daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

tapjacking.md (10363B)


      1 ---
      2 title: "Tapjacking"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/tapjacking.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/tapjacking.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Tapjacking
     14 
     15 ## **Basic Information**
     16 
     17 **Tapjacking** is an attack where a **malicious** **application** is launched and **positions itself on top of a victim application**. Once it visibly obscures the victim app, its user interface is designed in such a way as to trick the user to interact with it, while it is passing the interaction along to the victim app.\
     18 In effect, it is **blinding the user from knowing they are actually performing actions on the victim app**.
     19 
     20 ### Detection
     21 
     22 * Look for **exported activities** in the Android manifest (an activity with an intent-filter is exported by default). If an exported activity is protected by a permission, the attacking app will need the **same permission**, which limits exploitability.
     23 * Check the **minimum SDK** version `android:minSdkVersion` in `AndroidManifest.xml`. If it is **lower than 30**, older default behaviors may make tapjacking easier to exploit.
     24 * At runtime, use `logcat` to spot blocked touches on Android 12+: the system logs `Untrusted touch due to occlusion by <package>` when overlays are filtered.
     25 
     26 ### Protection
     27 
     28 #### Android 12+ default blocking & compat flags
     29 
     30 Android 12 (API 31) introduced **"Block untrusted touches"**: touches coming from another UID window of type `TYPE_APPLICATION_OVERLAY` (opacity ≥0.8) are dropped. This is enabled by default.<sup>[[1]](#references)</sup> During tests you can toggle it:
     31 
     32 ```bash
     33 # disable blocking for a specific package (for PoC crafting)
     34 adb shell am compat disable BLOCK_UNTRUSTED_TOUCHES com.example.victim
     35 # re‑enable
     36 adb shell am compat reset BLOCK_UNTRUSTED_TOUCHES com.example.victim
     37 ```
     38 
     39 Trusted windows (accessibility, IME, assistant) still receive events. Invisible or fully transparent overlays also bypass the block, which attackers try to abuse by keeping `alpha < 0.8`.
     40 
     41 #### Handling **partial occlusion**
     42 
     43 Partial overlays that leave the target area visible are not auto-blocked. Mitigate in sensitive views by rejecting events with the **`FLAG_WINDOW_IS_PARTIALLY_OBSCURED`** flag:<sup>[[1]](#references)</sup>
     44 
     45 ```java
     46 @Override
     47 public boolean onFilterTouchEventForSecurity(MotionEvent event) {
     48     if ((event.getFlags() & MotionEvent.FLAG_WINDOW_IS_PARTIALLY_OBSCURED) != 0) {
     49         return false; // drop tap when anything partially obscures us
     50     }
     51     return super.onFilterTouchEventForSecurity(event);
     52 }
     53 ```
     54 
     55 #### `filterTouchesWhenObscured`
     56 
     57 If **`android:filterTouchesWhenObscured`** is set to **`true`**, the `View` will not receive touches whenever view's window is obscured by another visible window.
     58 
     59 #### **`setFilterTouchesWhenObscured`**
     60 
     61 The attribute **`setFilterTouchesWhenObscured`** set to true can also prevent the exploitation of this vulnerability if the Android version is lower.\
     62 If set to **`true`**, for example, a button can be automatically **disabled if it is obscured**:
     63 
     64 ```xml
     65 <Button android:text="Button"
     66 android:id="@+id/button1"
     67 android:layout_width="wrap_content"
     68 android:layout_height="wrap_content"
     69 android:filterTouchesWhenObscured="true">
     70 </Button>
     71 ```
     72 
     73 ## Exploitation
     74 
     75 ### Tapjacking-ExportedActivity
     76 
     77 The most **recent Android application** performing a Tapjacking attack (+ invoking before an exported activity of the attacked application) can be found in: [**https://github.com/carlospolop/Tapjacking-ExportedActivity**](https://github.com/carlospolop/Tapjacking-ExportedActivity).
     78 
     79 Follow the **README instructions to use it**.
     80 
     81 ### FloatingWindowApp
     82 
     83 An example project implementing **FloatingWindowApp**, which can be used to put on top of other activities to perform a clickjacking attack, can be found in [**FloatingWindowApp**](https://github.com/aminography/FloatingWindowApp) (a bit old, good luck building the apk).
     84 
     85 ### Qark
     86 
     87 > [!CAUTION]
     88 > It looks like this project is now unmaintained and this functionality isn't properly working anymore
     89 
     90 You can use [**qark**](https://github.com/linkedin/qark) with the `--exploit-apk` --sdk-path `/Users/username/Library/Android/sdk` parameters to create a malicious application to test for possible **Tapjacking** vulnerabilities.\
     91 
     92 The mitigation is relatively simple as the developer may choose not to receive touch events when a view is covered by another. Using the [Android Developer’s Reference](https://developer.android.com/reference/android/view/View#security):
     93 
     94 > Sometimes it is essential that an application be able to verify that an action is being performed with the full knowledge and consent of the user, such as granting a permission request, making a purchase or clicking on an advertisement. Unfortunately, a malicious application could try to spoof the user into performing these actions, unaware, by concealing the intended purpose of the view. As a remedy, the framework offers a touch filtering mechanism that can be used to improve the security of views that provide access to sensitive functionality.
     95 >
     96 > To enable touch filtering, call [`setFilterTouchesWhenObscured(boolean)`](https://developer.android.com/reference/android/view/View#setFilterTouchesWhenObscured%28boolean%29) or set the android:filterTouchesWhenObscured layout attribute to true. When enabled, the framework will discard touches that are received whenever the view's window is obscured by another visible window. As a result, the view will not receive touches whenever a toast, dialog or other window appears above the view's window.
     97 
     98 ---
     99 
    100 ### Recent overlay-based malware techniques
    101 
    102 * **Hook/Ermac variants** use nearly transparent overlays (e.g., fake NFC prompts) to capture gestures and lock-screen PINs while forwarding touches underneath, delivered via Accessibility-ATS modules.<sup>[[2]](#references)</sup>
    103 * **Anatsa/TeaBot droppers** ship overlays for hundreds of banking/crypto apps and show full-screen "maintenance" overlays to stall victims while ATS completes transfers.<sup>[[2]](#references)</sup>
    104 * **Hidden-VNC banking RATs** briefly display phishing overlays to capture credentials, then rely on covert VNC plus Accessibility to replay taps with fewer on-device artifacts.
    105 
    106 Practical takeaway for red teams: mix an `alpha < 0.8` overlay to bypass Android 12 blocking, then escalate to a full-screen accessibility overlay once the user toggles the service. Instrument `GestureDescription` or a headless VNC to keep control after credentials are captured.
    107 
    108 ---
    109 
    110 ## Accessibility Overlay Phishing (Banking-Trojan Variant)
    111 
    112 Besides classic Tapjacking, modern Android banking malware families (e.g. **ToxicPanda**, BrasDex, Sova, etc.) abuse the **Accessibility Service** to place a full-screen WebView **overlay** above the legitimate application while still being able to **forward the user input** to the view underneath.  This dramatically increases believability and allows attackers to steal credentials, OTPs or even automate fraudulent transactions.<sup>[[3]](#references)</sup>
    113 
    114 ### How it works
    115 1. The malicious APK requests the highly-sensitive `BIND_ACCESSIBILITY_SERVICE` permission, usually hiding the request behind a fake Google/Chrome/PDF-viewer dialog.
    116 2. Once the user enables the service, the malware programmatically simulates the taps required to grant additional dangerous permissions (`READ_SMS`, `SYSTEM_ALERT_WINDOW`, `REQUEST_INSTALL_PACKAGES`, …).
    117 3. A **WebView** is inflated and added to the window manager using the **`TYPE_ACCESSIBILITY_OVERLAY`** window type.  The overlay can be rendered totally opaque or semi-transparent and can be flagged as *“through”* so that the original touches are still delivered to the background activity (thus the transaction really happens while the victim only sees the phishing form).
    118 
    119 ```java
    120 WebView phishingView = new WebView(getApplicationContext());
    121 phishingView.getSettings().setJavaScriptEnabled(true);
    122 phishingView.loadUrl("file:///android_asset/bank_login.html");
    123 
    124 WindowManager wm = (WindowManager) getSystemService(WINDOW_SERVICE);
    125 WindowManager.LayoutParams lp = new WindowManager.LayoutParams(
    126         WindowManager.LayoutParams.MATCH_PARENT,
    127         WindowManager.LayoutParams.MATCH_PARENT,
    128         WindowManager.LayoutParams.TYPE_ACCESSIBILITY_OVERLAY,  // <-- bypasses SYSTEM_ALERT_WINDOW prompt
    129         WindowManager.LayoutParams.FLAG_NOT_FOCUSABLE |
    130         WindowManager.LayoutParams.FLAG_NOT_TOUCH_MODAL,        // «through» flag → forward touches
    131         PixelFormat.TRANSLUCENT);
    132 wm.addView(phishingView, lp);
    133 ```
    134 
    135 ### Typical workflow used by banking Trojans
    136 * Query installed packages (`QUERY_ALL_PACKAGES`) to figure out which banking / wallet app is currently opened.
    137 * Download an **HTML/JS overlay template** from the C2 that perfectly imitates that specific application (Logo, colours, i18n strings…).
    138 * Display the overlay, harvest credentials/PIN/pattern.
    139 * Use the **Accessibility API** (`performGlobalAction`, `GestureDescription`) to automate transfers in the background.
    140 
    141 ### Detection & Mitigation
    142 * Audit the list of installed apps with `adb shell pm list packages -3 -e BIND_ACCESSIBILITY_SERVICE`.
    143 * From the application side (bank / wallet):
    144   - Enable **`android:accessibilityDataSensitive="accessibilityDataPrivateYes"`** (Android 14+) on sensitive views to block non-Play-Store services.
    145   - Combine with `setFilterTouchesWhenObscured(true)` and `FLAG_SECURE`.
    146 
    147 For additional details on leveraging Accessibility Services for full remote device control (e.g. PlayPraetor, SpyNote, etc.) see:
    148 
    149 
    150 [Accessibility Services Abuse](/hacktricks/mobile-pentesting/android-app-pentesting/accessibility-services-abuse)
    151 
    152 ## References
    153 - [1] [Android Developers – Tapjacking risk & mitigations (updated 2024)](https://developer.android.com/privacy-and-security/risks/tapjacking)
    154 - [2] [Zimperium – HOOK v3 overlay expansion (Aug 2025)](https://thehackernews.com/2025/08/hook-android-trojan-adds-ransomware.html)
    155 - [3] [Bitsight – ToxicPanda: The Android Banking Trojan Targeting Europe](https://www.bitsight.com/blog/toxicpanda-android-banking-malware-2025-study)