Rather than simply looking for blacklisted signatures, Quark analyses the progression of a "crime" (malicious behaviour) through five distinct stages:

  1. Permission Check: Does the app have the necessary permissions for the behaviour?

  2. API Class: Does it call the relevant Android classes?

  3. API Method: Does it invoke the specific methods needed to execute the action?

  4. Descriptor: Is it handling the data types associated with that behavior?

  5. Data Flow: Is there a verified tainted path where data is actually exfiltrated?

By weighing these stages, Quark provides a confidence score that allows us to distinguish between a benign app using a sensitive API and a malicious one performing a coordinated attack.

In this post, we will:

  • Run a Full Scan: Execute Quark against the Max Messenger APK to see how its behaviors are scored against Quark’s extensive ruleset.

  • Analyze the Report: Dive into the "Detail Report" to see which specific behavioral chains, such as SMS interception, location tracking, or root detection, triggered high-risk alerts.

  • Malware Classification: Compare Max Messenger’s behavior maps against known malware families like SpyNote or DroidKungFu to see where the overlaps lie.

By the end of this scan, we’ll have a data-driven verdict on whether Max Messenger’s "features" are simply aggressive telemetry or if they represent a more formal threat to the user.

The engine performed a total of 189 behavioral checks. To understand the results, we have to look at two primary metrics provided for every "crime" (potential malicious behaviour) detected:

Decoding the Metrics: Score & Confidence

Every check in the report is assigned two values that tell us how worried we should be:

  1. The Score (Risk vs. Commonality):

    • Positive Scores: These indicate behaviors that increase the app's overall threat level. The higher the number, the more likely the behavior is associated with malicious intent.

    • Negative Scores: These are "discounts." They represent behaviors that are very common in legitimate apps (like checking network connectivity). If an app does something normal, Quark reduces the total threat score to avoid false positives.

  2. The Confidence (The Evidence Chain):
    Quark uses "Order Theory" to see how far a behavior actually goes in the code.

    • 20% - 40%: The app has the permission or mentions the relevant code classes, but hasn't necessarily linked them together.

    • 60% - 80%: The app is calling specific methods and handling the data types needed to perform the action.

    • 100% (The Smoking Gun): Quark has verified the full data flow. The app isn't just capable of the behavior; the logic to execute it is fully present and connected.

Results

Results - Click to expand
Filename Rule Confidence Score Weight
00001.json Initialize bitmap object and compress data (e.g. JPEG) into bitmap object 60% -2.44 -0.61
00002.json Open the camera and take picture 40% 0 0
00003.json Put the compressed bitmap data into JSON object 60% -0.03 -0.0075
00004.json Get filename and put it to JSON object 100% -0.14 -0.14
00005.json Get absolute path of file and put it to JSON object 80% -1.32 -0.66
00006.json Scheduling recording task 60% 2.02 0.505
00007.json Use absolute path of directory for the output media file path 80% -0.06 -0.03
00008.json Check if successfully sending out SMS 40% 0.65 0.08125
00009.json Put data in cursor to JSON object 100% 0.56 0.56
00010.json Read sensitive data(SMS, CALLLOG) and put it into JSON object 60% 1.42 0.355
00011.json Query data from URI (SMS CALLLOGS) 100% 0.33 0.33
00012.json Read data and put it into a buffer stream 100% 0.87 0.87
00013.json Read file and put it into a stream 100% 1.17 1.17
00014.json Read file into a stream and put it into a JSON object 100% -1.28 -1.28
00015.json Put buffer stream (data) to JSON object 40% -0.38 -0.0475
00016.json Get location info of the device and put it to JSON object 60% -0.86 -0.215
00017.json Get Location of the device and append this info to a string 60% 0.02 0.005
00018.json Get JSON object prepared and fill in location info 40% -0.89 -0.11125
00019.json Find a method from given class name, usually for reflection 100% 0.17 0.17
00020.json Get absolute path of the file and store in string 100% -0.11 -0.11
00021.json Load additional DEX files dynamically 60% 1.69 0.4225
00022.json Open a file from given absolute path of the file 100% 0.6 0.6
00023.json Start another application from current application 100% 0.69 0.69
00024.json Write file after Base64 decoding 60% -0.28 -0.07
00025.json Monitor the general action to be performed 100% 0.59 0.59
00026.json Method reflection 100% -0.48 -0.48
00027.json Get specific method from other Dex files 60% -0.08 -0.02
00028.json Read file from assets directory 100% 0.5 0.5
00029.json Initialize class object dynamically 100% 1.37 1.37
00030.json Connect to the remote server through the given URL 40% -1.73 -0.21625
00031.json Check the list of currently running applications 40% -0.11 -0.01375
00032.json Load external class 100% 0.25 0.25
00033.json Query the IMEI number 40% 0.19 0.02375
00034.json Query the current data network type 100% -0.96 -0.96
00035.json Query the list of the installed packages 40% 1.15 0.14375
00036.json Get resource file from res/raw directory 100% -0.47 -0.47
00037.json Send notification 100% -0.09 -0.09
00038.json Query the phone number 40% 0.7 0.0875
00039.json Start a web server 40% 0.93 0.11625
00040.json Send SMS 20% -0.13 -0.008125
00041.json Save recorded audio/video to file 60% 0.34 0.085
00042.json Query WiFi BSSID and scan results 20% -0.14 -0.00875
00043.json Calculate WiFi signal strength 20% -0.21 -0.013125
00044.json Query the last time this package's activity was used 20% -0.66 -0.04125
00045.json Query the name of currently running application 20% 1.91 0.119375
00046.json Method reflection 100% -1.75 -1.75
00047.json Query the local IP address 60% 1.55 0.3875
00048.json Query the SMS contents 20% -2.39 -0.149375
00049.json Query the phone number from SMS sender 20% -1.02 -0.06375
00050.json Query the SMS service centre timestamp 20% 2.04 0.1275
00051.json Implicit intent(view a web page make a phone call etc.) via setData 100% -1.98 -1.98
00052.json Deletes media specified by a content URI(SMS, CALL_LOG, File, etc.) 60% -1.57 -0.3925
00053.json Monitor data identified by a given content URI changes(SMS, MMS, etc.) 60% 1.06 0.265
00054.json Install other APKs from file 60% -0.23 -0.0575
00055.json Query the SMS content and the source of the phone number 20% -0.44 -0.0275
00056.json Modify voice volume 60% 0.04 0.01
00057.json Return the DHCP-assigned addresses from the last successful DHCP request 40% -0.65 -0.08125
00058.json Connect to the specific WIFI network 20% -0.76 -0.0475
00059.json Query the SIM card status 40% 0.57 0.07125
00060.json Query the network operator name 100% -1.3 -1.3
00061.json Return dynamic information about the current Wi-Fi connection 40% -0.7 -0.0875
00062.json Query WiFi information and WiFi Mac Address 20% 1.12 0.07
00063.json Implicit intent(view a web page, make a phone call, etc.) 100% 0.74 0.74
00064.json Monitor incoming call status 40% -1.78 -0.2225
00065.json Get the country code of the SIM card provider 40% -0.11 -0.01375
00066.json Query the ICCID number 40% -1.54 -0.1925
00067.json Query the IMSI number 40% 1.63 0.20375
00068.json Executes the specified string Linux command 100% 0.88 0.88
00069.json Run shell script programmably 40% 1.21 0.15125
00070.json Get sender's address and send SMS 20% 0.26 0.01625
00071.json Write the ISO country code of the current network operator into a file 60% 0.38 0.095
00072.json Write HTTP input stream into a file 40% -0.02 -0.0025
00073.json Write the SIM card information into a file 40% 1.79 0.22375
00074.json Get IMSI and the ISO country code 40% -0.38 -0.0475
00075.json Get location of the device 100% -1.68 -1.68
00076.json Get the current WiFi information and put it into JSON 40% -1.05 -0.13125
00077.json Read sensitive data(SMS, CALLLOG, etc) 100% 1.27 1.27
00078.json Get the network operator name 80% -0.1 -0.05
00079.json Hide the current app's icon 100% -1.43 -1.43
00080.json Save recorded audio/video to a file 40% -0.77 -0.09625
00081.json Get declared method from given method name 100% -0.37 -0.37
00082.json Get the current WiFi MAC address 40% -1.01 -0.12625
00083.json Query the IMEI number 40% 0.42 0.0525
00084.json Get the ISO country code and IMSI 40% 1.57 0.19625
00085.json Get the ISO country code and put it into JSON 60% 0.63 0.1575
00086.json Check if the device is in data roaming mode 100% 0.34 0.34
00087.json Check the current network type 80% 0.17 0.085
00088.json Create a secure socket connection to the given host address 80% 1.83 0.915
00089.json Connect to a URL and receive input stream from the server 40% 0.72 0.09
00090.json Set recroded audio/video file format 40% -0.25 -0.03125
00091.json Retrieve data from broadcast 40% 1.02 0.1275
00092.json Send broadcast 40% 0.54 0.0675
00093.json Get the content of SMS and forward it to others via SMS 20% 0.73 0.045625
00094.json Connect to a URL and read data from it 100% 0.01 0.01
00095.json Write the ICCID of device into a file 40% -1.29 -0.16125
00096.json Connect to a URL and set request method 100% -0.34 -0.34
00097.json Get the sender address of the SMS and put it into JSON 40% 0.49 0.06125
00098.json Check if the network is connected 80% -1.6 -0.8
00099.json Get location of the current GSM and put it into JSON 40% -1.02 -0.1275
00100.json Check the network capabilities 100% 0.42 0.42
00101.json Initialize recorder 40% 0.05 0.00625
00102.json Set the phone speaker on 60% 1.63 0.4075
00103.json Check the active network type 80% -0.59 -0.295
00104.json Check if the given path is directory 40% 1.27 0.15875
00105.json Append the sender's address to the string 40% 0.55 0.06875
00106.json Get the currently formatted WiFi IP address 20% 0.01 0.000625
00107.json Write the IMSI number into a file 40% -0.61 -0.07625
00108.json Read the input stream from given URL 40% -0.12 -0.015
00109.json Connect to a URL and get the response code 100% 2.23 2.23
00110.json Query the ICCID number 20% 0.07 0.004375
00111.json Get the sender address of the SMS 40% 0.27 0.03375
00112.json Get the date of the calendar event 60% -1.2 -0.3
00113.json Get location and put it into JSON 60% -1.09 -0.2725
00114.json Create a secure socket connection to the proxy address 100% -1.77 -1.77
00115.json Get last known location of the device 100% 1.36 1.36
00116.json Get the current WiFi MAC address and put it into JSON 40% -1.02 -0.1275
00117.json Get the IMSI and network operator name 40% -0.56 -0.07
00118.json Check if the content of SMS contains given string 40% 0.09 0.01125
00119.json Write the IMEI number into a file 40% 0.37 0.04625
00120.json Append the sender's address to the string 40% 1.44 0.18
00121.json Create a directory 40% 1.62 0.2025
00122.json Check if the sender address of SMS contains the given string 40% -0.01 -0.00125
00123.json Save the response to JSON after connecting to the remote server 40% 2.38 0.2975
00124.json Check the current active network type 100% -0.84 -0.84
00125.json Check if the given file path exist 40% 0.16 0.02
00126.json Read sensitive data(SMS, CALLLOG, etc) 60% 2.32 0.58
00127.json Monitor the broadcast action events (BOOT_COMPLETED, etc) 60% -0.84 -0.21
00128.json Query user account information 40% -1.58 -0.1975
00129.json Get the content of SMS 40% 1.84 0.23
00130.json Get the current WIFI information 40% -1.21 -0.15125
00131.json Get location of the current GSM and put it into JSON 40% 0.27 0.03375
00132.json Query The ISO country code 100% -1.72 -1.72
00133.json Start recording 40% -2.12 -0.265
00134.json Get the current WiFi IP address 40% -0.19 -0.02375
00135.json Get the current WiFi id and put it into JSON. 40% 0.49 0.06125
00136.json Stop recording 40% -0.59 -0.07375
00137.json Get last known location of the device 40% -0.7 -0.0875
00138.json Set the audio source (MIC) 40% 0.22 0.0275
00139.json Get the current WiFi id 40% -0.59 -0.07375
00140.json Write the phone number into a file 40% -0.1 -0.0125
00141.json Load class from given class name 100% 0.86 0.86
00142.json Get calendar information 100% -0.15 -0.15
00143.json Get external class from given path or file name 40% -0.19 -0.02375
00144.json Write SIM card serial number into a file 40% -1.56 -0.195
00145.json Create a socket connection to the proxy address 100% 1.15 1.15
00146.json Get the network operator name and IMSI 40% 1.05 0.13125
00147.json Get the time of current location 100% 1.84 1.84
00148.json Create a socket connection to the given host address 80% 0.34 0.17
00149.json Unpack an asset 20% 0.66 0.04125
00150.json Send IMSI over Internet 40% -0.07 -0.00875
00151.json Send phone number over Internet 40% 1.78 0.2225
00152.json Get data from HTTP and send SMS 40% -1.45 -0.18125
00153.json Send binary data over HTTP 40% 0.26 0.0325
00154.json Connect hostname to TCP or UDP socket using KryoNet 40% -0.23 -0.02875
00155.json Execute commands on shell using DataOutputStream object 60% -0.38 -0.095
00156.json Acquire lock on Power Manager 100% -0.49 -0.49
00157.json Instantiate new object using reflection, possibly used for dexClassLoader 100% -0.54 -0.54
00158.json Connect to a URL and send sensitive data got from resolver 40% -0.86 -0.1075
00159.json Use accessibility service to perform action getting node info by text 20% -0.95 -0.059375
00160.json Use accessibility service to perform action getting node info by View Id 20% -0.08 -0.005
00161.json Perfom accessibility service action on accessibility node info 20% -0.91 -0.056875
00162.json Create InetSocketAddress object and connecting to it 40% -2.5 -0.3125
00163.json Create new Socket and connecting to it 20% 1.53 0.095625
00164.json Get SMS address and send it through http 20% 0.23 0.014375
00165.json Get SMS message body and send it through http 20% 0.01 0.000625
00166.json Get SMS message body and retrieve a string from it (possibly PIN / mTAN) 20% 0.02 0.00125
00167.json Use accessibility service to perform action getting root in active window 20% -0.87 -0.054375
00168.json Use accessibility service to perform global action getting node info by text 20% -0.24 -0.015
00169.json Use accessibility service to perform global action getting node info by View Id 20% -0.42 -0.02625
00170.json Get installed applications and put the list in shared preferences 40% -1.11 -0.13875
00171.json Compare network operator with a string 100% -1.41 -1.41
00172.json Check Admin permissions to (probably) get them 0% 1.73 0
00173.json Get bounds in screen of an AccessibilityNodeInfo and perform action 40% -0.15 -0.01875
00174.json Get all accounts by type and put them in a JSON object 100% 0.89 0.89
00175.json Get notification manager and cancel notifications 40% -0.24 -0.03
00176.json Send sms to a contact of contact list 0% 0.1 0
00177.json Check if permission is granted and request it 60% -0.46 -0.115
00178.json Execute Linux commands via ProcessBuilder 100% -0.44 -0.44
00179.json Send Location via SMS 0% 1 0
00180.json Load native libraries(.so) via System.loadLibrary (60% means caught) 60% -0.87 -0.2175
00181.json Load native libraries(.so) via System.load (60% means caught) 60% -1.07 -0.2675
00182.json Open camera. 100% 0.33 0.33
00183.json Get current camera paremeters and change the setting. 100% -1.58 -1.58
00184.json Set camera preview texture 100% 0.02 0.02
00185.json Start capturing camera preview frames to the screen 80% -0.86 -0.43
00186.json Control camera to take picture 40% -1.49 -0.18625
00187.json Query a URI and check the result 100% 1.21 1.21
00188.json Get the address of a SMS message 80% 0.39 0.195
00189.json Get the content of a SMS message 80% -0.19 -0.095
00190.json Query a URI and append the result into a string 100% 1.39 1.39
00191.json Get messages in the SMS inbox 80% 0.68 0.34
00192.json Get messages in the SMS inbox 80% -0.66 -0.33
00193.json Send a SMS message 20% 3.12 0.195
00194.json Set the audio source (MIC) and recorded file format 100% -1.36 -1.36
00195.json Set the output path of the recorded file 80% 1.58 0.79
00196.json Set the recorded file format and output path 100% -0.38 -0.38
00197.json Set the audio encoder and initialize the recorder 100% -0.89 -0.89
00198.json Initialize the recorder and start recording 100% -0.55 -0.55
00199.json Stop recording and release recording resources 100% 0.09 0.09
00200.json Query data from the contact list 100% 0.28 0.28
00201.json Query data from the call log 80% -1.37 -0.685
00202.json Make a phone call 80% -0.03 -0.015
00203.json Put a phone number into an intent 80% -0.99 -0.495
00204.json Get the default ringtone 60% -0.68 -0.17
00205.json Simulate a touch gesture on the device screen 20% 2.14 0.13375
00206.json Check if the text of the view contains the given string 60% 0.62 0.155
00207.json Check if the resource name of the view contains the given string 60% 1.2 0.3
00208.json Capture the contents of the device screen 60% -0.94 -0.235
00209.json Get pixels from the latest rendered image 80% 0.71 0.355
00210.json Copy pixels from the latest rendered image into a Bitmap 60% -1.06 -0.265
00211.json Open an URL in Wevbiew 20% -0.18 -0.01125
00212.json Query device data with ContentResolver 100% -0.07 -0.07
00213.json Get device latitude and check if logging is enabled 60% 0.52 0.13
00214.json Get device time and longitude 100% -0.6 -0.6
00215.json Query device data with ContentResolver and obtain the number of results 100% 1.31 1.31
00216.json Query device data with ContentResolver and obtain the number of results 100% -1.97 -1.97
00217.json Get secure system settings and log warning messages 100% 0.32 0.32
00218.json Query device data with ContentResolver 100% -1.64 -1.64
00219.json Query device data with ContentResolver 100% 0.96 0.96
00220.json Get the column index of device data and store a string in SharedPreferences 80% -0.44 -0.22
00221.json Query device data with ContentResolver 100% -0.03 -0.03
00222.json Query device data with ContentResolver and a URI parsed from a string 100% -0.04 -0.04
00223.json Access ContentResolver 40% -0.76 -0.095
00224.json Check for network connectivity 100% 0.24 0.24
00225.json Start a background service 100% -0.21 -0.21
00226.json Check for network connectivity 100% 1.48 1.48
00227.json Start a background service 100% 0.49 0.49
00228.json Access PackageManager and check for network connectivity 60% -1.33 -0.3325
00229.json Start an activity 100% 2.36 2.36
00230.json Start a background service 100% -1.41 -1.41
00231.json Get the package info of a particular app 100% 0.03 0.03
00232.json Create an intent based on the info from PackageManager 100% 0.33 0.33
00233.json Create an intent and check if any installed app can handle it 80% -0.93 -0.465
00234.json Monitor incoming SMS message 80% 0.18 0.09
00235.json Monitor outgoing phone call 80% 1.46 0.73
00236.json Write data to file 60% 1.11 0.2775
00237.json Write file content to an output stream 60% -0.62 -0.155
00238.json Extract screenshot data to bitmap format 40% 0.68 0.085
00239.json Establish a connection to an IP address 100% -0.25 -0.25
00240.json Simulate user gestures 20% 0.36 0.0225
00241.json Get the description of a UI element 40% -0.13 -0.01625
00242.json Write data to a file 60% -1.49 -0.3725
00243.json Connect to a URL and read data from it 40% 0.72 0.09
00244.json Write data to a file 100% -1.16 -1.16
00245.json Install other APKs from file 100% -0.31 -0.31
00246.json Create an overlay window on top of other applications 40% 0.99 0.12375
00247.json Establish a connection to an IP address 100% -0.16 -0.16
00248.json Establish a connection to an NFC card 20% 0.2 0.0125
00249.json Read the payment data stored in an NFC card 40% 0.31 0.03875
00250.json Create a UI layout from XML 100% 1.83 1.83
00251.json Listen for user clicks on a UI element 100% 1.42 1.42
00252.json Get the navigation bar height 100% -0.48 -0.48
00253.json Display URL content on a WebView 60% -0.27 -0.0675
00254.json Schedule a periodic job 100% 0.83 0.83
00255.json Save gestures into a list 40% 0.12 0.015
00256.json Read SMS message from PDU 0% 1.26 0
00257.json Get the status bar height 100% -0.8 -0.8
00258.json Create an overlay window on top of other applications 60% -0.29 -0.0725
00259.json Allow website to access internal methods 60% 0.1 0.025
00260.json Read SMS message from Intents 0% 1.14 0
00261.json Dispatch gesture from a list 40% 1.81 0.22625
00262.json Monitor device boot completion 80% -0.48 -0.24
00263.json Retrieve the application context and add a view to the window manager. 40% -0.19 -0.02375
00264.json Enumerate installed applications 40% 0.85 0.10625
00265.json Get application info and label 100% 0.33 0.33
00266.json Read clipboard 100% -1.66 -1.66
00267.json Dispatch gesture 20% -0.29 -0.018125
00268.json Allocate canvas 100% -0.98 -0.98
00269.json Compress bitmap 100% 0.04 0.04
00270.json Capture view 100% -1.29 -1.29
00271.json Accessing sensitive data from content provider 100% 0.12 0.12

Scoring Explained:

"Take Rule 00001.json (Bitmap Compression). At the 60% confidence level, Quark has identified the Permission and the Method call. However, it didn't hit 100% because the Data Flow (Stage 5) didn't show that compressed bitmap being sent to an external socket. In malware, that final stage is the 'Tainted Path'—the bridge between an app doing its job and an app stealing your screen."

Results Analysis

At first glance, seeing a security report mention "camera access," "SMS reading," and "location tracking" can be alarming. However, when you analyze these through the lens of a messaging app, the intent becomes clear: Utility, not Malice.

Core Communication Features

A messaging app without a camera or microphone isn't much of a messenger.

Open camera (00002.json) and Initialize recorder (00101.json).

These are essential for taking in-app photos and sending voice notes. The fact that the weights for these are near zero (or even negative) shows the analyzer recognizes these as standard, user-triggered events rather than background spying.

Account Verification & Contact Sync

You’ll notice flags for reading SMS contents (00048.json) and querying the IMSI/IMEI (00033.json, 00067.json).

Most modern messengers use your phone number as your ID. They need to read an incoming SMS to automatically verify your OTP (One-Time Password) and check the SIM status to ensure the account is tied to a valid device. Without these, the setup process would be a manual nightmare for the user.

Media Optimisation

There are several flags for "Initialise bitmap object and compress data" (00001.json) and "Put buffer stream to JSON object" (00015.json).

This is tech-speak for preparing a photo to be sent. When you attach a high-res photo, the app compresses it (the bitmap work) so it doesn't eat your data plan, then converts it into a format (the JSON/Stream work) that can be sent over the internet. The negative scores here prove the app is just being an efficient data-handler.

Location Sharing

The report mentions getting the device location (00075.json).

This is the "Send My Location" feature found in almost every chat app. Since this action is fragmented and lacks the high-frequency "heartbeat" score seen in tracking malware, it appears to be a dormant feature that only activates when the user explicitly hits "Share Location."

Overall Score

A total score of 2.34 is incredibly low. For perspective, actual spyware often scores in the hundreds because it performs these actions silently and simultaneously.

Quark-Engine is a pessimist by design. It sees a 'crime' in every permission. If we ran this same scan on Signal or WhatsApp, we would likely see similar flags for SMS reading and camera access. The reason the score remains a 2.34 is that Quark’s algorithm includes 'Negative Weights' for common behaviours. It recognises that in a communication-heavy environment, these are 'Necessary Evils' rather than 'Malicious Intents'.

In the world of professional forensics, we don't just look for "bad" code; we look for a Kill Chain. This is a sequence of linked behaviours that move an application from "functional tool" to "malicious actor." A typical mobile malware kill chain usually follows a predictable path: Persistence -> Privilege Escalation -> Stealth -> Exfiltration.

When we look at the Quark-Engine results for Max Messenger, the most striking thing isn't the presence of sensitive APIs, it’s the total collapse of this chain.

The Absence of Persistence

Most malware wants to survive a reboot. It will attempt to register itself as a "Boot Completed" listener (Rule 00262.json) or, more aggressively, hide its own icon (Rule 00079.json) to prevent the user from easily uninstalling it.

  • Max Messenger’s Reality: While the app can monitor boot completion (common for a messenger to ensure it can receive notifications), it makes no attempt to hide its presence. If an app isn't trying to hide, it’s usually because it doesn’t have anything to hide.

No Escalation of Force

Malware often tries to "break out" of the standard Android sandbox. This is usually done through Privilege Escalation, such as checking for Root access (Rule 00172.json) or abusing Accessibility Services to "read" the screen of other apps (Rules 0159-0161).

  • Max Messenger’s Reality: In our scan, these high-risk markers returned low confidence or zero-weight scores. The app is staying firmly within its assigned lane, using standard permissions for its intended purpose without trying to seize administrative control of the device.

The "Silent" Command & Control (C2)

The smoking gun for malware is a Command & Control (C2) link—a "heartbeat" to a remote server that waits for instructions to steal data or download additional payloads.

  • Max Messenger’s Reality: We see connections to URLs (Rule 00109.json), but Quark identifies these as simple HTTP response checks. There is no evidence of the complex, encrypted socket listeners or secondary "dropper" logic that characterises families like SpyNote.

Expert Insight: In a real "Kill Chain," you would see a 100% confidence link between Gathering Data (Reading SMS) and Exfiltration (Socket Connection). In Max Messenger, these behaviours are fragmented. They exist as isolated features (like verifying an OTP or checking for updates), but they never shake hands to form a malicious sequence.

By analysing the "Missing Kill Chain," we can see that Max Messenger lacks the predatory architecture of true malware. It possesses the capability to interact with sensitive data, as any messaging app must but it lacks the intent-driven logic required to weaponise that data against the user.

Investigating Max Messenger

Part 13 of 21

A research series here on the blog to dig into Max Messenger more deeply. My goal is to shine a light on what this app really is, how it works under the hood, and whether the concerns around it are warranted.

Up next

Max Messenger — Server-Side Toggle for Log Redaction

Continuing the Max Messenger research series, this post moves from broad evaluation into the hunt for specific 'surveillance signatures' within the codebase. In my recent summary of findings, I outlin