Hooking Native Android Methods with Frida

Опубликовано: 20 Октябрь 2024
на канале: LaurieWired
21,408
715

In this video, we use Frida hooking to intercept native Android methods after they have been loaded into the runtime. We write a custom script that uses Interceptor.attach to run code when the native method is invoked.

---

Timestamps:
00:00 Intro
00:50 Grabbing Sample
01:32 Looking at Native Libs
02:51 Emulation Time!
06:10 Attaching Frida
07:36 Enumerating Imports and Exports
09:45 Scripting
16:05 Intercepting Native Binary
20:20 Explaining the Interceptor
22:20 Exploring Method Names in Ghidra
25:30 Running with Hooking Script
28:05 Method order is Important!
30:06 One more time!
30:45 Recap

---

Links Mentioned in Video:

Frida:
https://github.com/frida/frida

Redroid:
https://github.com/remote-android/red...

Scrcpy:
https://github.com/Genymobile/scrcpy

---

Malware Examined in the video (Xloader):
sha256:ada2808ef254c39e70f74c93c7fd3b7f458ea439beebfc1520650fd0e3e34990

MalwareBazaar Link:
https://bazaar.abuse.ch/sample/ada280...

---
laurieWIRED Twitter:
  / lauriewired  

laurieWIRED Website:
http://lauriewired.com

laurieWIRED Github:
https://github.com/LaurieWired

laurieWIRED HN:
https://news.ycombinator.com/user?id=...

laurieWIRED Reddit:
  / lauriewired