Traditional mobile security is based on the assumption that the operating system is a trusted environment. However, within the mobile phone repair ecosystem, automated “one-click” tools that claim to bypass protection mechanisms and conceal Root status from financial applications have become increasingly widespread.
This presentation analyzes how these types of tools can operate as part of hybrid Malware-as-a-Service (MaaS) schemes, combining evasion techniques on mobile devices with the distribution of information-stealing malware targeting the computers used by technicians. Through reverse engineering, dynamic analysis, and C2 infrastructure research, the operational behavior of these threats is exposed, along with their impact on the trust chain of the mobile ecosystem.
Presented at Ekoparty Miami 2026