YumyHook

English · 简体中文

A system-level device-spoofing module for Android, built on LSPosed / libxposed. By hooking android.os.Build, SystemProperties, getprop and the Native property readers, it returns configurable fake values to any app inside the LSPosed scope, with a full set of anti-detection capabilities on top.

Built on the modern libxposed API 102 — LSPosed no longer flags the module as using deprecated APIs.

⚠️ Root is required. YumyHook's companion app needs Superuser access. In your root manager — Magisk (or KernelSU / APatch) — grant Superuser permission to YumyHook. Without it the home screen stays locked and the app cannot force-stop scoped apps or read Root / LSPosed / framework status. (LSPosed itself also requires root.)

Features

  • Per-app property spoofing (four channels) — android.os.Build static fields, Java SystemProperties, getprop, and Native __system_property_get, kept mutually consistent.
  • SIM card spoofing & customization — carrier MCC/MNC, operator name, ISO country, SIM state.
  • Device identifier spoofing — IMEI / IMSI / phone number / Android ID (partial or full).
  • Custom location — spoof GPS / network / fused location (lat/lng/altitude/accuracy).
  • Other identity — Wi-Fi info, install source (Google Play), browser fingerprint (WebView UA).
  • Anti-detection — hide Root (su/Magisk), hide LSPosed/Xposed (maps, files, module list, class fingerprints), hide developer options / VPN / proxy / airplane mode / Wi-Fi list / Bluetooth, block LAN scan; framework-scope (system_server) root-property hiding.
  • Multi-profile config, per-app four-channel/native override, and auto force-stop of scoped apps on config change (with Root).
  • In-app language switch (English / 中文) on the home screen; default English, cached across launches.

Requirements

Item Requirement
Android 8.0+ (minSdk 26)
Framework LSPosed with libxposed API 100+ (API 102 recommended)
Root Required — grant Superuser to YumyHook in Magisk / KernelSU / APatch

Install & Use

  1. Download and install the APK from this repo's Releases.
  2. Grant YumyHook Superuser permission in Magisk (or KernelSU / APatch) — approve the root prompt on first launch, or add it manually in the root manager.
  3. Enable YumyHook in LSPosed and select the target apps in its scope.
  4. Open YumyHook → turn on Enable Hook Spoofing → edit the config.
  5. Force-stop the target app and reopen it to verify.

Disclaimer

For study and research only. Users must comply with local laws and the target apps' terms of service. The author is not responsible for any consequences of misuse.

License

CC BY-NC-ND 4.0 — Attribution, NonCommercial, NoDerivatives. Third-party commercial use and distribution of modified builds are prohibited; the copyright holder (Yumito) reserves the exclusive commercial right. Attribution and the lineage fingerprint YH-LIN-8d4e2f91-yumito must be preserved.

Telegram: https://t.me/yumyhook

Releases

4-1.4

Stable

9/23/2026, 4:32:10 AM

Fixed the WeChat location bug. Please note that this version carries a high risk of account ban. Use with caution.

修复微信定位异常bug。请注意,该版本存在较高封号风险,请谨慎使用。毕竟人不能瞬间换一个设备从一个地方瞬间飞到另一个地方去,ip也对不上

Assets

1

3-1.3

Stable

9/20/2026, 10:19:22 AM

YumyHook v1.3

✨ What's New in 1.3

Location spoofing — major upgrade

  • Tencent location SDK support (QQ & apps using com.tencent.map.geolocation) — precise and coarse location are now spoofed, including the reverse-geocoded address (province / city / district) and anti–mock-detection fields.
  • AMap (高德) / Baidu (百度) SDK location coverage.
  • Location is now spoofed across all delivery paths: LocationManager (getLastKnownLocation / getCurrentLocation / requestLocationUpdates / getters), Google Fused Location, and the domestic SDKs above.
  • Smarter random location: presets are now language-aware — 20 real cities inside China in Chinese mode, 20 real cities worldwide in English mode (plausible coordinates & altitude, no "middle of the Pacific").

Device identifier spoofing — wider coverage

  • IMEI (getImei, incl. per-slot), MEID, legacy getDeviceId, IMSI (getSubscriberId), phone number (getLine1Number), serial (Build.getSerial) and SIM serial are now all covered across their method overloads (previously only the bare no-arg methods, so modern readers returned empty).

Scope

  • System Framework (android / system_server) and common map / ride-hailing apps added to the suggested scope list.

🛠 Fixes

  • Config changes now take effect immediately. Fixed a bug where the config mirror the hook reads (/data/local/tmp/yumyhook) was written only once and never refreshed, so edits after the first save silently had no effect.
  • Far fewer root-permission prompts. The app now reuses a single persistent su session and batches the force-stop of scoped apps into one call, so the root manager asks once instead of on every action.

⚠️ Known Issues

  • WeChat precise location is not yet spoofed. WeChat obtains its precise location through a native positioning path (libtencentlocsapp.so → native DataBus) that bypasses the Java layer, so current hooks cannot reach it. Under investigation.

📋 Current Features

  • Per-app property spoofing (four channels) — Build fields, Java SystemProperties, getprop, Native __system_property_get, kept consistent.
  • SIM spoofing — carrier MCC/MNC, operator name, ISO country, SIM state.
  • Device identifiers — IMEI / IMSI / phone number / Android ID / serial.
  • Location — system, Fused, and Tencent/AMap/Baidu SDKs.
  • Other identity — Wi-Fi info, install source (Google Play), WebView UA.
  • Anti-detection — hide Root (su/Magisk), hide LSPosed/Xposed, hide developer options / VPN / proxy / airplane mode / Wi-Fi list / Bluetooth, block LAN scan, framework-scope root-property hiding.
  • Multi-profile config, per-app override, auto force-stop of scoped apps on change (with Root), in-app language switch (English default), random device & location generator.

📦 Requirements

  • Android 8.0+ (minSdk 26)
  • LSPosed with libxposed API 100+ (102 recommended)
  • Root required (grant Superuser to YumyHook in Magisk / KernelSU / APatch)

YumyHook v1.3(简体中文)

✨ 1.3 新增

定位伪装 —— 重大升级

  • 支持腾讯定位 SDK(QQ 及使用 com.tencent.map.geolocation 的 App):精确与模糊定位均可伪装,包括逆地理编码地址(省/市/区)与反模拟检测字段。
  • 覆盖高德 / 百度定位 SDK。
  • 定位现已覆盖所有获取路径:系统 LocationManager、谷歌 Fused 融合定位、以及上述国产 SDK。
  • 更聪明的随机位置:预设按语言区分——中文界面随机中国境内 20 个城市,英文界面随机全球 20 个城市(坐标与海拔真实合理,不会定位到太平洋中间)。

设备标识伪装 —— 覆盖更全

  • IMEI(getImei,含分卡槽)、MEID、旧版 getDeviceId、IMSI(getSubscriberId)、手机号(getLine1Number)、序列号(Build.getSerial)、SIM 序列号,现已覆盖各方法重载(此前只 hook 无参方法,导致现代读取方拿到空值)。

作用域

  • 建议作用域清单新增**系统框架(android / system_server)**及常见地图 / 出行 App。

🛠 修复

  • 改配置立即生效。 修复了 Hook 侧读取的配置镜像(/data/local/tmp/yumyhook)只写一次、之后永不刷新的 bug(此前首次保存后再改配置不生效)。
  • 大幅减少 Root 授权弹窗。 改用常驻 su 会话,并将作用域内 App 的强杀合并为一次调用,Root 管理器只需授权一次,不再每次操作都弹。

⚠️ 已知问题

  • 微信精确定位暂未伪装。 微信通过 native 定位通道(libtencentlocsapp.so → native DataBus)获取精确位置,绕过了 Java 层,现有 hook 够不到,正在研究。

📋 现有功能

  • 按 App 属性伪装(四通道):Build 字段、Java SystemProperties、getprop、Native __system_property_get,四者保持一致。
  • SIM 伪装:运营商 MCC/MNC、运营商名称、ISO 国家、SIM 状态。
  • 设备标识:IMEI / IMSI / 手机号 / Android ID / 序列号。
  • 定位:系统、Fused、腾讯 / 高德 / 百度 SDK。
  • 其它身份:Wi-Fi 信息、安装来源(Google Play)、WebView UA。
  • 反检测:隐藏 Root(su/Magisk)、隐藏 LSPosed/Xposed、隐藏开发者选项 / VPN / 代理 / 飞行模式 / Wi-Fi 列表 / 蓝牙、阻止局域网扫描、系统框架作用域 Root 属性隐藏。
  • 多配置档案、按 App 单独覆盖、配置变更后(有 Root)自动强停作用域 App、App 内语言切换(默认英文)、随机设备与随机位置生成。

📦 环境要求

  • Android 8.0+(minSdk 26)
  • LSPosed,libxposed API 100+(推荐 102)
  • 必须 Root(在 Magisk / KernelSU / APatch 中给 YumyHook 授予超级用户权限)

adr_2_0.apk ----- 检测用APP,可以检查手机当前参数,具备一定的root查询能力

Assets

1

9/18/2026, 9:19:50 AM

English users are now supported.

  • Per-app property spoofing (four channels) — android.os.Build static fields, Java
    SystemProperties, getprop, and Native __system_property_get, kept mutually consistent.

  • SIM card spoofing & customization — carrier MCC/MNC, operator name, ISO country, SIM state.

  • Device identifier spoofing — IMEI / IMSI / phone number / Android ID (partial or full).

  • Custom location — spoof GPS / network / fused location (lat/lng/altitude/accuracy).

  • Other identity — Wi-Fi info, install source (Google Play), browser fingerprint (WebView UA).

  • Anti-detection — hide Root (su/Magisk), hide LSPosed/Xposed (maps, files, module list, class
    fingerprints), hide developer options / VPN / proxy / airplane mode / Wi-Fi list / Bluetooth,
    block LAN scan; framework-scope (system_server) root-property hiding.

  • Multi-profile config, per-app four-channel/native override, and auto force-stop of scoped
    apps on config change (with Root).

  • 按 App 属性伪装(四通道) —— android.os.Build 静态字段、Java SystemProperties、
    getprop、Native __system_property_get,四者保持一致。

  • SIM 卡伪装与自定义 —— 运营商 MCC/MNC、运营商名称、ISO 国家、SIM 状态。

  • 设备标识伪装 —— IMEI / IMSI / 手机号 / Android ID(部分或完整)。

  • 自定义位置定位 —— 伪装 GPS / 网络 / Fused 定位(纬度/经度/海拔/精度)。

  • 其它身份 —— Wi-Fi 信息、安装来源(Google Play)、浏览器指纹(WebView UA)。

  • 反检测 —— 隐藏 Root(su/Magisk)、隐藏 LSPosed/Xposed(maps、特征文件、模块列表、Java 类
    指纹)、隐藏开发者选项 / VPN / 代理 / 飞行模式 / Wi-Fi 列表 / 蓝牙、阻止局域网扫描;系统框架
    作用域(system_server)Root 属性隐藏。

  • 多配置档案、按 App 单独覆盖 Java 三通道/Native 四通道、配置变更后(有 Root)自动强停作用域
    内 App。

Full Changelog: https://github.com/Xposed-Modules-Repo/com.yumito.yumyhook/commits/v2-1.2

Assets

1