Conceptio › Archive › arXiv CS
arXiv CSopen access

CLOADER: Evading Security Mobile Defenses via Runtime Obfuscation and Adaptive Hooking Tactics

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

CLOADER: EVADING SECURITY MOBILE DEFENSES VIA RUNTIME OBFUSCATION AND ADAPTIVE HOOKING TACTICS Nhat-Anh Huynh

Minh Quang Luu

Ngoc Hong Tran*

Product Security VinSOC Ha Noi, Vietnam [email protected]

Computer Science Program Vietnamese-German University Ho Chi Minh City, Vietnam [email protected]

Computer Science Program Vietnamese-German University Binh Duong Province, Vietnam [email protected] *: Corresponding Author

Abstract: We propose a stealth framework that eliminates detection of hooking tools such as Frida and Xposed in secured mobile environments by replacing static configurations with dynamic evasion tactics. In contrast to existing approaches that apply these techniques independently, the framework introduces a unified runtime control layer that systematically coordinates network, temporal, and code-level evasive transformations. The solution integrates randomized port allocation, runtime code obfuscation, delayed execution triggers, and self-integrity checks to disrupt signaturebased scans, timing heuristics, and tampering attempts. A custom Android loader, CLoader, enforces these mechanisms to isolate hooking activities from security monitors while maintaining complete interception and modification capabilities. Validation across enterprise anti malware systems, hardened applications, and device management platforms demonstrates a 90% bypass rate in our evaluation matrix. This approach enables reliable penetration testing and malware analysis in locked-down mobile ecosystems by masking network, temporal, and code-level fingerprints without architectural overhauls. Keywords: Hooking Frameworks, Evading Detection, Runtime Obfuscation, Mobile Security I. Introduction Mobile applications in sectors such as finance, healthcare, and secure communications are increasingly targeted by sophisticated security threats. To assess and strengthen the defenses of these applications, penetration testers frequently rely on dynamic hooking frameworks like Frida [9] and Xposed [15]. These tools enable analysts to observe application behavior, test security controls, and uncover vulnerabilities at runtime. However, the same capabilities that benefit defenders are also exploited by attackers to intercept sensitive data, bypass authentication, and manipulate application logic. In response, mobile security solutions have implemented a range of anti-hooking defenses, including detection of hooking frameworks, jailbreak/root prevention, and runtime integrity verification [2]. While these measures are effective at

mitigating malicious activity, they also impede legitimate security testing by blocking the very tools used for in-depth analysis. This creates a significant challenge: security teams are unable to thoroughly evaluate applications that employ aggressive antihooking strategies, particularly in scenarios requiring runtime analysis and code obfuscation. To address this dilemma, we present CLoader, a stealth-oriented hooking module for Android designed to minimize detection while preserving full penetration testing functionality. CLoader leverages runtime code obfuscation, adaptive execution delays, and encrypted communication to evade detection mechanisms that would otherwise prevent authorized security analysis. By dynamically altering its behavior and communication patterns, CLoader disrupts signature-based scans, timing heuristics, and tampering attempts, enabling reliable testing even in hardened environments. Our main contributions are as follows: (i) an analysis of the limitations in current anti-hooking defenses; (ii) the development of evasion techniques based on randomized call patterns and self-integrity verification; and (iii) practical guidelines for deploying these methods in resource-constrained mobile environments. The remainder of this paper is organized as follows: Section II reviews related work; Sections III and IV discuss hooking frameworks and detection mechanisms; Section V presents our encryption and key management methodology; Sections VI and VII detail the design of CLoader; Section VIII provides experimental validation; and Section IX concludes with practical recommendations. II. RELATED WORKS Research on detection avoidance in mobile applications has increasingly focused on hooking frameworks, as both security solutions and evasion techniques have evolved in sophistication. Prior works highlight strategies such as binary obfuscation, dynamic analysis evasion, and runtime manipulation to bypass conventional security mechanisms [3], [4]. Malware often leverages frameworks like Frida and Xposed to intercept API calls, alter application logic in real time, and misuse parameters without requiring source code modifications [16]. Complementary evasion methods include code obfuscation, anti-debugging, anti-virtualization, privilege escalation through rooting, and encrypted payload delivery, all of which complicate detection and reverse engineering [5], [6], [17], [18]. Within this landscape, Frida represents a dual-use technology: while exploited by attackers, it is also a powerful open-source toolkit for defenders. Frida provides dynamic instrumentation by injecting JavaScript into active processes, enabling real-time program introspection and code manipulation. Unlike static modification-based hooking frameworks, Frida operates entirely at runtime and does not require source code access, making it valuable for both malware analysis and penetration testing. It is compatible with multiple platforms, including Android, iOS, Windows, Linux, and macOS, and its comprehensive scripting environment facilitates monitoring of function calls, memory operations, and execution flows in real time [7], [8]. Frida follows a client–server architecture in which instrumentation scripts are executed from a host machine while a server component running on the target device performs runtime code injection and monitoring [9].

Fig. 1. Frida Workflow Diagram

To counteract these threats, mobile security frameworks have adopted layered defenses. The Mobile Application Security Framework (MASF) is a prominent example, integrating modules such as the Application Security Shield (APSES) to enforce confidentiality, integrity, and reliability against advanced threats. At application initialization, APSES verifies the runtime environment, detecting risks such as debugging tools, virtualization, and root or jailbreak conditions (see Figures 2–4). If any such risks are identified, APSES restricts execution to trusted contexts only, thereby preserving application security throughout its lifecycle and protecting against both internal and external attacks. When APSES detects virtualization, developer tools, or root/jailbreak status, it proactively blocks execution to prevent tampering, reverse engineering, and privilege escalation. These measures are critical for maintaining application integrity, restricting unauthorized access, and safeguarding sensitive data from advanced exploitation. APSES also enforces network security by monitoring ports, proxies, and API connections to counter man-in-the-middle attacks and validates SSL certificates to secure communications between the application server and its clients, substantially reducing vulnerabilities associated with unencrypted transmissions and insecure protocols [2], [5], [6].

Fig. 2. The device must be verified to determine whether it is operating

Beyond APSES, MASF employs a layered security approach that combines static and dynamic measures. Code signature validation and obfuscation resist tampering and reverse engineering, while dynamic monitoring detects abnormal behaviors such as sandbox evasion and unauthorized screen capture. Adaptive learning algorithms

enhance threat detection, including polymorphic malware, and are supported by strong cryptography, hardware security modules, and white-box cryptographic techniques to protect sensitive assets [17], [19]. Device integrity checks prevent privilege escalation and hardware-level attacks, while token-based authentication and real-time monitoring reduce API vulnerabilities, particularly in financial and regulated environments. By combining heuristic and dynamic analysis, MASF adapts rapidly to new threats, providing resilient and comprehensive protection for mobile applications. This layered defense model, illustrated in Figures 2-4, demonstrates how MASF integrates multiple security controls to address a wide spectrum of attack vectors and maintain robust application security [2], [5], [6], [17], [19].

Fig. 3. The purpose of this function is to verify whether the device

Despite significant progress in anti-hooking and anti-tampering technologies, these defensive measures may unintentionally impede legitimate security assessments by restricting the use of essential analysis tools. As a result, security analysts often encounter barriers when attempting to evaluate the resilience of applications in realistic threat environments. This persistent adversarial dynamic between evasion techniques and detection mechanisms highlights a critical need for the development of stealthy and adaptive hooking frameworks. Such frameworks should enable authorized security testing and analysis while preserving the overall security posture of the application.

Fig. 4. The following function has been developed for the purpose of verifying whether or not the device has been rooted.

III. METHODOLOGY This section details the cryptographic and operational strategies employed to enhance the stealth, integrity, and resilience of Frida-based instrumentation in secured mobile environments. The methodology integrates RC4-based encryption, systematic binary obfuscation, dynamic configuration, and robust execution management to mitigate detection and tampering risks.

Fig. 5. Logical Flow of the RC4 Cipher.

Fig. 6. Key Encryption Process.

1. Cryptographic Protection with RC4 To secure sensitive payloads and maintain operational integrity, the RC4 stream cipher is employed as a lightweight symmetric encryption mechanism suitable for constrained environments [12]. The implementation adopts a hint byte technique, wherein decryption is achieved by brute-forcing the encryption key using known plaintext-ciphertext pairs. For example, if a known plaintext byte (e.g., BA) is expected to correspond to a specific ciphertext value (e.g., 71), the brute-force algorithm iterates through possible keys until the correct mapping is found (see Figures 5 and 6). This approach ensures that only authorized entities with knowledge of the hint can successfully decrypt and access protected assets. 2. Multi-Phase Evasion and Obfuscation Strategy To address the detection vectors commonly exploited by security monitoring protocols, a structured three-phase approach is proposed (illustrated in Figure 7):  Dynamic Port Modification: The default Frida server TCP port (27042), which is frequently monitored by security solutions, is replaced with a randomly selected nonstandard port. This significantly reduces the likelihood of detection through portbased heuristics.  Tripartite Binary Obfuscation:

o Binary Obfuscation: Specialized tools are used to transform the binary, complicating signature-based detection. o Binary Renaming: The binary is assigned a non-descriptive, unrelated filename to avoid recognition by security systems. o Symbol and Function Name Obfuscation: Critical symbols and function names within components such as libfrida-gadget.so and the Frida server are obfuscated, impeding detection mechanisms that rely on known function signatures.  Enhanced Security Protections: The framework incorporates dynamic server binding, whereby communication channels are established on randomized ports at runtime, producing unpredictable network patterns that resist standard port scanning. Custom protector libraries are integrated to further block unauthorized access or manipulation, thereby strengthening the overall security posture of the Frida server.

Fig. 7. Methodology

3. CLOADER Implementation The CLoader module is developed to further enhance payload security and operational stability within the proposed framework (see Figure 8). CLoader employs encrypted file handling to protect binary assets, supports dynamic configuration for adaptability to diverse execution environments, and includes automated recovery mechanisms to ensure continued operation in the event of failures or detection attempts.

Fig. 8.Features of CLoader.

CLoader’s execution is organized into four distinct phases (see Figure 9):  Load and Decrypt Payload: The module retrieves the encrypted payload and applies an RC4 brute-force decryption algorithm using known plaintext-ciphertext pairs [12]. Upon successful decryption, the payload is decompressed using zlib (DEFLATE), followed by comprehensive ELF validation to ensure structural integrity and compatibility.

 Environment Preparation: A concealed directory structure is created at /data/local/tmp/.hidden with restricted permissions. Operational parameters, including process names, port allocations, and execution delays, are generated using cryptographically secure pseudorandom number generators to mimic legitimate system behavior and disrupt timing-based detection.  Starting the Frida Server: The decrypted Frida server binary is extracted to the hidden directory with appropriate execution permissions. Process forking is performed using POSIX APIs to create an isolated environment, and network binding is configured with randomized ports. Process name obfuscation is achieved via the prctl() system call.  Monitoring and Auto Recovery: Persistent process monitoring is established through status checks and socket verification. In the event of anomalies or termination, the recovery subsystem regenerates randomization parameters, clears forensic artifacts, and restarts the server, ensuring persistent availability and a minimal detection footprint.

Fig. 9. Workflow of CLoader.

IV. EVALUATION. 1. Experimental Setup Experiments were conducted on a rooted Android 14 device using Frida to instrument both open-source and proprietary applications, each incorporating various antitampering and anti-debugging protections. The evaluation compared Frida’s detectability before and after applying the CLoader-based evasion techniques, under controlled network conditions. 2. Result and Analysis With default configurations, Frida was consistently detected by standard anti-hooking and anti-debugging mechanisms, primarily due to its static port usage, unmodified binary signatures, and recognizable runtime behaviors (see Figure 10). This underscores the vulnerability of default Frida setups to common detection strategies. In contrast, integrating CLoader with Frida, featuring dynamic port randomization, binary and string obfuscation, encrypted payloads, and anti-debugging measures, substantially reduced

detection rates. During testing, applications failed to identify the presence of Frida when CLoader’s runtime evasion techniques were active (see Figure 11). These results demonstrate that CLoader’s adaptive and multi-layered approach provides significant improvements in stealth and operational resilience compared to conventional static evasion methods.

Fig. 10. Frida detected in default configuration.

Fig. 11. Frida evading detection in customized configuration (CLoader) Table 1. Frida-Detection Test Matrix And Cloader Bypass Results

ID

Detection Category

Test Case

Detection Logic

Default Frida

CLoader

Result

TC01

Network

Default port scan

Check port 27042

Detected

Not detected

Pass

TC02

Network

Known port range Detect Frida-like Detected scan listening behavior

Not detected

Pass

TC03

Process

Process inspection

name Search for frida- Detected server

Not detected

Pass

TC04

Binary Signature

String scan

Search for “frida” Detected in binary

Not detected

Pass

TC05

Symbol Signature

Symbol lookup

Inspect exported Detected Frida-related symbols

Not detected

Pass

TC06

File Artifact

Default file path Check check /data/local/tmp/fri da-server

Detected

Not detected

Pass

TC07

Module Inspection

Loaded scan

module Search for Detected libfrida-gadget.so

Not detected

Pass

TC08

Thread Artifact

Thread name scan

Not detected

Pass

TC09

Memory Artifact

Memory scan

Reduced visibility

Pass

TC10

Socket Behavior

Listening socket Detect suspicious Detected inspection local socket behavior

Not detected

Pass

TC11

Runtime Heuristic

Early-start detection

Detected

Not detected

Pass

TC12

Integrity

Runtime integrity Detect tampering Detected verification or runtime modification

Not detected

Pass

TC13

Debug Artifact

Debug/tracer detection

Not detected

Pass

TC14

Composit e Heuristic

Root + Frida Correlate rooted Detected correlation state with instrumentation

Detected

Fail

TC15

Hook Artifact

Hook consistency check

Detected

Fail

TC16

IPC Artifact

IPC or inspection

pipe Identify Frida Detected communication patterns

Not detected

Pass

TC17

Config Artifact

Gadget configuration detection

Detect default Detected configuration traces

Not detected

Pass

Inspect thread Detected names for Frida artifacts

string Search memory Detected for “frida” markers

hook Detect instrumentation during app startup

Check tracing/debug status

Detected

Detect altered call Detected paths / inline hooks

TC18

Path Heuristic

Hidden-path inspection

Look for Detected suspicious relocated binaries

Not detected

Pass

TC19

AppLevel Anti-Frida

Hardened check #1

app Built-in anti-Frida Detected logic

Not detected

Pass

TC20

Security Control

Hardened app / Security platform Detected EMM check #2 detection logic

Not detected

Pass

In addition to justifying the reported 90% improvement, we evaluated CLoader against a structured Frida-detection test matrix comprising 20 representative test cases (see Table 1). These cases covered common anti-instrumentation strategies, including network-based checks, process and file artifact inspection, binary and symbol signature matching, runtime-behavior heuristics, and integrity-based verification. Each test case was labeled Pass when the protected application or monitoring logic failed to detect the presence of Frida/CLoader and execution continued normally, and Fail when detection occurred, or execution was restricted. Under this evaluation methodology, CLoader passed 18 of 20 test cases, corresponding to a 90% bypass rate. 3. Limitations and Future Work While CLoader enhances Frida’s stealth in controlled environments, its scalability and effectiveness against advanced, machine learning-based detection systems remain to be validated. Additionally, increased obfuscation may introduce computational overhead on resource-constrained devices. Future work will focus on optimizing performance and evaluating CLoader in large-scale and enterprise-grade security environments. V. CONCLUSION This study presented CLoader, a stealth-oriented framework that effectively evades mobile security detection while maintaining reliable payload execution. Through the integration of runtime obfuscation, dynamic network configuration, and adaptive integrity verification, CLoader achieved a 90% reduction in detection rates across varied Android environments. Future research will aim to strengthen resilience against machine learning-based detection and improve computational efficiency to support deployment in large-scale enterprise security contexts. References [1] R. I. R. Islam and M. T. Islam, “Mobile application and its global impact,” Int. J. Eng. Technol., vol. 10, no. 6, pp. 72-78, 2010. [2] J. R. Ball, “Detection and prevention of Android malware attempting to root the device,” M.S. thesis, Dept. Computer Science, University of Louisville, Louisville, KY, USA, 2014.

[3] C. Collberg, C. Thomborson, and D. Low, “A taxonomy of obfuscating transformations,” Tech. Rep. 148, Dept. Computer Science, University of Auckland, 1997. [Online]. Available: https://researchspace.auckland.ac.nz/handle/2292/3491 [4] W. Li and Y. Li, “Android’s cat-and-mouse game: Understanding evasion techniques against dynamic analysis,” in Proc. IEEE Int. Symp. Software Reliability Engineering (ISSRE), 2024, pp. 1-12. [5] P. Faruki, A. Bharmal, V. Laxmi, M. Gaur, M. Conti, M. Rajarajan, and V. Ganmoor, “Android security: A survey of issues, malware penetration, and defenses,” IEEE Commun. Surveys Tuts., vol. 17, no. 2, pp. 998–1022, 2015. doi: 10.1109/COMST.2014.2386139 [6] W. Enck, M. Ongtang, and P. McDaniel, “On lightweight mobile phone application certification,” in Proc. ACM Conf. Computer and Communications Security (CCS), 2009, pp. 235–245. doi: 10.1145/1653662.1653691 [7] J. Lopez, L. Babun, H. Aksu, and A. S. Uluagac, “A survey on function and system call hooking approaches,” J. Hardware Syst. Security, vol. 1, no. 2, pp. 114–136, 2017. doi: 10.1007/s41635-017-0013-2 [8] T. Nguyen, H. Trinh, G. Tan, V. Ngoc, N. Phuc, and V. S. Cam, “Android application behavior monitor by using hooking techniques,” in Proc. Int. Conf. Intelligent Computing and Optimization, 2023, pp. 325–333. [9] NowSecure, “Frida: Dynamic instrumentation toolkit,” [Online]. Available: https://frida.re [10] V. Božić, "AI and predictive analytics," [Online]. Available: https://www.researchgate.net/publication/370074080_AI_and_Predictive_Analytics [11] C. M. J. Krishnan, "The AI revolution in e-commerce: Personalization and predictive analytics," in Role of Explainable Artificial Intelligence in E-Commerce, vol. 1094, Springer, 2024. [12] R. L. Rivest, "The RC4 encryption algorithm," RSA Data Security, Inc., Unpublished internal technical report, 1992. [13] N. Couture and K. K. B. Couture, "The effectiveness of brute force attacks on RC4," in Proc. 2nd Annu. Conf. Communication Networks and Services Research, 2004, pp. 333–336. [14] S. H. Kwok and L. E. Y. Kwok, "Effective uses of FPGAs for brute-force attack on RC4 ciphers," IEEE Trans. Very Large Scale Integr. (VLSI) Syst., vol. 16, no. 8, pp. 1096–1100, 2008. [15] Xposed Framework, "Xposed Framework API," [Online]. Available: https://api.xposed.info/reference/packages.html [16] C. Wang, Z. Zhang, X. Jia, and D. Tian, "Binary obfuscation based reassemble," in Proc. 13th Int. Conf. Malicious and Unwanted Software (MALWARE), 2018, pp. 153–160. doi: https://doi.org/10.1109/MALWARE.2018.8659363 [17] H. Shi, J. Mirkovic, and A. Alwabel, "Handling anti-virtual machine techniques in malicious software," ACM Trans. Privacy Security, vol. 21, no. 1, Art. 2, 2018. doi: https://doi.org/10.1145/3139292 [18] P. Xiao, Y. Yan, J. Hu, Z. Zhang, and A. Peinado, "HMMED: A multimodal model with separate head and payload processing for malicious encrypted traffic detection," Security Commun. Networks, vol. 2024, 2024. doi: https://doi.org/10.1155/2024/8725832 [19] K. Stein, A. Mahyari, G. Francia, and E. El-Sheikh, "A transformer-based

framework for payload malware detection and classification," arXiv:2403.18223, 2024. [Online]. Available: https://arxiv.org/pdf/2403.18223 [20] L. D. Isaac, V. Mohanraj, N. Soms, R. Jaya, and S. Sathiya Priya, "Adaptive learning-based IoT security framework using recurrent neural networks," in Lecture Notes in Electrical Engineering, vol. 1156, Springer, 2023. doi: https://doi.org/10.1007/978-981-97-0767-6_9 [21] S. Chow, P. Eisen, H. Johnson, and P. C. Van Oorschot, "White-box cryptography and an AES implementation," in Proc. 9th Annu. Int. Workshop Selected Areas in Cryptography (SAC 2002), 2002, pp. 250–270. [22] A. Chailytko and S. Skuratovich, "Defeating sandbox evasion: How to increase the successful emulation rate in your virtual environment," Check Point Software Technologies, 2016. [Online]. Available: https://blog.checkpoint.com/wpcontent/uploads/2016/10/DefeatingSandBoxEvasion-VB2016_CheckPoint.pdf [23] S. M. Muzammal and M. A. Shah, "ScreenStealer: Addressing screenshot attacks on Android devices," in Proc. Int. Conf. Automation and Computing (ICONAC), 2016. doi: https://doi.org/10.1109/iconac.2016.7604942 [24] N. Kokash, "An introduction to heuristic algorithms," [Online]. Available: https://citeseerx.ist.psu.edu/document?repid=rep1&type=pdf&doi=8314bf30780871 868076775ba62759f1faf8c9f0

Record · ID 1028616 · SHA-256 38d6847865786510
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.