LANDFALL Android Spyware SELinux Policy Manipulation

Detects the LANDFALL Android spyware manipulating SELinux policy by preloading a malicious shared object and passing a path to the 'l.so' policy manipulator component via the PRELOAD_PATH environment variable.