android-application-level-virtualization.md (4694B)
1 --- 2 title: "Android Application-Level Virtualization (App Cloning)" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/android-application-level-virtualization.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/android-application-level-virtualization.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Android Application-Level Virtualization (App Cloning) 14 15 Application-level virtualization (app cloning/container frameworks such as DroidPlugin-style loaders) can run one or more APKs inside a host that controls lifecycle, class loading, storage, and permission mediation. In frameworks where guests execute under the host UID, Android's normal per-package UID isolation is collapsed; this behavior must be verified for the specific container rather than assumed for every cloning product.<sup>[[1]](#references)[[2]](#references)</sup> 16 17 ## Baseline install/launch vs virtualized execution 18 19 - **Normal install**: Package Manager installs an APK under an implementation-specific randomized `/data/app/` path, assigns an application UID, and Zygote normally forks a process that loads the app's `classes.dex` code. Historical layouts commonly resembled `/data/app/<random>/com.pkg-<random>/base.apk`; do not hardcode that shape on newer releases. Apps explicitly configured to share an identity are an exception to the one-package/one-UID simplification.<sup>[[2]](#references)</sup> 20 - **Dex load primitive**: `DexFile.openDexFile()` delegates to `openDexFileNative()` using absolute paths; virtualization layers commonly hook/redirect this to load guest dex from host-controlled paths.<sup>[[1]](#references)</sup> 21 - **Virtualized launch**: Host starts a process under **its UID**, loads the guest’s `base.apk`/dex with a custom loader, and exposes lifecycle callbacks via Java proxies. Guest storage API calls are remapped to host-controlled paths.<sup>[[1]](#references)</sup> 22 23 ## Abuse patterns 24 25 - **Permission escalation via shared UID**: Guests run under the host UID and can inherit **all host-granted permissions** even if not declared in the guest manifest. Over-permissioned hosts (massive `AndroidManifest.xml`) become “permission umbrellas”. 26 - **Stealthy code loading**: Host hooks `openDexFileNative`/class loaders to inject, replace, or instrument guest dex at runtime, bypassing static analysis. 27 - **Malicious host vs malicious guest**: 28 - *Evil host*: acts as dropper/executor, instruments/filters guest behavior, tampers with crashes. 29 - *Evil guest*: abuses shared UID to reach other guests’ data, ptrace them, or leverage host permissions.<sup>[[1]](#references)</sup> 30 31 ## Fingerprinting & detection 32 33 - **Multiple base.apk in one process**: A container often maps several APKs in the same PID. 34 ```bash 35 adb shell "cat /proc/<pid>/maps | grep base.apk" 36 # Suspicious: host base.apk + unrelated packages mapped together 37 ``` 38 - **Hooking/instrumentation artifacts**: Search for known libs (e.g., Frida) in maps and confirm on disk. 39 ```bash 40 adb shell "cat /proc/<pid>/maps | grep frida" 41 adb shell "file /data/app/..../lib/arm64/libfrida-gadget.so" 42 ``` 43 - **Crash-tamper probe**: Intentionally trigger an exception (e.g., NPE) and observe whether the process dies normally; hosts that intercept lifecycle/crash paths may swallow or rewrite crashes.<sup>[[1]](#references)</sup> 44 45 ## Hardening notes 46 47 - **Server-side attestation**: Use [Play Integrity](/hacktricks/mobile-pentesting/android-app-pentesting/play-integrity-attestation-bypass) as one risk signal for sensitive operations, verify tokens on the server, and combine it with account and transaction controls; it is not proof that no runtime instrumentation exists.<sup>[[3]](#references)</sup> 48 - **Use stronger isolation**: For supported system components and specialized workloads, **Android Virtualization Framework (AVF)** provides VM isolation that is materially different from an app container sharing a UID.<sup>[[4]](#references)</sup> 49 50 ## References 51 52 - [1] [Android Application-Level Virtualization (App Cloning) — How It Works, Abuse, and Detection](https://blog.azzahid.com/posts/android-app-virtualization/) 53 - [2] [Android Developers — Application sandbox](https://source.android.com/docs/security/app-sandbox) 54 - [3] [Android Developers — Play Integrity standard requests](https://developer.android.com/google/play/integrity/standard) 55 - [4] [Android Open Source Project — Android Virtualization Framework](https://source.android.com/docs/core/virtualization)