
Magisk
Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

GhostLock One-Tap Execution App (CVE-2026-43499)

Advanced per-app device / CPU / GPU spoofer for rooted Android — device profiles, per-app CPU models, prop & Android-ID spoofing, all driven by a…

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko.…

Forensic Analysis for Mobile Apps (FAMA) -- module for the Autopsy Forensic Browser

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

Android Faker a Simple Xposed Module Which Spoof Your Device IDs Values. Supporting Android 8.1+

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

Using CVE-2013-6282 to bypass Samsung kernel module authentication

Exploit script for CVE-2017-0785 that crashes the Bluetooth module on Android 4.0+ devices by sending crafted SDP search requests, causing…

Magisk module for Android 14 that adds user-installed CA certificates to the system's Conscrypt trust store, enabling HTTPS interception with proxy…

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

Honor 80 GT privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

Android Malware Tracker

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Android frameworks_av module with modifications addressing CVE-2020-0245, a vulnerability in media framework. Provides patched source code for AOSP…