arXiv · 2609.23396
CLOADER: Evading Security Mobile Defenses via Runtime Obfuscation and Adaptive Hooking Tactics
Abstract
We propose a stealth framework that eliminates detection of hooking tools such as Frida and Xposed in secured mobile environments by replacing static configurations with dynamic evasion tactics. In contrast to existing approaches that apply these techniques independently, the framework introduces a unified runtime control layer that systematically coordinates network, temporal, and code-level evasive transformations. The solution integrates randomized port allocation, runtime code obfuscation, delayed execution triggers, and self-integrity checks to disrupt signature-based scans, timing heuristics, and tampering attempts. A custom Android loader, CLoader, enforces these mechanisms to isolate hooking activities from security monitors while maintaining complete interception and modification capabilities. Validation across enterprise anti malware systems, hardened applications, and device management platforms demonstrates a 90% bypass rate in our evaluation matrix. This approach enables reliable penetration testing and malware analysis in locked-down mobile ecosystems by masking network, temporal, and code-level fingerprints without architectural overhauls.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Nhat-Anh Huynh, Minh Quang Luu, Ngoc Hong Tran. 2026-09-20. CLOADER: Evading Security Mobile Defenses via Runtime Obfuscation and Adaptive Hooking Tactics. https://arxiv.org/abs/2609.23396
Cite the original work for its findings. Save a collection to share your selection of sources.