CLOADER: EVADING SECURITY MOBILE DEFENSES VIA RUNTIME OBFUSCATION AND ADAPTIVE HOOKING TACTICS Nhat-Anh Huynh
Minh Quang Luu
Ngoc Hong Tran*
Product Security VinSOC Ha Noi, Vietnam [email protected]
Computer Science Program Vietnamese-German University Ho Chi Minh City, Vietnam [email protected]
Computer Science Program Vietnamese-German University Binh Duong Province, Vietnam [email protected] *: Corresponding Author
Abstract: We propose a stealth framework that eliminates detection of hooking tools such as Frida and Xposed in secured mobile environments by replacing static configurations with dynamic evasion tactics. In contrast to existing approaches that apply these techniques independently, the framework introduces a unified runtime control layer that systematically coordinates network, temporal, and code-level evasive transformations. The solution integrates randomized port allocation, runtime code obfuscation, delayed execution triggers, and self-integrity checks to disrupt signaturebased scans, timing heuristics, and tampering attempts. A custom Android loader, CLoader, enforces these mechanisms to isolate hooking activities from security monitors while maintaining complete interception and modification capabilities. Validation across enterprise anti malware systems, hardened applications, and device management platforms demonstrates a 90% bypass rate in our evaluation matrix. This approach enables reliable penetration testing and malware analysis in locked-down mobile ecosystems by masking network, temporal, and code-level fingerprints without architectural overhauls. Keywords: Hooking Frameworks, Evading Detection, Runtime Obfuscation, Mobile Security I. Introduction Mobile applications in sectors such as finance, healthcare, and secure communications are increasingly targeted by sophisticated security threats. To assess and strengthen the defenses of these applications, penetration testers frequently rely on dynamic hooking frameworks like Frida [9] and Xposed [15]. These tools enable analysts to observe application behavior, test security controls, and uncover vulnerabilities at runtime. However, the same capabilities that benefit defenders are also exploited by attackers to intercept sensitive data, bypass authentication, and manipulate application logic. In response, mobile security solutions have implemented a range of anti-hooking defenses, including detection of hooking frameworks, jailbreak/root prevention, and runtime integrity verification [2]. While these measures are effective at
mitigating malicious activity, they also impede legitimate security testing by blocking the very tools used for in-depth analysis. This creates a significant challenge: security teams are unable to thoroughly evaluate applications that employ aggressive antihooking strategies, particularly in scenarios requiring runtime analysis and code obfuscation. To address this dilemma, we present CLoader, a stealth-oriented hooking module for Android designed to minimize detection while preserving full penetration testing functionality. CLoader leverages runtime code obfuscation, adaptive execution delays, and encrypted communication to evade detection mechanisms that would otherwise prevent authorized security analysis. By dynamically altering its behavior and communication patterns, CLoader disrupts signature-based scans, timing heuristics, and tampering attempts, enabling reliable testing even in hardened environments. Our main contributions are as follows: (i) an analysis of the limitations in current anti-hooking defenses; (ii) the development of evasion techniques based on randomized call patterns and self-integrity verification; and (iii) practical guidelines for deploying these methods in resource-constrained mobile environments. The remainder of this paper is organized as follows: Section II reviews related work; Sections III and IV discuss hooking frameworks and detection mechanisms; Section V presents our encryption and key management methodology; Sections VI and VII detail the design of CLoader; Section VIII provides experimental validation; and Section IX concludes with practical recommendations. II. RELATED WORKS Research on detection avoidance in mobile applications has increasingly focused on hooking frameworks, as both security solutions and evasion techniques have evolved in sophistication. Prior works highlight strategies such as binary obfuscation, dynamic analysis evasion, and runtime manipulation to bypass conventional security mechanisms [3], [4]. Malware often leverages frameworks like Frida and Xposed to intercept API calls, alter application logic in real time, and misuse parameters without requiring source code modifications [16]. Complementary evasion methods include code obfuscation, anti-debugging, anti-virtualization, privilege escalation through rooting, and encrypted payload delivery, all of which complicate detection and reverse engineering [5], [6], [17], [18]. Within this landscape, Frida represents a dual-use technology: while exploited by attackers, it is also a powerful open-source toolkit for defenders. Frida provides dynamic instrumentation by injecting JavaScript into active processes, enabling real-time program introspection and code manipulation. Unlike static modification-based hooking frameworks, Frida operates entirely at runtime and does not require source code access, making it valuable for both malware analysis and penetration testing. It is compatible with multiple platforms, including Android, iOS, Windows, Linux, and macOS, and its comprehensive scripting environment facilitates monitoring of function calls, memory operations, and execution flows in real time [7], [8]. Frida follows a client–server architecture in which instrumentation scripts are executed from a host machine while a server component running on the target device performs runtime code injection and monitoring [9].
Fig. 1. Frida Workflow Diagram
To counteract these threats, mobile security frameworks have adopted layered defenses. The Mobile Application Security Framework (MASF) is a prominent example, integrating modules such as the Application Security Shield (APSES) to enforce confidentiality, integrity, and reliability against advanced threats. At application initialization, APSES verifies the runtime environment, detecting risks such as debugging tools, virtualization, and root or jailbreak conditions (see Figures 2–4). If any such risks are identified, APSES restricts execution to trusted contexts only, thereby preserving application security throughout its lifecycle and protecting against both internal and external attacks. When APSES detects virtualization, developer tools, or root/jailbreak status, it proactively blocks execution to prevent tampering, reverse engineering, and privilege escalation. These measures are critical for maintaining application integrity, restricting unauthorized access, and safeguarding sensitive data from advanced exploitation. APSES also enforces network security by monitoring ports, proxies, and API connections to counter man-in-the-middle attacks and validates SSL certificates to secure communications between the application server and its clients, substantially reducing vulnerabilities associated with unencrypted transmissions and insecure protocols [2], [5], [6].
Fig. 2. The device must be verified to determine whether it is operating
Beyond APSES, MASF employs a layered security approach that combines static and dynamic measures. Code signature validation and obfuscation resist tampering and reverse engineering, while dynamic monitoring detects abnormal behaviors such as sandbox evasion and unauthorized screen capture. Adaptive learning algorithms
enhance threat detection, including polymorphic malware, and are supported by strong cryptography, hardware security modules, and white-box cryptographic techniques to protect sensitive assets [17], [19]. Device integrity checks prevent privilege escalation and hardware-level attacks, while token-based authentication and real-time monitoring reduce API vulnerabilities, particularly in financial and regulated environments. By combining heuristic and dynamic analysis, MASF adapts rapidly to new threats, providing resilient and comprehensive protection for mobile applications. This layered defense model, illustrated in Figures 2-4, demonstrates how MASF integrates multiple security controls to address a wide spectrum of attack vectors and maintain robust application security [2], [5], [6], [17], [19].
Fig. 3. The purpose of this function is to verify whether the device
Despite significant progress in anti-hooking and anti-tampering technologies, these defensive measures may unintentionally impede legitimate security assessments by restricting the use of essential analysis tools. As a result, security analysts often encounter barriers when attempting to evaluate the resilience of applications in realistic threat environments. This persistent adversarial dynamic between evasion techniques and detection mechanisms highlights a critical need for the development of stealthy and adaptive hooking frameworks. Such frameworks should enable authorized security testing and analysis while preserving the overall security posture of the application.
Fig. 4. The following function has been developed for the purpose of verifying whether or not the device has been rooted.
III. METHODOLOGY This section details the cryptographic and operational strategies employed to enhance the stealth, integrity, and resilience of Frida-based instrumentation in secured mobile environments. The methodology integrates RC4-based encryption, systematic binary obfuscation, dynamic configuration, and robust execution management to mitigate detection and tampering risks.
Fig. 5. Logical Flow of the RC4 Cipher.
Fig. 6. Key Encryption Process.
1. Cryptographic Protection with RC4 To secure sensitive payloads and maintain operational integrity, the RC4 stream cipher is employed as a lightweight symmetric encryption mechanism suitable for constrained environments [12]. The implementation adopts a hint byte technique, wherein decryption is achieved by brute-forcing the encryption key using known plaintext-ciphertext pairs. For example, if a known plaintext byte (e.g., BA) is expected to correspond to a specific ciphertext value (e.g., 71), the brute-force algorithm iterates through possible keys until the correct mapping is found (see Figures 5 and 6). This approach ensures that only authorized entities with knowledge of the hint can successfully decrypt and access protected assets. 2. Multi-Phase Evasion and Obfuscation Strategy To address the detection vectors commonly exploited by security monitoring protocols, a structured three-phase approach is proposed (illustrated in Figure 7): Dynamic Port Modification: The default Frida server TCP port (27042), which is frequently monitored by security solutions, is replaced with a randomly selected nonstandard port. This significantly reduces the likelihood of detection through portbased heuristics. Tripartite Binary Obfuscation:
o Binary Obfuscation: Specialized tools are used to transform the binary, complicating signature-based detection. o Binary Renaming: The binary is assigned a non-descriptive, unrelated filename to avoid recognition by security systems. o Symbol and Function Name Obfuscation: Critical symbols and function names within components such as libfrida-gadget.so and the Frida server are obfuscated, impeding detection mechanisms that rely on known function signatures. Enhanced Security Protections: The framework incorporates dynamic server binding, whereby communication channels are established on randomized ports at runtime, producing unpredictable network patterns that resist standard port scanning. Custom protector libraries are integrated to further block unauthorized access or manipulation, thereby strengthening the overall security posture of the Frida server.
Fig. 7. Methodology
3. CLOADER Implementation The CLoader module is developed to further enhance payload security and operational stability within the proposed framework (see Figure 8). CLoader employs encrypted file handling to protect binary assets, supports dynamic configuration for adaptability to diverse execution environments, and includes automated recovery mechanisms to ensure continued operation in the event of failures or detection attempts.
Fig. 8.Features of CLoader.
CLoader’s execution is organized into four distinct phases (see Figure 9): Load and Decrypt Payload: The module retrieves the encrypted payload and applies an RC4 brute-force decryption algorithm using known plaintext-ciphertext pairs [12]. Upon successful decryption, the payload is decompressed using zlib (DEFLATE), followed by comprehensive ELF validation to ensure structural integrity and compatibility.
Environment Preparation: A concealed directory structure is created at /data/local/tmp/.hidden with restricted permissions. Operational parameters, including process names, port allocations, and execution delays, are generated using cryptographically secure pseudorandom number generators to mimic legitimate system behavior and disrupt timing-based detection. Starting the Frida Server: The decrypted Frida server binary is extracted to the hidden directory with appropriate execution permissions. Process forking is performed using POSIX APIs to create an isolated environment, and network binding is configured with randomized ports. Process name obfuscation is achieved via the prctl() system call. Monitoring and Auto Recovery: Persistent process monitoring is established through status checks and socket verification. In the event of anomalies or termination, the recovery subsystem regenerates randomization parameters, clears forensic artifacts, and restarts the server, ensuring persistent availability and a minimal detection footprint.
Fig. 9. Workflow of CLoader.
IV. EVALUATION. 1. Experimental Setup Experiments were conducted on a rooted Android 14 device using Frida to instrument both open-source and proprietary applications, each incorporating various antitampering and anti-debugging protections. The evaluation compared Frida’s detectability before and after applying the CLoader-based evasion techniques, under controlled network conditions. 2. Result and Analysis With default configurations, Frida was consistently detected by standard anti-hooking and anti-debugging mechanisms, primarily due to its static port usage, unmodified binary signatures, and recognizable runtime behaviors (see Figure 10). This underscores the vulnerability of default Frida setups to common detection strategies. In contrast, integrating CLoader with Frida, featuring dynamic port randomization, binary and string obfuscation, encrypted payloads, and anti-debugging measures, substantially reduced
detection rates. During testing, applications failed to identify the presence of Frida when CLoader’s runtime evasion techniques were active (see Figure 11). These results demonstrate that CLoader’s adaptive and multi-layered approach provides significant improvements in stealth and operational resilience compared to conventional static evasion methods.
Fig. 10. Frida detected in default configuration.
Fig. 11. Frida evading detection in customized configuration (CLoader) Table 1. Frida-Detection Test Matrix And Cloader Bypass Results
ID
Detection Category
Test Case
Detection Logic
Default Frida
CLoader
Result
TC01
Network
Default port scan
Check port 27042
Detected
Not detected
Pass
TC02
Network
Known port range Detect Frida-like Detected scan listening behavior
Not detected
Pass
TC03
Process
Process inspection
name Search for frida- Detected server
Not detected
Pass
TC04
Binary Signature
String scan
Search for “frida” Detected in binary
Not detected
Pass
TC05
Symbol Signature
Symbol lookup
Inspect exported Detected Frida-related symbols
Not detected
Pass
TC06
File Artifact
Default file path Check check /data/local/tmp/fri da-server
Detected
Not detected
Pass
TC07
Module Inspection
Loaded scan
module Search for Detected libfrida-gadget.so
Not detected
Pass
TC08
Thread Artifact
Thread name scan
Not detected
Pass
TC09
Memory Artifact
Memory scan
Reduced visibility
Pass
TC10
Socket Behavior
Listening socket Detect suspicious Detected inspection local socket behavior
Not detected
Pass
TC11
Runtime Heuristic
Early-start detection
Detected
Not detected
Pass
TC12
Integrity
Runtime integrity Detect tampering Detected verification or runtime modification
Not detected
Pass
TC13
Debug Artifact
Debug/tracer detection
Not detected
Pass
TC14
Composit e Heuristic
Root + Frida Correlate rooted Detected correlation state with instrumentation
Detected
Fail
TC15
Hook Artifact
Hook consistency check
Detected
Fail
TC16
IPC Artifact
IPC or inspection
pipe Identify Frida Detected communication patterns
Not detected
Pass
TC17
Config Artifact
Gadget configuration detection
Detect default Detected configuration traces
Not detected
Pass
Inspect thread Detected names for Frida artifacts
string Search memory Detected for “frida” markers
hook Detect instrumentation during app startup
Check tracing/debug status
Detected
Detect altered call Detected paths / inline hooks
TC18
Path Heuristic
Hidden-path inspection
Look for Detected suspicious relocated binaries
Not detected
Pass
TC19
AppLevel Anti-Frida
Hardened check #1
app Built-in anti-Frida Detected logic
Not detected
Pass
TC20
Security Control
Hardened app / Security platform Detected EMM check #2 detection logic
Not detected
Pass
In addition to justifying the reported 90% improvement, we evaluated CLoader against a structured Frida-detection test matrix comprising 20 representative test cases (see Table 1). These cases covered common anti-instrumentation strategies, including network-based checks, process and file artifact inspection, binary and symbol signature matching, runtime-behavior heuristics, and integrity-based verification. Each test case was labeled Pass when the protected application or monitoring logic failed to detect the presence of Frida/CLoader and execution continued normally, and Fail when detection occurred, or execution was restricted. Under this evaluation methodology, CLoader passed 18 of 20 test cases, corresponding to a 90% bypass rate. 3. Limitations and Future Work While CLoader enhances Frida’s stealth in controlled environments, its scalability and effectiveness against advanced, machine learning-based detection systems remain to be validated. Additionally, increased obfuscation may introduce computational overhead on resource-constrained devices. Future work will focus on optimizing performance and evaluating CLoader in large-scale and enterprise-grade security environments. V. CONCLUSION This study presented CLoader, a stealth-oriented framework that effectively evades mobile security detection while maintaining reliable payload execution. Through the integration of runtime obfuscation, dynamic network configuration, and adaptive integrity verification, CLoader achieved a 90% reduction in detection rates across varied Android environments. Future research will aim to strengthen resilience against machine learning-based detection and improve computational efficiency to support deployment in large-scale enterprise security contexts. References [1] R. I. R. Islam and M. T. Islam, “Mobile application and its global impact,” Int. J. Eng. Technol., vol. 10, no. 6, pp. 72-78, 2010. [2] J. R. Ball, “Detection and prevention of Android malware attempting to root the device,” M.S. thesis, Dept. Computer Science, University of Louisville, Louisville, KY, USA, 2014.
[3] C. Collberg, C. Thomborson, and D. Low, “A taxonomy of obfuscating transformations,” Tech. Rep. 148, Dept. Computer Science, University of Auckland, 1997. [Online]. Available: https://researchspace.auckland.ac.nz/handle/2292/3491 [4] W. Li and Y. Li, “Android’s cat-and-mouse game: Understanding evasion techniques against dynamic analysis,” in Proc. IEEE Int. Symp. Software Reliability Engineering (ISSRE), 2024, pp. 1-12. [5] P. Faruki, A. Bharmal, V. Laxmi, M. Gaur, M. Conti, M. Rajarajan, and V. Ganmoor, “Android security: A survey of issues, malware penetration, and defenses,” IEEE Commun. Surveys Tuts., vol. 17, no. 2, pp. 998–1022, 2015. doi: 10.1109/COMST.2014.2386139 [6] W. Enck, M. Ongtang, and P. McDaniel, “On lightweight mobile phone application certification,” in Proc. ACM Conf. Computer and Communications Security (CCS), 2009, pp. 235–245. doi: 10.1145/1653662.1653691 [7] J. Lopez, L. Babun, H. Aksu, and A. S. Uluagac, “A survey on function and system call hooking approaches,” J. Hardware Syst. Security, vol. 1, no. 2, pp. 114–136, 2017. doi: 10.1007/s41635-017-0013-2 [8] T. Nguyen, H. Trinh, G. Tan, V. Ngoc, N. Phuc, and V. S. Cam, “Android application behavior monitor by using hooking techniques,” in Proc. Int. Conf. Intelligent Computing and Optimization, 2023, pp. 325–333. [9] NowSecure, “Frida: Dynamic instrumentation toolkit,” [Online]. Available: https://frida.re [10] V. Božić, "AI and predictive analytics," [Online]. Available: https://www.researchgate.net/publication/370074080_AI_and_Predictive_Analytics [11] C. M. J. Krishnan, "The AI revolution in e-commerce: Personalization and predictive analytics," in Role of Explainable Artificial Intelligence in E-Commerce, vol. 1094, Springer, 2024. [12] R. L. Rivest, "The RC4 encryption algorithm," RSA Data Security, Inc., Unpublished internal technical report, 1992. [13] N. Couture and K. K. B. Couture, "The effectiveness of brute force attacks on RC4," in Proc. 2nd Annu. Conf. Communication Networks and Services Research, 2004, pp. 333–336. [14] S. H. Kwok and L. E. Y. Kwok, "Effective uses of FPGAs for brute-force attack on RC4 ciphers," IEEE Trans. Very Large Scale Integr. (VLSI) Syst., vol. 16, no. 8, pp. 1096–1100, 2008. [15] Xposed Framework, "Xposed Framework API," [Online]. Available: https://api.xposed.info/reference/packages.html [16] C. Wang, Z. Zhang, X. Jia, and D. Tian, "Binary obfuscation based reassemble," in Proc. 13th Int. Conf. Malicious and Unwanted Software (MALWARE), 2018, pp. 153–160. doi: https://doi.org/10.1109/MALWARE.2018.8659363 [17] H. Shi, J. Mirkovic, and A. Alwabel, "Handling anti-virtual machine techniques in malicious software," ACM Trans. Privacy Security, vol. 21, no. 1, Art. 2, 2018. doi: https://doi.org/10.1145/3139292 [18] P. Xiao, Y. Yan, J. Hu, Z. Zhang, and A. Peinado, "HMMED: A multimodal model with separate head and payload processing for malicious encrypted traffic detection," Security Commun. Networks, vol. 2024, 2024. doi: https://doi.org/10.1155/2024/8725832 [19] K. Stein, A. Mahyari, G. Francia, and E. El-Sheikh, "A transformer-based
framework for payload malware detection and classification," arXiv:2403.18223, 2024. [Online]. Available: https://arxiv.org/pdf/2403.18223 [20] L. D. Isaac, V. Mohanraj, N. Soms, R. Jaya, and S. Sathiya Priya, "Adaptive learning-based IoT security framework using recurrent neural networks," in Lecture Notes in Electrical Engineering, vol. 1156, Springer, 2023. doi: https://doi.org/10.1007/978-981-97-0767-6_9 [21] S. Chow, P. Eisen, H. Johnson, and P. C. Van Oorschot, "White-box cryptography and an AES implementation," in Proc. 9th Annu. Int. Workshop Selected Areas in Cryptography (SAC 2002), 2002, pp. 250–270. [22] A. Chailytko and S. Skuratovich, "Defeating sandbox evasion: How to increase the successful emulation rate in your virtual environment," Check Point Software Technologies, 2016. [Online]. Available: https://blog.checkpoint.com/wpcontent/uploads/2016/10/DefeatingSandBoxEvasion-VB2016_CheckPoint.pdf [23] S. M. Muzammal and M. A. Shah, "ScreenStealer: Addressing screenshot attacks on Android devices," in Proc. Int. Conf. Automation and Computing (ICONAC), 2016. doi: https://doi.org/10.1109/iconac.2016.7604942 [24] N. Kokash, "An introduction to heuristic algorithms," [Online]. Available: https://citeseerx.ist.psu.edu/document?repid=rep1&type=pdf&doi=8314bf30780871 868076775ba62759f1faf8c9f0