inputmethodservice-ime-abuse.md (4916B)
1 --- 2 title: "Android IME / InputMethodService Abuse (Malicious Keyboards)" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/inputmethodservice-ime-abuse.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/inputmethodservice-ime-abuse.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Android IME / InputMethodService Abuse (Malicious Keyboards) 14 15 ## Overview 16 17 Android allows third-party keyboards through `InputMethodService` (IME). Once a user **enables** a keyboard and selects it as the **current input method**, it participates in text entry across apps and can observe or influence much of the text sent through its input connection. Password fields can request reduced learning/suggestions, but applications must not treat an enabled third-party IME as a trusted boundary.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 18 19 This is why some Android banking trojans bundle or enable a custom keyboard: the malicious IME can receive keystrokes from target apps that never embed a `WebView`, including banking, chat, and wallet applications.<sup>[[4]](#references)</sup> 20 21 > [!NOTE] 22 > `android.permission.BIND_INPUT_METHOD` is declared on the IME *service* so only the system can bind to it. Declaring it does not grant the app blanket access by itself; the key step is getting the victim to **enable and select** the keyboard in Settings.<sup>[[1]](#references)</sup> 23 24 ## Manifest declaration 25 26 A keyboard is exposed via a service with the `android.view.InputMethod` intent action and an IME configuration XML: 27 28 ```xml 29 <!-- AndroidManifest.xml --> 30 <service 31 android:name=".SpyKeyboard" 32 android:permission="android.permission.BIND_INPUT_METHOD" 33 android:exported="false"> 34 35 <intent-filter> 36 <action android:name="android.view.InputMethod" /> 37 </intent-filter> 38 39 <meta-data 40 android:name="android.view.im" 41 android:resource="@xml/spy_ime" /> 42 </service> 43 ``` 44 45 **Hunting tip:** a non-keyboard-looking app that declares an `InputMethodService` is a strong red flag. 46 47 ## Where the data comes from 48 49 At runtime an IME learns: 50 51 - The **target app** being typed into (via `EditorInfo`, e.g. `attribute.packageName` in `onStartInput`). 52 - The text being entered (through the IME’s interaction with the current `InputConnection` and/or key events depending on the implementation). 53 54 Minimal (non-functional) sketch of the high-signal hook point: 55 56 ```java 57 public class SpyKeyboard extends InputMethodService { 58 @Override public void onStartInput(EditorInfo attribute, boolean restarting) { 59 // attribute.packageName identifies the foreground app receiving input 60 } 61 } 62 ``` 63 64 ## Common enablement & collection workflow (observed in the wild) 65 66 - The APK is marketed as a “secure keyboard” or the keyboard is embedded inside a broader trojan.<sup>[[4]](#references)</sup> 67 - The malware drives the victim into the system keyboard settings (for example, by launching `Settings.ACTION_INPUT_METHOD_SETTINGS` and/or using UI automation) until the IME is enabled and set as default.<sup>[[3]](#references)</sup> 68 - Keystrokes are buffered per-app and exfiltrated via the malware’s existing C2 channel, often combined with other data sources (e.g., `WebView` man-in-the-browser telemetry). 69 70 ## How to detect / triage 71 72 ### On-device checks 73 74 - **Settings**: Installed keyboards / default keyboard (look for unknown IMEs). 75 - **ADB**: 76 77 ```bash 78 adb shell dumpsys input_method 79 adb shell ime list -a 80 adb shell ime help 81 ``` 82 83 ### Static triage of an APK 84 85 - Look for `InputMethodService` classes and the `android.view.InputMethod` intent filter. 86 - Inspect `@xml/*` IME config referenced by `android.view.im`. 87 - Check whether the app’s stated functionality matches shipping a full keyboard UI/resources. 88 89 ## Mitigations 90 91 - **User/MDM**: allowlist trusted keyboards; block unknown IMEs in managed profiles/devices. 92 - **App-side (high risk apps)**: prefer phishing-resistant auth (passkeys/biometrics) and avoid relying on “secret text entry” as a security boundary (a malicious IME sits below the app UI). 93 94 ## References 95 96 - [1] [Android Developers - Creating an input method](https://developer.android.com/develop/ui/views/touch-and-input/creating-input-method) 97 - [2] [Android Developers - `EditorInfo.inputType`](https://developer.android.com/reference/android/view/inputmethod/EditorInfo#inputType) 98 - [3] [Android Developers - `Settings.ACTION_INPUT_METHOD_SETTINGS`](https://developer.android.com/reference/android/provider/Settings#ACTION_INPUT_METHOD_SETTINGS) 99 - [4] [Intel 471 - BlankBot custom `InputMethodService` keyboard](https://www.intel471.com/blog/blankbot-a-new-android-banking-trojan-with-screen-recording-keylogging-and-remote-control-capabilities)