Overview
Developed by lico-n, ZygiskFrida is a stealth dynamic instrumentation framework designed for Android reverse engineers and security researchers.
Traditional mobile dynamic analysis requires either attaching to an app using frida-server (which uses Linux’s ptrace system call and is easily detected by anti-tamper SDKs) or repackaging the APK to embed libgadget.so (which trips APK signature and checksum verification). ZygiskFrida solves both challenges by injecting the Frida gadget into the application process during Zygote specialization, leaving the original APK completely unmodified and avoiding external debugger attachment.
Technical Architecture & How It Works
In-Process Gadget Loading & Specialization Hooks
ZygiskFrida hooks into the Android process creation lifecycle:
- Zygote Companion Hook: When an application process is forked by Zygote, ZygiskFrida intercepts
postAppSpecialize. It checks the process package name against the target rules defined in/data/local/tmp/re.zyg.fri/config.json. - Native Gadget Injection: If the process matches an enabled target, the module uses dynamic linker primitives (such as
dlopenviaxdl) to maplibgadget.sodirectly into process memory. - Execution Delay & Anti-Tamper Avoidance: Many protected applications perform aggressive integrity scans only within the first few hundred milliseconds of process startup. Through
start_up_delay_ms, researchers can configure an intentional delay, allowing initial security checks to complete before the gadget initializes. - Child Gating: Supports instrumenting multi-process applications by intercepting secondary process forks and loading child gadgets in
freezemode until explicitly released.
Installation & Setup
1. Flash the Module
- Download the latest
ZygiskFrida-v*.zipfrom the project’s official releases. - Flash the module in your root manager (Magisk, KernelSU, or APatch) with Zygisk enabled.
- Reboot your device.
2. Configure Your Target Application
Copy the example configuration file and specify your target package name:
adb shell 'su -c cp /data/local/tmp/re.zyg.fri/config.json.example /data/local/tmp/re.zyg.fri/config.json'
adb shell "su -c sed -i 's/com.example.package/com.target.application/' /data/local/tmp/re.zyg.fri/config.json"
3. Attach with Frida
Launch the application on your Android device. The app will hold at startup:
frida -U -N com.target.application
# Or attach by gadget name:
frida -U -n Gadget
Configuration & Practical Usage
Fine-tuning is handled in /data/local/tmp/re.zyg.fri/config.json:
{
"targets": [
{
"app_name": "com.target.application",
"enabled": true,
"start_up_delay_ms": 500,
"injected_libraries": [
{
"path": "/data/local/tmp/re.zyg.fri/libgadget.so"
}
],
"child_gating": {
"enabled": false,
"mode": "freeze",
"injected_libraries": [
{
"path": "/data/local/tmp/re.zyg.fri/libgadget-child.so"
}
]
}
}
]
}
Troubleshooting & Common Issues
- Port Conflict with frida-server: If you also run a standalone
frida-server(e.g. via MagiskFrida), both tools will compete for TCP port27042. Configure a custom listening port or unix domain socket for the gadget, or disablefrida-serverwhile using ZygiskFrida. - Emulator Native Hooks: On Android emulators running binary translation (e.g. ARM-on-x86), the gadget initializes within the native translation realm. You can hook Java classes and methods, but hooks on native C/C++ routines may require matching host architecture builds.
Frequently Asked Questions
Why use ZygiskFrida instead of running a standard frida-server daemon?
Standard frida-server attaches to the target application from the outside using Linux's ptrace system call, which is immediately detected and blocked by modern banking and anti-cheat SDKs. Additionally, repackaging APKs with frida-gadget breaks cryptographic signature checks. ZygiskFrida injects the gadget from within the process during Zygote initialization, bypassing both ptrace and signature checks.
Why does the target app pause immediately upon launching?
By default, the injected Frida gadget runs in 'listen' mode, pausing application execution at startup until a Frida client (e.g. frida -U -N
