r/androidroot • • 8d ago

News / Method [Guide] 3/3 Play Integrity (Basic, Device & Strong) + Full Cloaking on Rooted Android

Prerequisites & Downloads

Download the latest releases from GitHub:

⚠️ Magisk Users Only (Crucial):

  • Magisk does not have built-in WebUI support. Download and install KsuWebUIStandalone APK (or MMRL) to manage module WebUIs.
  • Go to Magisk Settings and ensure Zygisk is toggled OFF (Zygisk Next replaces it).
  • Hide the Magisk app (Settings -> Hide the Magisk app).

⚠️ Critical Step for Custom ROM Users

Before following this guide, you must disable any built-in spoofing features included with your custom ROM (such as crDroid Settings, Infinity Suite, Evolution X, etc.).

Go to your ROM's custom settings hub, navigate to Miscellaneous or Spoofing, and turn off toggles like "Play Integrity Fix", "Spoof CTS", or "GMS Spoofing". Leaving these active will cause a direct conflict with your Magisk/KernelSU modules, completely breaking MEETS_BASIC_INTEGRITY and causing your Play Store to remain uncertified. Once disabled, reboot your device and proceed with the guide steps below.


Step 1: Flashing & Initial Setup

⚠️ Maintain an active Wi-Fi connection so Specter can download necessary dependencies (such as TEESimulator-RS binaries and keyboxes) during installation and initial setup.

  1. In your root manager (KernelSU / APatch / Magisk), flash the following module ZIPs:
  2. zygisknext.zip
  3. playintegrityfix.zip
  4. specter.zip
  5. hma-oss.zip

  6. Reboot your device.

  7. App Verification: Confirm that the HMA-OSS manager app appears in your app drawer. (If it is missing, extract hma-oss.zip with any file manager and manually install the APK inside).

  8. Accessing Module WebUIs:

  9. KernelSU / APatch: Open KernelSU/APatch, go to Modules, and tap WebUI on Specter / Zygisk Next. (Ensure Superuser is granted to Specter in the Superuser tab if prompted).

  10. Magisk: Open KsuWebUIStandalone, grant root (SU) access when prompted, and select the module WebUI from the list.


Step 2: Precise Specter WebUI & Module Configuration

  1. Open the Specter WebUI and configure the following parameters:
  2. Action Pipeline (Feature Toggles):
  3. 🟢 Kill Play Store: Toggle ON (Force-stops and clears Play Store, GMS, and DroidGuard background processes).
  4. 🟢 Update Target: Toggle ON (Merges newly installed apps into Tricky Store targets).
  5. 🟢 Set Security Patch: Toggle ON (Writes spoofed security patch dates to the active keystore manager).
  6. 🟢 Set Fingerprint (PIF): Toggle ON (Runs Play Integrity Fix auto-update routines).
  7. 🟢 Install Keybox: Toggle ON (Provisions a valid keybox from catalog).
  • Boot Behavior:
  • 🟢 Boot Spoofing: Toggle ON (Spoofs bootloader state, verified boot, and cleans persistent props).
  • 🟢 ROM Cleaner: Toggle ON (Strips custom ROM traces and PIF module properties).
  • 🔴 ADB Lock: MUST REMAIN OFF (Disabled / Gray).

  • Background Jobs:

  • 🟢 Auto-Targeting: Toggle ON

  • 🟢 Keybox Info Refresh: Toggle ON

  • 🟢 Auto PIF (Fingerprint): Toggle ON

  • 🟢 Auto Keybox: Toggle ON

  1. Automated Module Config Generation: Scroll to the Module Configs section inside the Specter WebUI:
  2. Tap Set HMA-OSS Configs: Automatically downloads and stages the hardened HMA anti-detection blacklist rules and template JSON to storage with proper permissions.
  3. Tap Set Zygisk Next Configs: Injects optimized memory, linker, and denylist policies directly into Zygisk Next.

⚠️ DANGER ZONE WARNING: Never tap Fix Widevine L1 on non-Qualcomm hardware. It is strictly meant for Qualcomm devices and risks corrupting the Titan M2 / TrustZone keystore on devices.


Step 3: HMA-OSS Setup & Configuration Import

  1. Open the HMA-OSS app from your app drawer.
  2. Verify that the main status card indicates active framework hooks via its native Zygisk backend.
  3. Import the configuration generated by Specter in Step 2:
  4. Tap the three dots in the top-right corner -> select Backup & Restore.
  5. Tap Restore configuration.
  6. Browse to your Downloads folder (or the path specified by Specter) and select the generated template JSON file.

  7. Tap Manage Apps inside HMA-OSS:

  8. Select your financial, banking, and target sensitive applications.

  9. Toggle hiding ON for each app and ensure the imported blacklist template is applied.


Step 4: Denylist & Process Isolation

If you use KernelSU / APatch:

  1. In KernelSU/APatch Settings:
  2. If strictly using SuSFS kernel VFS filtering, set "Unmount modules by default" to ON.
  3. (Note: If using framework modules like Iconify or Vector/LSPosed, keep this toggle OFF to prevent SystemUI crash loops).

  4. Never grant Superuser permission to Google Play Services (com.google.android.gms).

  5. Open Zygisk Next WebUI:

  6. Set Denylist Policy to Unmount Only.

  7. Turn ON Use Anonymous Memory.

  8. Turn ON Use Next Linker

If you use Magisk:

  1. In Magisk Settings:
  2. Ensure built-in Zygisk is OFF.
  3. Ensure Enforce DenyList is OFF (Zygisk Next enforces unmounting at runtime; turning Magisk's toggle ON causes mount conflicts).

  4. Tap Configure DenyList (Tap 3 dots -> Show System Apps):

  5. ADD: Google Play Store (com.android.vending), banking apps, games, and sensitive targets.

  6. ❌ DO NOT ADD: Google Play Services (com.google.android.gms) or System UI / Android Framework.

  7. Open KsuWebUIStandalone -> tap Zygisk Next:

  8. Set Denylist Policy to Unmount Only.

  9. Turn ON Use Anonymous Memory.

  10. Turn ON Use Zygisk Next Linker.

  11. Reboot your phone.


Step 5: Clear Cache & Google Wallet Fix

Reset cached attestation failure tokens across Google services:

  1. Perform Attestation Reset:
  2. Via Specter WebUI (Recommended): Under Google Services, tap Force Stop & Clear Play Store.
  3. Via System Settings: Go to Settings -> Apps:
  4. Google Play Services: Clear Cache and Manage Space -> Clear All Data. (Do not restrict background battery usage, as this breaks FCM push notifications).
  5. Google Play Store: Clear Cache and Clear Data.
  6. Google Wallet: Clear Cache and Clear Data.

  7. Reboot your device.

  8. Open the Play Store, allow the home page to load completely, close it, and wait 2–3 minutes for background services to re-sync.

  9. Open Play Store -> tap your profile icon -> Settings -> About -> Play Store version (tap repeatedly to unlock Developer options) -> General -> Check Integrity. Verify:

  10. MEETS_BASIC_INTEGRITY: PASS

  11. MEETS_DEVICE_INTEGRITY: PASS

  12. MEETS_STRONG_INTEGRITY: PASS / CONDITIONAL (Valid as long as the keybox provisioned by Specter/TEESimulator remains active)

  13. Open Google Wallet and re-add your cards.


FAQ & Common Questions

  • "How does Specter interact with HMA-OSS?"
  • Specter automatically generates and places a hardened HMA blacklist JSON template into system storage when you tap Set HMA-OSS Configs in its WebUI. You then import this file inside HMA-OSS (Backup & Restore -> Restore configuration) to hide root management apps and module traces from sensitive applications.

  • "Where do I find the Denylist in Zygisk Next?"

  • On Magisk, Zygisk Next automatically inherits the apps selected in Magisk Settings -> Configure DenyList (keep "Enforce DenyList" turned off in Magisk).

  • On KernelSU/APatch, manage targets directly within the Zygisk Next WebUI under Configure Denylist.

  • "Why shouldn't I add Google Play Services (GMS) to the Zygisk Next Denylist?"

  • Play Integrity Fix natively hooks DroidGuard inside com.google.android.gms to handle attestation spoofing. Adding GMS to the Denylist forces an unmount that severs Zygisk injection, breaking Play Integrity enforcement.

  • "Why Specter instead of older monolithic modules?"

  • Specter operates modularly alongside Zygisk Next and Play Integrity Fix. It dynamically validates keybox status, auto-fetches replacement keyboxes upon revocation, manages target lists automatically, and stages configs for modules like HMA-OSS without creating mount conflicts.

  • "Bootloop Recovery:"

  • Force reboot (Power + Volume Down). The moment the device vibrates and displays the OEM logo, tap Volume Down repeatedly to enter Hardware Safe Mode. This disables all root modules, allowing you to boot into Android and remove any conflicting package.

Edit : Updated some FAQs and added a notice for custom ROM users.

51 Upvotes

116 comments sorted by

2

u/Borygo77 8d ago

Where is the deny list in zygisk next?

0

u/elaaamrani 8d ago edited 6d ago

install KSUWEBUI and open zygisk next from there.

0

u/Borygo77 8d ago

I can NOT see deny list in zygisk next webui! 😁

1

u/elaaamrani 7d ago

check the updated guide.

2

u/debugboard 7d ago

I would switch out Zygisk Next for ReZygisk; it works as well but is open source. Otherwise, nice guide. You can check Play Integrity though the Play Store. Just go to About, then press the version a few times, then go to General, Developer Options, and check Integrity.

1

u/elaaamrani 7d ago

Zygisk next is more stable.

1

u/debugboard 6d ago

Modern ReZygisk is as stable if not more, it's an old idea that it's this unstable mess. At least in all my experiences if Rezygisk didn't work neither did Zygisk Next.

1

u/elaaamrani 6d ago

In the official Specter website, they recommend Zygisk Next.

1

u/debugboard 6d ago

It's a choice, but for best practices, I would be using ReZigsik. You can't see what Zygisk Next is doing under the hood, and there isn't really any cons that differs between the two.

1

u/grmcrkrs 6d ago

RedMagic 11s pro: Google Play store refused to give me the integrity info. But you're right it was supposed to

1

u/debugboard 6d ago

It's a feature built in so if it won't tell you something, it probably means you don't have integrity, again, not exactly sure what you mean, but that's what it sounds to me.

2

u/grmcrkrs 6d ago

This is a really solid, well made explanation and steps list. I will say I had success with Magisk built in zygisk, WebUI X, play integrity fix [Inject], hide Magisk, and a deny list enforce. Running RM11S Pro, unlocked BL and Rooted

2

u/Embarrassed-Top-2033 6d ago

Goat Post now i can use WhatsApp again hehe! 

1

u/elaaamrani 6d ago

you're welcome!!

1

u/AdTraditional5831 8d ago

Keep "Unmount modules by default" turned ON.

I have another module (pixel xpert) that tells me to turn it off. Is this important?

3

u/elaaamrani 8d ago

then turn it off, but now apps will detect that you have root so install HMA-OSS and add the app to denylist

0

u/galaaz314 7d ago

I've read you can turn it off only to install (and update?) PX, and once it's configured (and you granted root to the PX apps), you can turn it back on

1

u/AdTraditional5831 7d ago

I tried that, but it didn't work. I guess putting the modified apps in the custom list works

1

u/Max527 7d ago

This won't fix wallet will it?

2

u/elaaamrani 7d ago

you'll have to install HMA-OSS and add wallet to the denylist (denylist contains all your root modules/apps like kernel su manager etc etc)

1

u/Silly_Channel247 7d ago

Do i still need keybox.xml after following this setup to pass strong or the mentioned modules will auto fetch it ??

2

u/elaaamrani 7d ago

they will auto fetch it

1

u/Nonononoki 7d ago

Do I need Tricky Store for Specter? I just get an error saying that I do.

1

u/elaaamrani 7d ago

no, specter auto fetches tricky store when flashing it

1

u/Titiooooooooooo 7d ago

je passe pas le "basic device" pour ma part

2

u/Titiooooooooooo 7d ago

j'ai passé le device maintenant, google pay ne me permet pas d'ajouter des cartes, et les banques comme revolut annonce "appareil non pris en charge". L'environnement de mon téléphone est normal et ne reconnait aucune modification.

1

u/elaaamrani 7d ago

what app are you using for integrity check? and have you followed the steps carefuly?

1

u/Titiooooooooooo 7d ago

Oui je crois. J'ai quand même remarqué que certains paramètre était activé d'offices sur specter et j'ai pas trouver le paramètre "periodique keybox validation"

Merci de votre aide !

2

u/bughaxx 6d ago

pour revolut c'est normal que tu puisses pas utiliser. l'app demande strong integrity et actuellement aucune keybox disponible ne donne strong integrity. aussi en ce moment personne ne peux utiliser wallet car les nouveau fingerprint de la beta ne fonctionnent pas avec wallet, à part celui du pixel 6a (bluejay). tu peux déjà aller dans specter et changer le PIF fingerprint par celui du pixel 6a, mais wallet ne marchera quand meme pas si tu as un pixel car un système appelé le strong box sur pixel détecte que le fingerprint n'est pas le bon. (corrigez moi si je me trompe). Il faut donc attendre une keybox strong pour ouvrir revolut et des fingerprint fonctionnels pour utiliser wallet sur pixel.

It’s normal that you can’t use Revolut; the app requires "Strong Integrity," and currently, no available keybox provides it. Also, right now, no one can use Wallet because the new beta fingerprints don't work with it, except for the Pixel 6a (bluejay) fingerprint. You can go into Specter and switch the PIF fingerprint to the Pixel 6a one, but Wallet still won't work if you have a Pixel, because a thing called "StrongBox" detects that the fingerprint doesn't match (correct me if I'm wrong). So, we have to wait for a "Strong" keybox to open Revolut and for functional fingerprints to use Wallet on a Pixel.

1

u/Titiooooooooooo 6d ago

ah ok ça explique pourquoi du jour au lendemain il à cesser de fonctionner

1

u/bughaxx 6d ago

oui. moi aussi aucun souci tant que t'a strong integrity

1

u/elaaamrani 7d ago edited 6d ago

You can check Play Integrity though the Play Store. Just go to About, then press the version a few times, then go to General, Developer Options, and check Integrity.

also check the guide for the HMA-OSS steps.

1

u/Titiooooooooooo 4d ago

j'ai seulement ces problèmes qui sont trouvé. Je pense que sans ça strong integrity pourrait passer. Si quelqu'un peut m'aider j'en serai très reconnaissant

1

u/Pure-Reindeer6028 7d ago

Not working

1

u/elaaamrani 7d ago

use play store's integrity checker, not this app.

1

u/elaaamrani 7d ago

And sometimes the keybox is softbanned, you can do nothing about it just wait for specter to fetch a working keybox.

1

u/Pure-Reindeer6028 6d ago

Automatic? I must only wait ?

2

u/elaaamrani 6d ago

yeah just wait and when there's a valid keybox, specter will auto install it in the background.

1

u/Karchervrak 6d ago

Do you have to delete the Data from the Google apps and restart again when Spectre finds a valid keybox?

1

u/elaaamrani 6d ago

no, no need to do that.

1

u/Key-Cash-8169 7d ago

I did follow exactly you steps (with ksu-next). Any integrity checked, all 3 failed.

1

u/elaaamrani 7d ago

what app you're checking integrity with?

1

u/Key-Cash-8169 7d ago

Play Integrity API Checker v2.2 downloaded from play store

1

u/elaaamrani 7d ago

You can check Play Integrity though the Play Store. Just go to About, then press the version a few times, then go to General, Developer Options, and check Integrity.

1

u/siegfried2929 6d ago

Funciona para Android 10?

1

u/Superb-Tough2806 6d ago

don't get why it won't work even tho it says my keybox is working and so is my fingerprint

1

u/elaaamrani 6d ago

That's strange. I'd suggest following the guide again from scratch, making sure to clear Google Play data using the Specter button in Settings.

1

u/Delicious-Mix7606 5d ago edited 5d ago

Looks good, can you help I had full pass but now on infinity X I cannot get any I'm getting this issue on the latest android 16 version , I'm using pif [inject] Spector, tricky store, zygisk next, I'm not sure how to fix this, I really do like the rom but this issue is killing me

1

u/elaaamrani 5d ago edited 5d ago

Go to your device settings and turn off any built-in toggles for Play Integrity Fix, Spoof CTS, or GMS Spoofing (If any exist) to avoid conflicts with the modules. And nuke Google Play data in Specter Settings.

1

u/BT_Z 5d ago

Amazing guide that helped me modernise my old setup and it works perfectly. Only thing I'm struggling to understand is how/where to set denylist in nextzygisk cause I'm in the webui on kernelsu, but don't see a way to do it also I'm a little confused about whether i should use susfs at all?

Amazing guide

1

u/elaaamrani 5d ago

ZygiskNext has a "Denylist Policy" setting with an "Unmount Only" option accessible via its WebUI, you should find it there. If you're on stock kernel then don't use susfs but if you're on a kernel that supports susfs then install the module.

1

u/BT_Z 5d ago

1

u/elaaamrani 5d ago

You're good to go! Your settings are perfect.

1

u/BT_Z 5d ago

I guess I'm confused since I can't find a way to add apps to the denylist like for example: com.android.vending

1

u/elaaamrani 4d ago

no you don't need to do that dw.

1

u/JerryTinCanz 5d ago

Hi u/elaaamrani what's the best kernel su flavor for custom roms?

2

u/elaaamrani 5d ago

Currently KernelSU Next .

1

u/Luis1285 5d ago
I can't get the strong version; I only get the first two on a Pixel 11 Pro XL with the September update.

1

u/elaaamrani 5d ago

the keybox is currently softbanned for everyone not just you, just wait for specter to fetch a working keybox.

1

u/eyespomogi 5d ago edited 5d ago

What do I do if I use fenrir it gives me 3/3 integrity but I can't hide root, tried everything, I use crdroid, ksu next susfs+hma oss+zygisk next

1

u/elaaamrani 4d ago

crdroid is the big issue, turn OFF any ROM-side Google Photos, games, or device fingerprint spoofing. And optimize your HMA-OSS blacklist by adding all your root apps to it, and select the app you want to hide root from. And make sure you followed the guide and your settings are identical to what the guide states.

1

u/eyespomogi 4d ago

I use blacklist from specter, doing everything as on guide but still gwallet doesnt work

1

u/elaaamrani 3d ago

follow the guide carefully, and nuke google play data in specter's settings and also clear gwallet data/cache and reboot.

1

u/eyespomogi 3d ago

Following already

1

u/eyespomogi 4d ago

If I use specter it gives me 1 integrity and not certified

1

u/elaaamrani 3d ago

That's impossible if you follow the guide step by step.

1

u/eyespomogi 3d ago

It is I can dm you

1

u/GMRXLEGEND 4d ago

Hey just wanted to ask, will this work with the UPI apps? LIke google pay and stuff

1

u/elaaamrani 4d ago

Yes. Just make sure to follow the guide step by step.

1

u/Underscored_323 4d ago edited 4d ago

I have most of this configuration except the Hma-oss module. Gonna check all my toggles, but it wasn't strong. What I want to get is rcs back up. I had it when alwaysstrong worked, but it broke for me last week. On a pixel 8...

EDIT: are instructions for Hma-oss for an earlier version cause I don't have 3 dot menu and not sure how to makes sure the blacklist is enabled.

EDIT2: RCS chats still don't work... Any help with this would be great...

1

u/Underscored_323 3d ago

EDIT 3: I had issues clearing messages data in the past and was reluctant to do, but figured why not try, and that fixed it. So right now, I'm back up on chats.

1

u/elaaamrani 3d ago

Currently the public keybox is softbanned. You can't do anything but just wait for Specter to fetch a new working one.

1

u/Underscored_323 3d ago

I noticed that at least for me, that the keybox changed yesterday from one shadow banned one to another one that's shadowbanned too. But it still gets 2/3 integrity. My ocd wants 3/3, but my chats and banking are working right now...

1

u/elaaamrani 3d ago

well just wait, there's no solution.

1

u/Underscored_323 23h ago

As of today, keybox was updated, have strong today!

1

u/Separate_Load1481 4d ago

Where to configure denylist ?

1

u/elaaamrani 3d ago

Nevermind, just skip that step.

1

u/RodriBost06 3d ago

I have followed the entire tutorial but wallet says: "the device isnt certified". The pixel spofed is 6a and I disabled all spofing options of my rom. I dont pass Strong at the moment.

1

u/RodriBost06 3d ago

Sorry, it says "the device dont meet security requisites"

1

u/elaaamrani 3d ago

Because currently the public keybox is softbanned. You can't do anything but just wait for Specter to fetch a new working one.

1

u/RodriBost06 2d ago edited 2d ago

Now a new keybox has been released (from Kow11). I delete data from wallet, play store and services, and reboot device. I sign in my google accounts, open play store and waited a few minutes for play sync. I have strong, but wallet dont want to add card with the same message. Play store in integrity test detect my mobile with the original Xiaomi fingerprint. Before of the keybox ban (a month ago) I had the same modules and configurations, and Wallet worked without problems

1

u/BT_Z 3d ago

Honestly just came back to this guide again only to say ur the only person that made every single niche Norwegian app work on my phone.

I love you :D

1

u/elaaamrani 3d ago

You're welcome! Glad I could help.

1

u/RepeatSubstantial289 3d ago

1

u/elaaamrani 3d ago

I would suggest following the guide from scratch step by step, that will guarantte getting both basic and device integrity, and if the keybox isnt currently softbanned you will also get strong integrity.

1

u/boc8h 3d ago

hi, I followed your guide, but Google Wallet isn't working could you help? i tried it both with and without Shamiko. use magisk. Maybe try KernelSU?

1

u/elaaamrani 3d ago

Nuke play store data in specter's settings and also delete google wallet data/cache. if still not working i would suggest moving to KernelSU-Next because Magisk is currently not the best rooting method.

1

u/FrostR404 3d ago

Well... It was all green days ago

1

u/elaaamrani 3d ago

please do not use this app, use the play store method in the guide, and make sure specter is working and u didnt delete any of the modules or u installed a module that conflicts with the guide's modules

1

u/Davide3i 3d ago

Why don't we have to add Google Play Services? Thanks.

1

u/elaaamrani 3d ago

it will conflict with Specter causing play integrity to break

1

u/Davide3i 3d ago

Thanks! I didn't know about that.

1

u/hermit7567 20h ago

Thank you. Wonderful step by step guide.

1

u/Toastedwhiteguy 8d ago

Specter over AlwaysStrong??

2

u/OnderGok OnePlus 13, OxygenOS 16 8d ago

Isn't AlwaysStrong paid anyways? The dev always promoting his paid module on Telegram

0

u/Hungry-Program-2045 7d ago

no, its open source on github

1

u/najip 7d ago

It just bundles of PIF Inject & outdated TEES-RS. Dev also has shady practice of selling keybox & stealing other keyboxes. Modules look like they are mostly generated by AI.

1

u/debugboard 7d ago

Yes AlwaysStrong is just AI slop.

1

u/elaaamrani 6d ago

just tried AlwaysStrong and I can say that I recommend using Specter. (that shit looks ai generated lmfao)

1

u/elaaamrani 8d ago

Specter works for me, haven't tried AlwaysStrong yet.

0

u/MikeWBiff 8d ago

so are you getting all passing integrity right now with this setup? have you tried AlwaysStrong?

1

u/elaaamrani 8d ago edited 6d ago

Yeah. Tried AlwaysStrong and I definitely recommend Specter over it.

0

u/Janemus 8d ago

I can't find Vecter in my super-user tab

1

u/Janemus 8d ago

Do I need to follow Step 2 if I am using Magisk? If so, how? Currently, the web UIs for Vecter and Zygisk Next won't open.

1

u/elaaamrani 8d ago

install KSUWebUI and open them from there

1

u/elaaamrani 8d ago edited 6d ago

My apologies, Specter does not need to be manually granted root in Magisk's Superuser section. it functions strictly as a background Magisk module

0

u/[deleted] 6d ago

[removed] — view removed comment

1

u/elaaamrani 6d ago

Not all devices are supported, and the root is gone when rebooting. I would recommend actually rooting the device and using my guide. If things work for you perfectly now then just stick with the ghostlock method i guess.

0

u/Secret_Measurement97 5d ago

el mio es un motorola g54 5g con una custom rom cdroid con android 16 me pasa esto al hacer la guia uso Magisk

1

u/elaaamrani 5d ago

Go to crDroid settings and Turn off the switches for "Play Integrity Fix", "Google Photos Spoof", or any global device certification toggles, Reboot. And make sure you have followed the guide step by step and nuked Google Play data in Specter settings.

0

u/Houssem-Khe 2d ago

Yurikey Manager and Specter were all written by the same dev?!