I've just published a blog post on a new sample of Android/BianLian botnet which uses (1) an intentionally bad formed ZIP, and (2) uses a new packer.
https://cryptax.medium.com/bad-zip-and-new-packer-for-android-bianlian-5bdad4b90aeb
By the way, this will be covered in my @ringzer0 training.