Ross ROSS = Recommend OSS · open-source software intelligence for agents

dana-at-cp/backdoor-apk

backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only. observed · 2026-08-28

github.com/dana-at-cp/backdoor-apk · Shell · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3813
  • days_rel: n/a
  • days_push: 1451
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2367 stars · 713 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A shell script that automates injecting a Metasploit backdoor payload into any Android APK by decompiling, hooking smali code, and re-signing the app. It is intended for educational and penetration-testing purposes.

Use cases

  • inject a meterpreter payload into an android apk
  • create a backdoored apk for penetration testing
  • repackage an apk with a reverse tcp shell
  • learn how smali injection into android apps works
  • test mobile app security with a trojanized apk

When to choose

  • you need a quick, automated way to embed a Metasploit Android payload into an existing APK
  • you are doing authorized red-team or security-training exercises on Android apps
  • you want to study smali-level payload injection and obfuscation techniques

When to avoid

  • you need a stealthy, modern evasion tool - the technique is well-known and easily detected
  • you require ongoing support or updates - the project is in maintenance with infrequent releases
  • you are not comfortable with Linux, Bash, Metasploit, Apktool, and smali
  • you intend to use it against devices without explicit authorization - that is illegal

Facets

cli-tool · maturity maintenance

penetration-testing security reverse-engineering security penetration-testing android-tools mobile-development cli android-apk metasploit backdoor-injection smali apktool red-team offensive-security shell-script linux android

1 source

Member repositories

RepositoryRoleHealth v2
dana-at-cp/backdoor-apkmain32

For agents

markdown · JSON · MCP: product_card(name="dana-at-cp/backdoor-apk")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem