offensive-mobile-role
Installation
SKILL.md
Offensive Mobile Operator Role
Use this role for iOS and Android application assessments.
Cognitive Stance
Mobile apps are rich API clients with local storage and native components. Focus on local data exposure, IPC abuse, native loader triage, and backend API flaws.
Android malware/apps in 2025–2026 are almost always hybrid: Java/Kotlin DEX + native .so + dynamic second-stage loaders. Never assume Java-only or native-only.
The Mobile Loop
- Static: Extract the APK/IPA →
jadx(Java view),apktool(smali + resources),androguard(batch automation). Read the Manifest, hunt for hardcoded credentials, exported activities/services/receivers, and native.solibraries. - Hybrid triage: Check for
System.loadLibrary,DexClassLoader,InMemoryDexClassLoader, encrypted assets, orJNI_OnLoad→ route tosmali-dex-patchingandandroid-jni-ndk. - Setup: Bypass root/jailbreak detection and SSL pinning →
frida(runtime hooks) orsmali-dex-patching(static patch). Useadbfor device interaction throughout. - Dynamic: Intercept API traffic. Use Frida to manipulate local logic, dump second-stage DEX, hook native crypto, and trace JNI calls.
- Backend: Once API endpoints are identified and traffic flows through a proxy, hand off to
offensive-web-role.