The digital world has simplified life through technology, particularly with the significant role of smartphones. Android has become the dominant operating system in Indonesia, but its widespread use also increases potential security vulnerabilities, especially since many users lack understanding of data security. During the period of 2018-2020, around 74.95% of smartphone users in Indonesia used Android, most of whom were regular users who may not be aware of data security issues. This research aims to analyze the vulnerabilities of Android devices and the characteristics of the wedding invitation.apk application using reverse engineering to identify malware. Reverse engineering was used to extract data from the wedding invitation.apk file. The research results showed the presence of Spyware malware in the application, which, after installation, could send sensitive data to an external server without adequate protection and access data through OTP SMS and a Telegram bot. This application has the potential to misuse permissions to access SMS, send sensitive data to external servers without permission, and automatically send SMS. To reduce risks, it is recommended to download applications only from trusted sources, check application permissions before installation, regularly update the operating system and applications, and use security applications. This research emphasizes the importance of better security practices in mobile application development to protect users' privacy and data integrity.
Copyrights © 2025