MhmRdd

NoHello

0.0.7guide

A Zygisk module to hide root.

★1,360 stars
•Root Management•by MhmRdd•MIT•Updated May 31, 2025
Platforms:
✓ Magisk
Download 0.0.7Starting download...GitHub Source
Nohello-v0.0.7-53-4d53ecf-release.zip

Overview

Developed by MhmRdd, Zygisk NoHello is a specialized anti-detection module engineered to hide root privileges, Zygisk runtime artifacts, and systemless filesystem mounts from modern application integrity checks.

Standard root-hiding approaches frequently fail against modern multi-vector detection suites that scan for open ports, inspect /proc/mounts, analyze loaded shared libraries, and test execution permissions. NoHello operates at the Zygisk level to intercept detection routines before applications can complete their startup scans.


Technical Architecture & How It Works

Process Isolation & Mount Rules

NoHello hooks into application processes during the Zygote fork lifecycle:

  1. Mount Unmounting: For applications flagged in your manager’s DenyList or target configuration, NoHello detaches module overlays and mounts from the process mount namespace.
  2. Dynamic Rule Processing: Features a rule-based engine allowing users to specify exact path masking, file redirections, and property overrides for specific detection vectors.
  3. Trace Eradication: Cleans up internal hooking stubs and resets process capabilities before control is handed over to the application’s main entry point.

Installation & Setup

For KernelSU & APatch Users

  1. Install an active Zygisk implementation (ZygiskNext or ReZygisk).
  2. Ensure the Umount modules toggle is enabled for your target application in the Manager.
  3. Disable Enforce DenyList in ZygiskNext/ReZygisk settings if present.
  4. Flash the NoHello module and reboot.

For Magisk Users

  1. Magisk v28.0+ is recommended for optimal namespace isolation.
  2. Use ZygiskNext or ReZygisk (recommended over built-in Zygisk).
  3. Turn OFF Enforce DenyList in Magisk settings.
  4. Add your target application to Magisk’s Configure DenyList.

Configuration & Practical Usage

  • Whitelisting Mode: On version 0.0.4+, you can invert the operating policy to whitelist mode so all applications are isolated by default unless explicitly granted root visibility.
  • Custom Mount Rules: Place specialized unmount and masking instructions in /data/adb/nohello/rules to handle non-standard device modifications.

Troubleshooting & Common Issues

  • Detection Persists: Confirm that all background services and auxiliary processes of the target app are selected in the DenyList. Ensure Enforce DenyList is disabled across all manager settings.
  • Manager App Crashes: Do not enable module unmounting for the root manager itself (KernelSU Manager, APatch, or Magisk).

Frequently Asked Questions

Why must 'Enforce DenyList' be turned off when using NoHello?

NoHello manages its own unmounting and isolation routines. Enabling Enforce DenyList in Magisk or Zygisk providers activates competing mount namespaces that conflict with NoHello's cloaking logic.

Should I use the debug or release build of NoHello?

Always use the release build for daily use. The debug build contains verbose logging routines and exported symbols that can trigger security detections in anti-cheat and banking applications.