From APK to Golden Ticket

Owning an Android smartphone and gaining Domain Admin rights
and more…

Andrea Pierini <>, Giuseppe Trotta <>

February 24, 2017

This article describes the potential dangers of using personal smartphones in corporate
networks and as a result has been modeled after real events. It has been demonstrated that
it is not so difficult for ill­intentioned to deceive an employee installing a malicious app on his
smartphone, circumvent network protections, gain access to the corporate network, escalate
privileges and access reserved information.

