daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

android-application-level-virtualization.md (4694B)


      1 ---
      2 title: "Android Application-Level Virtualization (App Cloning)"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/android-application-level-virtualization.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/android-application-level-virtualization.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Android Application-Level Virtualization (App Cloning)
     14 
     15 Application-level virtualization (app cloning/container frameworks such as DroidPlugin-style loaders) can run one or more APKs inside a host that controls lifecycle, class loading, storage, and permission mediation. In frameworks where guests execute under the host UID, Android's normal per-package UID isolation is collapsed; this behavior must be verified for the specific container rather than assumed for every cloning product.<sup>[[1]](#references)[[2]](#references)</sup>
     16 
     17 ## Baseline install/launch vs virtualized execution
     18 
     19 - **Normal install**: Package Manager installs an APK under an implementation-specific randomized `/data/app/` path, assigns an application UID, and Zygote normally forks a process that loads the app's `classes.dex` code. Historical layouts commonly resembled `/data/app/<random>/com.pkg-<random>/base.apk`; do not hardcode that shape on newer releases. Apps explicitly configured to share an identity are an exception to the one-package/one-UID simplification.<sup>[[2]](#references)</sup>
     20 - **Dex load primitive**: `DexFile.openDexFile()` delegates to `openDexFileNative()` using absolute paths; virtualization layers commonly hook/redirect this to load guest dex from host-controlled paths.<sup>[[1]](#references)</sup>
     21 - **Virtualized launch**: Host starts a process under **its UID**, loads the guest’s `base.apk`/dex with a custom loader, and exposes lifecycle callbacks via Java proxies. Guest storage API calls are remapped to host-controlled paths.<sup>[[1]](#references)</sup>
     22 
     23 ## Abuse patterns
     24 
     25 - **Permission escalation via shared UID**: Guests run under the host UID and can inherit **all host-granted permissions** even if not declared in the guest manifest. Over-permissioned hosts (massive `AndroidManifest.xml`) become “permission umbrellas”.
     26 - **Stealthy code loading**: Host hooks `openDexFileNative`/class loaders to inject, replace, or instrument guest dex at runtime, bypassing static analysis.
     27 - **Malicious host vs malicious guest**:
     28   - *Evil host*: acts as dropper/executor, instruments/filters guest behavior, tampers with crashes.
     29   - *Evil guest*: abuses shared UID to reach other guests’ data, ptrace them, or leverage host permissions.<sup>[[1]](#references)</sup>
     30 
     31 ## Fingerprinting & detection
     32 
     33 - **Multiple base.apk in one process**: A container often maps several APKs in the same PID.
     34   ```bash
     35   adb shell "cat /proc/<pid>/maps | grep base.apk"
     36   # Suspicious: host base.apk + unrelated packages mapped together
     37   ```
     38 - **Hooking/instrumentation artifacts**: Search for known libs (e.g., Frida) in maps and confirm on disk.
     39   ```bash
     40   adb shell "cat /proc/<pid>/maps | grep frida"
     41   adb shell "file /data/app/..../lib/arm64/libfrida-gadget.so"
     42   ```
     43 - **Crash-tamper probe**: Intentionally trigger an exception (e.g., NPE) and observe whether the process dies normally; hosts that intercept lifecycle/crash paths may swallow or rewrite crashes.<sup>[[1]](#references)</sup>
     44 
     45 ## Hardening notes
     46 
     47 - **Server-side attestation**: Use [Play Integrity](/hacktricks/mobile-pentesting/android-app-pentesting/play-integrity-attestation-bypass) as one risk signal for sensitive operations, verify tokens on the server, and combine it with account and transaction controls; it is not proof that no runtime instrumentation exists.<sup>[[3]](#references)</sup>
     48 - **Use stronger isolation**: For supported system components and specialized workloads, **Android Virtualization Framework (AVF)** provides VM isolation that is materially different from an app container sharing a UID.<sup>[[4]](#references)</sup>
     49 
     50 ## References
     51 
     52 - [1] [Android Application-Level Virtualization (App Cloning) — How It Works, Abuse, and Detection](https://blog.azzahid.com/posts/android-app-virtualization/)
     53 - [2] [Android Developers — Application sandbox](https://source.android.com/docs/security/app-sandbox)
     54 - [3] [Android Developers — Play Integrity standard requests](https://developer.android.com/google/play/integrity/standard)
     55 - [4] [Android Open Source Project — Android Virtualization Framework](https://source.android.com/docs/core/virtualization)