Once upon a time, Google took a tradeoff - an open permission model over an open source system, so developers thrive. Today, 10 years later, Android permissions are abused by Malware, Ad Fraud SDKs, and even state actors. In this talk Adam will overview the reverse engineering of 3 malware frameworks, and how they utilize different vulnerabilities to bypass Android's protections. The analysis will outline the issues from the bits and bytes, through the root cause, to how developers can protect themselves from being hacked by threat actors using their operating system against them.