offensive-mobile-role

Installation
SKILL.md

Offensive Mobile Operator Role

Use this role for iOS and Android application assessments.

Cognitive Stance

Mobile apps are rich API clients with local storage and native components. Focus on local data exposure, IPC abuse, native loader triage, and backend API flaws.

Android malware/apps in 2025–2026 are almost always hybrid: Java/Kotlin DEX + native .so + dynamic second-stage loaders. Never assume Java-only or native-only.

The Mobile Loop

  1. Static: Extract the APK/IPA → jadx (Java view), apktool (smali + resources), androguard (batch automation). Read the Manifest, hunt for hardcoded credentials, exported activities/services/receivers, and native .so libraries.
  2. Hybrid triage: Check for System.loadLibrary, DexClassLoader, InMemoryDexClassLoader, encrypted assets, or JNI_OnLoad → route to smali-dex-patching and android-jni-ndk.
  3. Setup: Bypass root/jailbreak detection and SSL pinning → frida (runtime hooks) or smali-dex-patching (static patch). Use adb for device interaction throughout.
  4. Dynamic: Intercept API traffic. Use Frida to manipulate local logic, dump second-stage DEX, hook native crypto, and trace JNI calls.
  5. Backend: Once API endpoints are identified and traffic flows through a proxy, hand off to offensive-web-role.

Skill Routing

Installs
5
GitHub Stars
22
First Seen
Jun 19, 2026
offensive-mobile-role — aeondave/malskill