daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

inputmethodservice-ime-abuse.md (4916B)


      1 ---
      2 title: "Android IME / InputMethodService Abuse (Malicious Keyboards)"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/inputmethodservice-ime-abuse.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/inputmethodservice-ime-abuse.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Android IME / InputMethodService Abuse (Malicious Keyboards)
     14 
     15 ## Overview
     16 
     17 Android allows third-party keyboards through `InputMethodService` (IME). Once a user **enables** a keyboard and selects it as the **current input method**, it participates in text entry across apps and can observe or influence much of the text sent through its input connection. Password fields can request reduced learning/suggestions, but applications must not treat an enabled third-party IME as a trusted boundary.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     18 
     19 This is why some Android banking trojans bundle or enable a custom keyboard: the malicious IME can receive keystrokes from target apps that never embed a `WebView`, including banking, chat, and wallet applications.<sup>[[4]](#references)</sup>
     20 
     21 > [!NOTE]
     22 > `android.permission.BIND_INPUT_METHOD` is declared on the IME *service* so only the system can bind to it. Declaring it does not grant the app blanket access by itself; the key step is getting the victim to **enable and select** the keyboard in Settings.<sup>[[1]](#references)</sup>
     23 
     24 ## Manifest declaration
     25 
     26 A keyboard is exposed via a service with the `android.view.InputMethod` intent action and an IME configuration XML:
     27 
     28 ```xml
     29 <!-- AndroidManifest.xml -->
     30 <service
     31     android:name=".SpyKeyboard"
     32     android:permission="android.permission.BIND_INPUT_METHOD"
     33     android:exported="false">
     34 
     35     <intent-filter>
     36         <action android:name="android.view.InputMethod" />
     37     </intent-filter>
     38 
     39     <meta-data
     40         android:name="android.view.im"
     41         android:resource="@xml/spy_ime" />
     42 </service>
     43 ```
     44 
     45 **Hunting tip:** a non-keyboard-looking app that declares an `InputMethodService` is a strong red flag.
     46 
     47 ## Where the data comes from
     48 
     49 At runtime an IME learns:
     50 
     51 - The **target app** being typed into (via `EditorInfo`, e.g. `attribute.packageName` in `onStartInput`).
     52 - The text being entered (through the IME’s interaction with the current `InputConnection` and/or key events depending on the implementation).
     53 
     54 Minimal (non-functional) sketch of the high-signal hook point:
     55 
     56 ```java
     57 public class SpyKeyboard extends InputMethodService {
     58   @Override public void onStartInput(EditorInfo attribute, boolean restarting) {
     59     // attribute.packageName identifies the foreground app receiving input
     60   }
     61 }
     62 ```
     63 
     64 ## Common enablement & collection workflow (observed in the wild)
     65 
     66 - The APK is marketed as a “secure keyboard” or the keyboard is embedded inside a broader trojan.<sup>[[4]](#references)</sup>
     67 - The malware drives the victim into the system keyboard settings (for example, by launching `Settings.ACTION_INPUT_METHOD_SETTINGS` and/or using UI automation) until the IME is enabled and set as default.<sup>[[3]](#references)</sup>
     68 - Keystrokes are buffered per-app and exfiltrated via the malware’s existing C2 channel, often combined with other data sources (e.g., `WebView` man-in-the-browser telemetry).
     69 
     70 ## How to detect / triage
     71 
     72 ### On-device checks
     73 
     74 - **Settings**: Installed keyboards / default keyboard (look for unknown IMEs).
     75 - **ADB**:
     76 
     77 ```bash
     78 adb shell dumpsys input_method
     79 adb shell ime list -a
     80 adb shell ime help
     81 ```
     82 
     83 ### Static triage of an APK
     84 
     85 - Look for `InputMethodService` classes and the `android.view.InputMethod` intent filter.
     86 - Inspect `@xml/*` IME config referenced by `android.view.im`.
     87 - Check whether the app’s stated functionality matches shipping a full keyboard UI/resources.
     88 
     89 ## Mitigations
     90 
     91 - **User/MDM**: allowlist trusted keyboards; block unknown IMEs in managed profiles/devices.
     92 - **App-side (high risk apps)**: prefer phishing-resistant auth (passkeys/biometrics) and avoid relying on “secret text entry” as a security boundary (a malicious IME sits below the app UI).
     93 
     94 ## References
     95 
     96 - [1] [Android Developers - Creating an input method](https://developer.android.com/develop/ui/views/touch-and-input/creating-input-method)
     97 - [2] [Android Developers - `EditorInfo.inputType`](https://developer.android.com/reference/android/view/inputmethod/EditorInfo#inputType)
     98 - [3] [Android Developers - `Settings.ACTION_INPUT_METHOD_SETTINGS`](https://developer.android.com/reference/android/provider/Settings#ACTION_INPUT_METHOD_SETTINGS)
     99 - [4] [Intel 471 - BlankBot custom `InputMethodService` keyboard](https://www.intel471.com/blog/blankbot-a-new-android-banking-trojan-with-screen-recording-keylogging-and-remote-control-capabilities)