Kimwolf: su persistence of hidden binary under disguised app-data package path

Detects the execution of 'su' or 'sh' binaries from within suspicious application-specific directories on Android devices. These directories typically house application libraries or data, and execution of system binaries from these locations, particularly when combined with arguments like 'persisted' or 'exit', is indicative of privilege escalation attempts or malicious persistence mechanisms by Android malware.