daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

spoofing-your-location-in-play-store.md (5605B)


      1 ---
      2 title: "Spoofing Your Location in Google Play Store"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/spoofing-your-location-in-play-store.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/spoofing-your-location-in-play-store.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Spoofing Your Location in Google Play Store
     14 
     15 Google Play storefront georestrictions are usually enforced by a mix of **Play country / billing profile**, **network geolocation**, and **cached Play state** — not only by the phone GPS. Therefore a VPN alone sometimes works, but in newer Play flows you usually also need to reset cached state and, for real country/profile switches, use an account/payment profile that matches the target country.
     16 
     17 If your goal is only to **obtain the APK for reversing**, it is often easier to use the alternative acquisition workflow documented in [Android Applications Pentesting](/hacktricks/mobile-pentesting/android-app-pentesting/overview) instead of fighting the storefront.
     18 
     19 ## What Google Play Actually Checks
     20 
     21 - **Current network location** (the country seen from the exit IP).
     22 - The **Google Play country/profile** attached to the account and Google Payments profile.
     23 - Cached state in **`com.android.vending`**, **`com.google.android.gms`**, and **Download Manager**.
     24 - Whether the package is **published in that country** by the developer.
     25 - In some cases, **device certification / integrity** (this is a different problem from pure region spoofing).
     26 
     27 If an app is hidden because the device is not **Play-certified** or fails attestation, check [Play Integrity attestation spoofing](/hacktricks/mobile-pentesting/android-app-pentesting/play-integrity-attestation-bypass).
     28 
     29 ## Fast Path on a Non-Rooted Device
     30 
     31 1. **Connect to a VPN** endpoint in the target country.
     32 2. Prefer a **fresh test Google account** already configured for that country. Reusing an account from another country often triggers the _selected Play country matches your country of residence_ error.
     33 3. **Clear Play state** from the GUI or directly with `adb`:
     34 
     35 ```bash
     36 adb shell am force-stop com.android.vending
     37 adb shell pm clear com.android.vending
     38 adb shell am force-stop com.google.android.gms
     39 adb shell pm clear com.google.android.gms
     40 adb shell am force-stop com.android.providers.downloads
     41 adb shell pm clear com.android.providers.downloads
     42 ```
     43 
     44 4. Re-open **Play Store** and inspect **Settings --> General --> Account and device preferences --> Country and profiles**.<sup>[[1]](#references)</sup>
     45 5. If the target country/profile appears, switch to it and retry the install. Google Play profile changes can take **up to 48 hours** to fully update.
     46 6. If the country/profile does not appear, remember that Google expects you to be **in the target country** and to have a **payment method from that country** when creating a new Play country/profile.
     47 
     48 ## Rooted / Emulator Workflow
     49 
     50 When the target app checks GPS after installation, align the device geolocation with the storefront country:
     51 
     52 - **Android Emulator**: send a GPS fix directly to the emulator:<sup>[[3]](#references)</sup>
     53 
     54 ```bash
     55 adb -e emu geo fix -3.7038 40.4168   # longitude latitude (Madrid)
     56 ```
     57 
     58 - **Physical device**: enable **Developer options --> Select mock location app** and set your GPS spoofer as the mock provider. If you need to do it from the shell:
     59 
     60 ```bash
     61 adb shell appops set <MOCK_LOCATION_APP_PKG> android:mock_location allow
     62 ```
     63 
     64 ## Bypassing App-Side Mock-Location Checks
     65 
     66 Modern Android apps can detect lab GPS spoofing by calling **`Location.isMock()`** (API 31+) or the legacy **`isFromMockProvider()`**. On an authorized rooted lab, LSPosed modules such as **HideMockLocation** or a Frida hook can neutralize these checks:<sup>[[2]](#references)</sup><sup>[[4]](#references)</sup>
     67 
     68 ```javascript
     69 Java.perform(function () {
     70   const L = Java.use('android.location.Location');
     71   try { L.isMock.implementation = function () { return false; }; } catch (e) {}
     72   try { L.isFromMockProvider.implementation = function () { return false; }; } catch (e) {}
     73 });
     74 ```
     75 
     76 Keep the hook scoped to the **target app** when possible: the Play Store itself is mostly country/profile/IP driven, while the **installed app** is the component that commonly performs the GPS/mock-location check.
     77 
     78 ## Common Failure Modes
     79 
     80 - A **VPN only changes the IP**; it does not rewrite the Google Payments profile behind the account.
     81 - Clearing only **Play Store** is frequently insufficient; also reset **Google Play services** and **Download Manager**.
     82 - Google currently enforces a **cooldown between Play country changes**, and **Family group** membership can block switching countries.
     83 - Even after installation, the app backend may still geofence you using **GPS, IP, SIM MCC/MNC, phone number, locale, or server-side KYC**.
     84 - Some install failures are actually **Play Integrity / certification** failures rather than country failures.
     85 
     86 ## References
     87 
     88 - [1] [Google Play Help: How to change your Google Play country](https://support.google.com/googleplay/answer/7431675?hl=en)
     89 - [2] [HideMockLocation (LSPosed/Xposed)](https://modules.lsposed.org/module/io.github.auag0.hidemocklocation/)
     90 - [3] [Android Emulator console - `geo fix`](https://developer.android.com/studio/run/emulator-console#geo)
     91 - [4] [Android `Location.isMock()` API](https://developer.android.com/reference/android/location/Location#isMock())