How to Create an Encrypted ZIP Archive on Android and Share It Securely with Nearby Share

9 min read Learn step‑by‑step how to make an AES‑256 encrypted ZIP file on Android using Termux or ZArchiver, then share it safely via Nearby Share without exposing your data. October 07, 2026 13:30 How to Create an Encrypted ZIP Archive on Android and Share It Securely with Nearby Share

Why encrypt before sharing?

When you send files directly through Nearby Share, the transfer itself is encrypted, but the files remain in plain text on the receiving device. If the recipient’s device is compromised or you later need to store the archive, the data stays exposed. Wrapping the files in an AES‑256 encrypted ZIP guarantees that only someone who knows the password can open the archive, even if the file falls into the wrong hands.

Both Termux (command‑line) and ZArchiver (GUI) are free, open‑source tools that work on Android 6.0+ without root.

Before you start

  • Charge your phone to at least 50 % (encryption can be CPU‑intensive).
  • Connect to a stable Wi‑Fi network – you’ll be downloading a few packages.
  • Identify the files you want to protect (photos, PDFs, etc.). Keep them in a single folder for easier archiving.
  • Choose a strong password (minimum 12 characters, mix of letters, numbers, symbols). Write it down somewhere safe; forgetting it makes the archive unrecoverable.
  • If you plan to use the command‑line method, enable Termux storage access: open Termux and run termux-setup-storage.

Method 1 – Command‑line with Termux

This approach gives you full control over encryption parameters and works on any device that can run Termux.

Step 1: Install Termux and required packages

  1. Open the Play Store or F‑Droid, search for Termux, and install it.
  2. Launch Termux. The first launch may ask for storage permission – grant it.
  3. Update the package list and install p7zip (the 7‑Zip command‑line tool):
    pkg update && pkg upgrade -y
    pkg install p7zip -y

Step 2: Prepare the source folder

  1. Move (or copy) the files you want to encrypt into a folder you can easily reference, e.g. /sdcard/EncryptMe. You can use a file manager or the mv command:
    mkdir -p /sdcard/EncryptMe
    mv /sdcard/Download/important.pdf /sdcard/EncryptMe/
  2. Verify the folder contents with:
    ls -l /sdcard/EncryptMe

Step 3: Create the encrypted ZIP

  1. Run the 7‑Zip command, replacing MySecretPassword with your chosen password:
    7z a -tzip -pMySecretPassword -mem=AES256 /sdcard/EncryptMe.zip /sdcard/EncryptMe/*
    • a – add files to an archive.
    • -tzip – specify ZIP format (compatible with most OSes).
    • -p – set the password.
    • -mem=AES256 – enforce AES‑256 encryption.
  2. Wait for the process to finish. Termux will display a progress line and then return to the prompt.
  3. Check that the archive was created:
    ls -l /sdcard/EncryptMe.zip

Step 4: Verify the archive (optional but recommended)

  1. Test the archive without extracting:
    7z t -pMySecretPassword /sdcard/EncryptMe.zip
  2. If the output ends with Everything is OK, the encryption succeeded.
  3. To preview the file list without extracting, run:
    7z l /sdcard/EncryptMe.zip

Step 5: Share via Nearby Share

  1. Open the Android Files app (or any file manager) and navigate to /sdcard/EncryptMe.zip.
  2. Long‑press the file and tap the Share icon.
  3. Select Nearby Share from the share sheet.
  4. Make sure the receiving device has Nearby Share turned on (Settings > Google > Device connections > Nearby Share) and is within ~10 m.
  5. Tap the receiving device’s name; the transfer will begin. Android encrypts the transport, and your ZIP remains encrypted on both ends.

Method 2 – GUI with ZArchiver (no command line)

If you prefer a visual approach, ZArchiver provides a straightforward way to create AES‑256 encrypted ZIPs.

Step 1: Install ZArchiver

  1. Download ZArchiver from the Play Store (free) or F‑Droid.
  2. Open the app and grant it storage access when prompted.

Step 2: Create the archive

  1. Navigate to the folder containing the files you want to protect.
  2. Tap the three‑dot menu in the upper‑right corner and choose Compress.
  3. In the dialog:
    • Set Archive name (e.g., SecureDocs.zip).
    • Choose ZIP as the format.
    • Enable Encryption and select AES‑256.
    • Enter your password twice.
  4. Tap OK. ZArchiver will show a progress bar and then list the new archive.

Step 3: Verify (optional)

  1. Long‑press the newly created .zip file and choose Test archive. ZArchiver will report success or any errors.

Step 4: Share with Nearby Share

  1. From ZArchiver, long‑press the archive and tap the Share button.
  2. Select Nearby Share and follow the same steps as in Method 1.

Understanding the encryption choices

Both methods use AES‑256, the current industry‑standard for symmetric encryption. The ZIP format stores the password‑derived key in the file header, but the actual file contents remain unreadable without the password. This is different from password‑protected ZIP implementations that rely on weaker ZipCrypto – our steps explicitly request AES‑256.

Troubleshooting

  • “Password incorrect” when opening the archive: Verify you typed the exact same password when creating the ZIP. Passwords are case‑sensitive and spaces count. If you used Termux, remember that the command line does not hide the password; a stray space can cause a mismatch.
  • File not found / permission denied: On Android 11+ the app may be restricted by scoped storage. Ensure you granted Termux the MANAGE_EXTERNAL_STORAGE permission (Settings > Apps > Termux > Permissions) or keep the files inside the ~/storage/shared directory created by termux-setup-storage.
  • Nearby Share shows “Device not visible”: Both devices must have Bluetooth and location services enabled. Turn them on, then retry. Also, make sure the receiving device is set to receive files from “Everyone” or “Contacts only” as appropriate.
  • Archive size seems larger than original files: AES‑256 adds a small overhead (about 12 bytes per file plus padding). If the increase is dramatic, double‑check you didn’t accidentally compress an already‑compressed file (e.g., a video) with the -mx=9 flag, which can inflate size.
  • Unable to open the ZIP on Windows: Use a recent version of 7‑Zip or WinRAR that supports ZIP AES‑256. Older built‑in Windows zip utilities may not recognise the encryption.

Safety warnings

Never store the password in the same location as the encrypted archive. If the password is lost, the data cannot be recovered. Additionally, avoid sharing the password over insecure channels (e.g., plain SMS).

Alternative ways to encrypt files on Android

  • Cryptomator – creates a virtual vault with transparent AES‑256 encryption. Good for cloud‑synced folders.
  • OpenKeychain + GnuPG – for PGP‑style encryption, useful when you need asymmetric keys.
  • VeraCrypt (via Termux) – creates encrypted containers larger than 4 GB, but requires more setup.

When to use this workflow

This method shines in scenarios where you need to:

  • Send confidential documents to a colleague without exposing them to the recipient’s OS.
  • Back up personal data to a shared cloud folder while keeping the contents unreadable to the cloud provider.
  • Archive sensitive screenshots, receipts, or private media before handing the device to a technician.

By combining a strong AES‑256 ZIP with Android’s peer‑to‑peer Nearby Share, you get both transport‑level encryption and at‑rest protection, covering the two most common attack vectors for file sharing.

User Comments (0)

Add Comment
We'll never share your email with anyone else.