Analyzing Android Phones at Scale — Anthony

Join us at hack.lu 2026 — Info & Registration

Duration: 30 min

Type: Talk

Speakers: Anthony

Abstract

Mobile devices have become the primary targets for highly sophisticated, targeted spyware and state-sponsored surveillance, yet validating a suspected compromise remains an adversarial challenge across all sectors. Whether in a corporate enterprise, an investigative newsroom, or a human rights organization, tracking mobile malware forces an impossible binary choice: accept the existential risk of data exfiltration, or initiate traditional forensics. For individual users, journalists, and corporate Incident Response (IR) teams alike, standard forensic methods are deeply destructive, and breaks critical software access. Because specialized forensic workstations are complex and cost-prohibitive, high-risk individuals and organizations often remain completely blind to ongoing breaches.

This talk introduces IsMyPhonePwned, an open-source, non-destructive mobile forensic framework designed to democratize device auditing. It allows anyone to scan for Indicators of Compromise (IoCs) and malware infections directly from a standard web browser over a USB connection. By leveraging WebAssembly and a high-performance stack written entirely in Rust, our framework enables client-side extraction, log parsing, and industry-standard Sigma rule evaluation without rooting, zero software installation, and zero device downtime. We will demonstrate how organizations and individual citizens can bypass complex, destructive investigative bottlenecks and perform rapid, privacy-preserving mobile triage at scale: https://ismyphonepwned.com/

Description

Innovation

The project introduces three key paradigm shifts to corporate mobile forensics:

  • Solving the Forensic “Nuke” Dilemma: It provides an intermediate triage layer. Instead of choosing between operational blindness and a disruptive factory reset, security teams can run a deep diagnostic assessment within five minutes without modifying system integrity.

  • Zero-Install, Client-Side Architecture: Traditional tools require forensic workstation setups. By shifting the ADB stack to WebUSB and compiling parsing engines to WebAssembly, triage is reduced to visiting a URL.

  • Privacy-First Execution Boundaries: Corporate data privacy is protected because the entire stack executes locally within the browser sandbox. The deep log extraction and threat analysis happen on the local machine; raw system dump files are never transmitted to third-party cloud backends. It could be used in total privacy without the risk to send your data in the cloud.

Full Technical Details

1. Communication Layer (webadb-rs)

The connection relies on the WebUSB browser API to map low-level USB interfaces directly into user-space JavaScript/WebAssembly. webadb-rs implements the raw Android Debug Bridge (ADB) framing protocol natively in Rust.

  • Cryptographic Handshake: It manages the necessary RSA keypair generation, token signing, and authentication handshake required by the Android adbd (ADB daemon) running on the device.

  • Data Streaming: Once authenticated, it opens a dynamic stream over a bulk USB endpoint to read system properties and trigger commands without a local ADB host server installed on the machine.

2. Ingestion & Extraction (bugreport-extractor-library)

Instead of attempting to pull raw memory dumps—which requires root access—the tool triggers a native Android bugreport. This produces a comprehensive zip archive containing system states, dumpsys outputs, kernel ring buffers (dmesg), and system logs (logcat).

  • High-Throughput Parsing: Bug reports can easily exceed 50MB to 100MB of dense unformatted text. This library uses Rust’s memory safety and zero-copy string parsing techniques to rapidly structure this data into key-value sets, active process tables, and chronological event timelines.

  • Anomaly Hunting: It checks for suspicious persistent daemons, hidden packages, altered permissions, and unauthorized property changes (getprop) that indicate persistent exploits.

3. Evaluation Engine (sigma-rs)

The core detection layer uses Sigma, the open-source generic signature format for security logs.

  • Local Rule Compilation: sigma-rs reads standard YAML Sigma rules (such as custom enterprise rules or external threat intelligence indicators from organizations like Amnesty International) and compiles them into highly optimized memory matching routines.

  • Log Evaluation in Wasm: The structured logs parsed by the extractor are fed straight into the sigma-rs execution layer inside the WebAssembly runtime. It evaluates behavioral logic (e.g., looking for unauthorized processes calling network APIs or unexpected system crashes) instantly at the edge.

Flow Of The Talk

**Phase 1: The Corporate Mobile Blindspot **

  • The Scenario: An executive returns from a high-risk trip; a targeted fishing or zero-day exploit link was potentially clicked. What happens next?

The Operational Reality: The breakdown of high-level fleet oversight vs. invasive physical investigation.

  • The MDM/UEM Limitation: Standard MDMs and analytics suites (like JAMF for iOS or Samsung Knox Asset Intelligence / KAI for Android) excel at operational health, app deployment, policy configuration, and surface telemetry (e.g., app crashes, battery state). However, they lack the deep system visibility required to identify low-level root compromises or stealthy kernel-level spyware.

  • The Heavy Forensic Alternative: Specialized imaging tools (Cellebrite, GrayKey) that extract raw data but are incredibly expensive, slow, and operationally destructive for business use.

  • The Binary Choice: Quantifying the actual financial and operational costs when an IR team has to wipe a functional phone to inspect it, if it is possible in the country.

**Phase 2: Introducing Web-Based Non-Destructive Triage **

  • The Paradigm Shift: Why browser-based WebUSB bridges the gap between end-users and security engineers.

  • Architecture Blueprint: Walkthrough of how data flows out of the device, through the browser engine, and maps directly into the processing pipeline without external cloud infrastructure.

**Phase 3: Deep Dive into the Rust Core & Diagnostics **

  • The WebUSB Framing Protocol (webadb-rs):

    • Direct Transport: Communicates via USB bulk endpoints using the WebUSB API, completely bypassing native host ADB daemons.

    • Handshake & Auth: Pure-Rust implementation of the token authentication challenge.

    • Multiplexed Streams: Handles packet commands and the sync protocol to pull logs and stream real-time updates.

  • Wasm Performance & Memory (bugreport-extractor-library):

    • Zero-Copy Scaling: Parses massive 100MB+ logs inside the browser using zero-copy string slicing to minimize memory footprint.

    • Parallel Ingestion: Leverages multi-threaded compilation pipelines to process heavy system state dumps simultaneously.

  • Behavioral Diagnostics & Amnesty Rule Matching:

    • Heuristic Defenses: Identifies advanced threats without root access by tracking power-drain beaconing (periodic C2 alarms) and memory corruption patterns in system crash tombstones.

    • Community Rule Pipeline: Pulls and compiles live threat playbooks and public Indicators of Compromise (IoCs) sourced directly from Amnesty International.

View on pretalx