What is the persistent payload?
If you're using Metasploit and everything is running smoothly, but suddenly the target device restarts or the app is terminated, the session will be disconnected. This means you'll lose access to the target device, and you won't be able to regain access unless the app is launched again by the target (which is unlikely).
If the user notices an unfamiliar app on their device, they may uninstall it. This post provides guidance on concealing the app's icon to avoid detection. Furthermore, I'll outline steps to establish a persistent connection, allowing continued access to the device, even after it restarts and reconnects to the internet.
Create persistent payload :
In order to do this step, you should already be in the meterpreter session. If you don't have meterpreter session please read this blog on [hacking my second android phone using Termux with Metasploit]
Step 1:
First of all Download the shell.sh file and paste it in your internal storage:
Step 2:
In the Meterpreter session type this command to access the internal storage of the second phone.
cd /sdcardafter this command, you can type ls command to see all the folders in internal storage
Step 3:
Now use this command to upload the shell.sh file in second phone.
upload /data/data/com.termux/files/home/storage/shared/shell.sh
this command will upload shell.sh file from your internal storage to the target internal storage.
Step 4:
Type shell command to open shell in android.
shell
type below command to run the script in the shell.
sh shell.shNow After 1-2 min(or when the line starts to repeat then) press CTRL+C and then type y to terminate the channel.
Step 6:
Now everything is done, just hide the app icon using below command and the app will be hidden and you will still be able to access the phone.
hide_app_icon
19 Comments
Graciasss ;!!
ReplyDeleteThis is the most wonderful tutorial ive ever came by
ReplyDeleteThanks bro
DeletePlease I need a private tutoring
ReplyDeleteHit me up on Instagram
Deletewhat is your instagram??
DeletePlz share shell.sh file
ReplyDeleteit on to of the post
DeleteIts help full for me tq
ReplyDeleteIts very helpfull 😊👌
ReplyDelete❤👾
DeleteIt isn't working for Android 10 :-(
ReplyDeleteAre you getting any errors?
DeleteIf I change the name of the app in apkeditor from 'MainActivity' to 'Updater', then will I have to edit the shell file also???
ReplyDeleteNo, You Don.t have to
Deletemaybe you can edit name but not edit there extension like shell.sh to processfile.sh
DeleteBro file jo tmne di hai vo virus se bhari padi kamskam shi file to do
ReplyDeleteHi
ReplyDeleteHi
ReplyDelete