tapjacking.md (10363B)
1 --- 2 title: "Tapjacking" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/tapjacking.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/tapjacking.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Tapjacking 14 15 ## **Basic Information** 16 17 **Tapjacking** is an attack where a **malicious** **application** is launched and **positions itself on top of a victim application**. Once it visibly obscures the victim app, its user interface is designed in such a way as to trick the user to interact with it, while it is passing the interaction along to the victim app.\ 18 In effect, it is **blinding the user from knowing they are actually performing actions on the victim app**. 19 20 ### Detection 21 22 * Look for **exported activities** in the Android manifest (an activity with an intent-filter is exported by default). If an exported activity is protected by a permission, the attacking app will need the **same permission**, which limits exploitability. 23 * Check the **minimum SDK** version `android:minSdkVersion` in `AndroidManifest.xml`. If it is **lower than 30**, older default behaviors may make tapjacking easier to exploit. 24 * At runtime, use `logcat` to spot blocked touches on Android 12+: the system logs `Untrusted touch due to occlusion by <package>` when overlays are filtered. 25 26 ### Protection 27 28 #### Android 12+ default blocking & compat flags 29 30 Android 12 (API 31) introduced **"Block untrusted touches"**: touches coming from another UID window of type `TYPE_APPLICATION_OVERLAY` (opacity ≥0.8) are dropped. This is enabled by default.<sup>[[1]](#references)</sup> During tests you can toggle it: 31 32 ```bash 33 # disable blocking for a specific package (for PoC crafting) 34 adb shell am compat disable BLOCK_UNTRUSTED_TOUCHES com.example.victim 35 # re‑enable 36 adb shell am compat reset BLOCK_UNTRUSTED_TOUCHES com.example.victim 37 ``` 38 39 Trusted windows (accessibility, IME, assistant) still receive events. Invisible or fully transparent overlays also bypass the block, which attackers try to abuse by keeping `alpha < 0.8`. 40 41 #### Handling **partial occlusion** 42 43 Partial overlays that leave the target area visible are not auto-blocked. Mitigate in sensitive views by rejecting events with the **`FLAG_WINDOW_IS_PARTIALLY_OBSCURED`** flag:<sup>[[1]](#references)</sup> 44 45 ```java 46 @Override 47 public boolean onFilterTouchEventForSecurity(MotionEvent event) { 48 if ((event.getFlags() & MotionEvent.FLAG_WINDOW_IS_PARTIALLY_OBSCURED) != 0) { 49 return false; // drop tap when anything partially obscures us 50 } 51 return super.onFilterTouchEventForSecurity(event); 52 } 53 ``` 54 55 #### `filterTouchesWhenObscured` 56 57 If **`android:filterTouchesWhenObscured`** is set to **`true`**, the `View` will not receive touches whenever view's window is obscured by another visible window. 58 59 #### **`setFilterTouchesWhenObscured`** 60 61 The attribute **`setFilterTouchesWhenObscured`** set to true can also prevent the exploitation of this vulnerability if the Android version is lower.\ 62 If set to **`true`**, for example, a button can be automatically **disabled if it is obscured**: 63 64 ```xml 65 <Button android:text="Button" 66 android:id="@+id/button1" 67 android:layout_width="wrap_content" 68 android:layout_height="wrap_content" 69 android:filterTouchesWhenObscured="true"> 70 </Button> 71 ``` 72 73 ## Exploitation 74 75 ### Tapjacking-ExportedActivity 76 77 The most **recent Android application** performing a Tapjacking attack (+ invoking before an exported activity of the attacked application) can be found in: [**https://github.com/carlospolop/Tapjacking-ExportedActivity**](https://github.com/carlospolop/Tapjacking-ExportedActivity). 78 79 Follow the **README instructions to use it**. 80 81 ### FloatingWindowApp 82 83 An example project implementing **FloatingWindowApp**, which can be used to put on top of other activities to perform a clickjacking attack, can be found in [**FloatingWindowApp**](https://github.com/aminography/FloatingWindowApp) (a bit old, good luck building the apk). 84 85 ### Qark 86 87 > [!CAUTION] 88 > It looks like this project is now unmaintained and this functionality isn't properly working anymore 89 90 You can use [**qark**](https://github.com/linkedin/qark) with the `--exploit-apk` --sdk-path `/Users/username/Library/Android/sdk` parameters to create a malicious application to test for possible **Tapjacking** vulnerabilities.\ 91 92 The mitigation is relatively simple as the developer may choose not to receive touch events when a view is covered by another. Using the [Android Developer’s Reference](https://developer.android.com/reference/android/view/View#security): 93 94 > Sometimes it is essential that an application be able to verify that an action is being performed with the full knowledge and consent of the user, such as granting a permission request, making a purchase or clicking on an advertisement. Unfortunately, a malicious application could try to spoof the user into performing these actions, unaware, by concealing the intended purpose of the view. As a remedy, the framework offers a touch filtering mechanism that can be used to improve the security of views that provide access to sensitive functionality. 95 > 96 > To enable touch filtering, call [`setFilterTouchesWhenObscured(boolean)`](https://developer.android.com/reference/android/view/View#setFilterTouchesWhenObscured%28boolean%29) or set the android:filterTouchesWhenObscured layout attribute to true. When enabled, the framework will discard touches that are received whenever the view's window is obscured by another visible window. As a result, the view will not receive touches whenever a toast, dialog or other window appears above the view's window. 97 98 --- 99 100 ### Recent overlay-based malware techniques 101 102 * **Hook/Ermac variants** use nearly transparent overlays (e.g., fake NFC prompts) to capture gestures and lock-screen PINs while forwarding touches underneath, delivered via Accessibility-ATS modules.<sup>[[2]](#references)</sup> 103 * **Anatsa/TeaBot droppers** ship overlays for hundreds of banking/crypto apps and show full-screen "maintenance" overlays to stall victims while ATS completes transfers.<sup>[[2]](#references)</sup> 104 * **Hidden-VNC banking RATs** briefly display phishing overlays to capture credentials, then rely on covert VNC plus Accessibility to replay taps with fewer on-device artifacts. 105 106 Practical takeaway for red teams: mix an `alpha < 0.8` overlay to bypass Android 12 blocking, then escalate to a full-screen accessibility overlay once the user toggles the service. Instrument `GestureDescription` or a headless VNC to keep control after credentials are captured. 107 108 --- 109 110 ## Accessibility Overlay Phishing (Banking-Trojan Variant) 111 112 Besides classic Tapjacking, modern Android banking malware families (e.g. **ToxicPanda**, BrasDex, Sova, etc.) abuse the **Accessibility Service** to place a full-screen WebView **overlay** above the legitimate application while still being able to **forward the user input** to the view underneath. This dramatically increases believability and allows attackers to steal credentials, OTPs or even automate fraudulent transactions.<sup>[[3]](#references)</sup> 113 114 ### How it works 115 1. The malicious APK requests the highly-sensitive `BIND_ACCESSIBILITY_SERVICE` permission, usually hiding the request behind a fake Google/Chrome/PDF-viewer dialog. 116 2. Once the user enables the service, the malware programmatically simulates the taps required to grant additional dangerous permissions (`READ_SMS`, `SYSTEM_ALERT_WINDOW`, `REQUEST_INSTALL_PACKAGES`, …). 117 3. A **WebView** is inflated and added to the window manager using the **`TYPE_ACCESSIBILITY_OVERLAY`** window type. The overlay can be rendered totally opaque or semi-transparent and can be flagged as *“through”* so that the original touches are still delivered to the background activity (thus the transaction really happens while the victim only sees the phishing form). 118 119 ```java 120 WebView phishingView = new WebView(getApplicationContext()); 121 phishingView.getSettings().setJavaScriptEnabled(true); 122 phishingView.loadUrl("file:///android_asset/bank_login.html"); 123 124 WindowManager wm = (WindowManager) getSystemService(WINDOW_SERVICE); 125 WindowManager.LayoutParams lp = new WindowManager.LayoutParams( 126 WindowManager.LayoutParams.MATCH_PARENT, 127 WindowManager.LayoutParams.MATCH_PARENT, 128 WindowManager.LayoutParams.TYPE_ACCESSIBILITY_OVERLAY, // <-- bypasses SYSTEM_ALERT_WINDOW prompt 129 WindowManager.LayoutParams.FLAG_NOT_FOCUSABLE | 130 WindowManager.LayoutParams.FLAG_NOT_TOUCH_MODAL, // «through» flag → forward touches 131 PixelFormat.TRANSLUCENT); 132 wm.addView(phishingView, lp); 133 ``` 134 135 ### Typical workflow used by banking Trojans 136 * Query installed packages (`QUERY_ALL_PACKAGES`) to figure out which banking / wallet app is currently opened. 137 * Download an **HTML/JS overlay template** from the C2 that perfectly imitates that specific application (Logo, colours, i18n strings…). 138 * Display the overlay, harvest credentials/PIN/pattern. 139 * Use the **Accessibility API** (`performGlobalAction`, `GestureDescription`) to automate transfers in the background. 140 141 ### Detection & Mitigation 142 * Audit the list of installed apps with `adb shell pm list packages -3 -e BIND_ACCESSIBILITY_SERVICE`. 143 * From the application side (bank / wallet): 144 - Enable **`android:accessibilityDataSensitive="accessibilityDataPrivateYes"`** (Android 14+) on sensitive views to block non-Play-Store services. 145 - Combine with `setFilterTouchesWhenObscured(true)` and `FLAG_SECURE`. 146 147 For additional details on leveraging Accessibility Services for full remote device control (e.g. PlayPraetor, SpyNote, etc.) see: 148 149 150 [Accessibility Services Abuse](/hacktricks/mobile-pentesting/android-app-pentesting/accessibility-services-abuse) 151 152 ## References 153 - [1] [Android Developers – Tapjacking risk & mitigations (updated 2024)](https://developer.android.com/privacy-and-security/risks/tapjacking) 154 - [2] [Zimperium – HOOK v3 overlay expansion (Aug 2025)](https://thehackernews.com/2025/08/hook-android-trojan-adds-ransomware.html) 155 - [3] [Bitsight – ToxicPanda: The Android Banking Trojan Targeting Europe](https://www.bitsight.com/blog/toxicpanda-android-banking-malware-2025-study)