Attacking Android with Metasploit

Attacking Android with Metasploit

May 08, 2022 2 min read 0 views 0 discussions
Table of Contents

    The Android platform can be attacked either by creating a simple APK file or by injecting the payload into an actual APK. We will cover the first one. Let us get started by generating an APK file with msfvenom as follows: 

    On generating the APK file, all we need to do is to either convince the victim (perform social engineering) to install the APK or physically gain access to the phone. Let us see what happens on the phone as soon as a victim downloads the malicious APK:

    Once the download is complete, the user installs the file as follows:

    Most people never notice what permissions an app asks for. Hence, an attacker gains full access to the phone and steals personal data. The preceding section lists the required permissions an application needs to operate correctly. Once the installation happens successfully, the attacker gains meterpreter access to the target phone as follows:

    Whooaaa! We got the meterpreter access easily. Post-exploitation is widely covered in Chapter 4, Post-Exploitation with Metasploit. However, let us see some of the basic functionalities as follows:

    We can see that running the check_root command states that the device is rooted. Let us see some other functions:

    We can use the send_sms command to send an SMS to any number from the exploited phone. Let us see whether the message was delivered or not:

    Bingo! The message was delivered successfully. Meanwhile, let us see what system we broke into using the sysinfo command as follows:

    Let's geolocate the mobile phone as follows:

    Browsing the Google Maps link, we can get the exact location of the cell phone as follows:

    Let us take some pictures with the exploited phone's camera as follows:

    We can see we got the picture from the camera. Let us view the image as follows:

    Client-side exploitation is fun. However, it is tough to conduct since we require actions and help from the victim to execute a file, visit a link, or install an APK. However, in the situations where no direct attack is possible, client-side attacks are the ones that are the most useful.

    Community Q&A