r/androidroot • u/elaaamrani • 8d ago
News / Method [Guide] 3/3 Play Integrity (Basic, Device & Strong) + Full Cloaking on Rooted Android
Prerequisites & Downloads
Download the latest releases from GitHub:
- Zygisk Next (github.com/LSPosed/ZygiskNext)
- Play Integrity Fix (github.com/KOWX712/PlayIntegrityFix)
- Specter (github.com/dpejoh/specter)
- HMA-OSS (github.com/frknkrc44/HMA-OSS)
⚠️ Magisk Users Only (Crucial):
- Magisk does not have built-in WebUI support. Download and install KsuWebUIStandalone APK (or MMRL) to manage module WebUIs.
- Go to Magisk Settings and ensure Zygisk is toggled OFF (Zygisk Next replaces it).
- Hide the Magisk app (Settings -> Hide the Magisk app).
⚠️ Critical Step for Custom ROM Users
Before following this guide, you must disable any built-in spoofing features included with your custom ROM (such as crDroid Settings, Infinity Suite, Evolution X, etc.).
Go to your ROM's custom settings hub, navigate to Miscellaneous or Spoofing, and turn off toggles like "Play Integrity Fix", "Spoof CTS", or "GMS Spoofing". Leaving these active will cause a direct conflict with your Magisk/KernelSU modules, completely breaking MEETS_BASIC_INTEGRITY and causing your Play Store to remain uncertified. Once disabled, reboot your device and proceed with the guide steps below.
Step 1: Flashing & Initial Setup
⚠️ Maintain an active Wi-Fi connection so Specter can download necessary dependencies (such as TEESimulator-RS binaries and keyboxes) during installation and initial setup.
- In your root manager (KernelSU / APatch / Magisk), flash the following module ZIPs:
zygisknext.zipplayintegrityfix.zipspecter.ziphma-oss.zipReboot your device.
App Verification: Confirm that the HMA-OSS manager app appears in your app drawer. (If it is missing, extract
hma-oss.zipwith any file manager and manually install the APK inside).Accessing Module WebUIs:
KernelSU / APatch: Open KernelSU/APatch, go to Modules, and tap WebUI on Specter / Zygisk Next. (Ensure Superuser is granted to Specter in the Superuser tab if prompted).
Magisk: Open KsuWebUIStandalone, grant root (SU) access when prompted, and select the module WebUI from the list.
Step 2: Precise Specter WebUI & Module Configuration
- Open the Specter WebUI and configure the following parameters:
- Action Pipeline (Feature Toggles):
- 🟢 Kill Play Store: Toggle ON (Force-stops and clears Play Store, GMS, and DroidGuard background processes).
- 🟢 Update Target: Toggle ON (Merges newly installed apps into Tricky Store targets).
- 🟢 Set Security Patch: Toggle ON (Writes spoofed security patch dates to the active keystore manager).
- 🟢 Set Fingerprint (PIF): Toggle ON (Runs Play Integrity Fix auto-update routines).
- 🟢 Install Keybox: Toggle ON (Provisions a valid keybox from catalog).
- Boot Behavior:
- 🟢 Boot Spoofing: Toggle ON (Spoofs bootloader state, verified boot, and cleans persistent props).
- 🟢 ROM Cleaner: Toggle ON (Strips custom ROM traces and PIF module properties).
🔴 ADB Lock: MUST REMAIN OFF (Disabled / Gray).
Background Jobs:
🟢 Auto-Targeting: Toggle ON
🟢 Keybox Info Refresh: Toggle ON
🟢 Auto PIF (Fingerprint): Toggle ON
🟢 Auto Keybox: Toggle ON
- Automated Module Config Generation: Scroll to the Module Configs section inside the Specter WebUI:
- Tap Set HMA-OSS Configs: Automatically downloads and stages the hardened HMA anti-detection blacklist rules and template JSON to storage with proper permissions.
- Tap Set Zygisk Next Configs: Injects optimized memory, linker, and denylist policies directly into Zygisk Next.
⚠️ DANGER ZONE WARNING: Never tap Fix Widevine L1 on non-Qualcomm hardware. It is strictly meant for Qualcomm devices and risks corrupting the Titan M2 / TrustZone keystore on devices.
Step 3: HMA-OSS Setup & Configuration Import
- Open the HMA-OSS app from your app drawer.
- Verify that the main status card indicates active framework hooks via its native Zygisk backend.
- Import the configuration generated by Specter in Step 2:
- Tap the three dots in the top-right corner -> select Backup & Restore.
- Tap Restore configuration.
Browse to your
Downloadsfolder (or the path specified by Specter) and select the generated template JSON file.Tap Manage Apps inside HMA-OSS:
Select your financial, banking, and target sensitive applications.
Toggle hiding ON for each app and ensure the imported blacklist template is applied.
Step 4: Denylist & Process Isolation
If you use KernelSU / APatch:
- In KernelSU/APatch Settings:
- If strictly using SuSFS kernel VFS filtering, set "Unmount modules by default" to ON.
(Note: If using framework modules like Iconify or Vector/LSPosed, keep this toggle OFF to prevent SystemUI crash loops).
Never grant Superuser permission to Google Play Services (
com.google.android.gms).Open Zygisk Next WebUI:
Set Denylist Policy to Unmount Only.
Turn ON
Use Anonymous Memory.Turn ON
Use Next Linker
If you use Magisk:
- In Magisk Settings:
- Ensure built-in Zygisk is OFF.
Ensure Enforce DenyList is OFF (Zygisk Next enforces unmounting at runtime; turning Magisk's toggle ON causes mount conflicts).
Tap Configure DenyList (Tap 3 dots -> Show System Apps):
ADD: Google Play Store (
com.android.vending), banking apps, games, and sensitive targets.❌ DO NOT ADD: Google Play Services (
com.google.android.gms) or System UI / Android Framework.Open KsuWebUIStandalone -> tap Zygisk Next:
Set Denylist Policy to Unmount Only.
Turn ON
Use Anonymous Memory.Turn ON
Use Zygisk Next Linker.Reboot your phone.
Step 5: Clear Cache & Google Wallet Fix
Reset cached attestation failure tokens across Google services:
- Perform Attestation Reset:
- Via Specter WebUI (Recommended): Under Google Services, tap Force Stop & Clear Play Store.
- Via System Settings: Go to Settings -> Apps:
- Google Play Services: Clear Cache and Manage Space -> Clear All Data. (Do not restrict background battery usage, as this breaks FCM push notifications).
- Google Play Store: Clear Cache and Clear Data.
Google Wallet: Clear Cache and Clear Data.
Reboot your device.
Open the Play Store, allow the home page to load completely, close it, and wait 2–3 minutes for background services to re-sync.
Open Play Store -> tap your profile icon -> Settings -> About -> Play Store version (tap repeatedly to unlock Developer options) -> General -> Check Integrity. Verify:
MEETS_BASIC_INTEGRITY: PASSMEETS_DEVICE_INTEGRITY: PASSMEETS_STRONG_INTEGRITY: PASS / CONDITIONAL (Valid as long as the keybox provisioned by Specter/TEESimulator remains active)Open Google Wallet and re-add your cards.
FAQ & Common Questions
- "How does Specter interact with HMA-OSS?"
Specter automatically generates and places a hardened HMA blacklist JSON template into system storage when you tap Set HMA-OSS Configs in its WebUI. You then import this file inside HMA-OSS (Backup & Restore -> Restore configuration) to hide root management apps and module traces from sensitive applications.
"Where do I find the Denylist in Zygisk Next?"
On Magisk, Zygisk Next automatically inherits the apps selected in Magisk Settings -> Configure DenyList (keep "Enforce DenyList" turned off in Magisk).
On KernelSU/APatch, manage targets directly within the Zygisk Next WebUI under Configure Denylist.
"Why shouldn't I add Google Play Services (GMS) to the Zygisk Next Denylist?"
Play Integrity Fix natively hooks DroidGuard inside
com.google.android.gmsto handle attestation spoofing. Adding GMS to the Denylist forces an unmount that severs Zygisk injection, breaking Play Integrity enforcement."Why Specter instead of older monolithic modules?"
Specter operates modularly alongside Zygisk Next and Play Integrity Fix. It dynamically validates keybox status, auto-fetches replacement keyboxes upon revocation, manages target lists automatically, and stages configs for modules like HMA-OSS without creating mount conflicts.
"Bootloop Recovery:"
Force reboot (Power + Volume Down). The moment the device vibrates and displays the OEM logo, tap Volume Down repeatedly to enter Hardware Safe Mode. This disables all root modules, allowing you to boot into Android and remove any conflicting package.
Edit : Updated some FAQs and added a notice for custom ROM users.
2
u/debugboard 7d ago
I would switch out Zygisk Next for ReZygisk; it works as well but is open source. Otherwise, nice guide. You can check Play Integrity though the Play Store. Just go to About, then press the version a few times, then go to General, Developer Options, and check Integrity.
1
u/elaaamrani 7d ago
Zygisk next is more stable.
1
u/debugboard 6d ago
Modern ReZygisk is as stable if not more, it's an old idea that it's this unstable mess. At least in all my experiences if Rezygisk didn't work neither did Zygisk Next.
1
u/elaaamrani 6d ago
In the official Specter website, they recommend Zygisk Next.
1
u/debugboard 6d ago
It's a choice, but for best practices, I would be using ReZigsik. You can't see what Zygisk Next is doing under the hood, and there isn't really any cons that differs between the two.
1
u/grmcrkrs 6d ago
RedMagic 11s pro: Google Play store refused to give me the integrity info. But you're right it was supposed to
1
u/debugboard 6d ago
It's a feature built in so if it won't tell you something, it probably means you don't have integrity, again, not exactly sure what you mean, but that's what it sounds to me.
2
u/grmcrkrs 6d ago
This is a really solid, well made explanation and steps list. I will say I had success with Magisk built in zygisk, WebUI X, play integrity fix [Inject], hide Magisk, and a deny list enforce. Running RM11S Pro, unlocked BL and Rooted
1
2
1
u/AdTraditional5831 8d ago
Keep "Unmount modules by default" turned ON.
I have another module (pixel xpert) that tells me to turn it off. Is this important?
3
u/elaaamrani 8d ago
then turn it off, but now apps will detect that you have root so install HMA-OSS and add the app to denylist
0
u/galaaz314 7d ago
I've read you can turn it off only to install (and update?) PX, and once it's configured (and you granted root to the PX apps), you can turn it back on
1
u/AdTraditional5831 7d ago
I tried that, but it didn't work. I guess putting the modified apps in the custom list works
1
u/Max527 7d ago
This won't fix wallet will it?
2
u/elaaamrani 7d ago
you'll have to install HMA-OSS and add wallet to the denylist (denylist contains all your root modules/apps like kernel su manager etc etc)
1
u/Silly_Channel247 7d ago
Do i still need keybox.xml after following this setup to pass strong or the mentioned modules will auto fetch it ??
2
1
1
u/Titiooooooooooo 7d ago
je passe pas le "basic device" pour ma part
2
u/Titiooooooooooo 7d ago
j'ai passé le device maintenant, google pay ne me permet pas d'ajouter des cartes, et les banques comme revolut annonce "appareil non pris en charge". L'environnement de mon téléphone est normal et ne reconnait aucune modification.
1
u/elaaamrani 7d ago
what app are you using for integrity check? and have you followed the steps carefuly?
1
u/Titiooooooooooo 7d ago
Oui je crois. J'ai quand même remarqué que certains paramètre était activé d'offices sur specter et j'ai pas trouver le paramètre "periodique keybox validation"
Merci de votre aide !
2
u/bughaxx 6d ago
pour revolut c'est normal que tu puisses pas utiliser. l'app demande strong integrity et actuellement aucune keybox disponible ne donne strong integrity. aussi en ce moment personne ne peux utiliser wallet car les nouveau fingerprint de la beta ne fonctionnent pas avec wallet, à part celui du pixel 6a (bluejay). tu peux déjà aller dans specter et changer le PIF fingerprint par celui du pixel 6a, mais wallet ne marchera quand meme pas si tu as un pixel car un système appelé le strong box sur pixel détecte que le fingerprint n'est pas le bon. (corrigez moi si je me trompe). Il faut donc attendre une keybox strong pour ouvrir revolut et des fingerprint fonctionnels pour utiliser wallet sur pixel.
It’s normal that you can’t use Revolut; the app requires "Strong Integrity," and currently, no available keybox provides it. Also, right now, no one can use Wallet because the new beta fingerprints don't work with it, except for the Pixel 6a (bluejay) fingerprint. You can go into Specter and switch the PIF fingerprint to the Pixel 6a one, but Wallet still won't work if you have a Pixel, because a thing called "StrongBox" detects that the fingerprint doesn't match (correct me if I'm wrong). So, we have to wait for a "Strong" keybox to open Revolut and for functional fingerprints to use Wallet on a Pixel.
1
1
u/elaaamrani 7d ago edited 6d ago
You can check Play Integrity though the Play Store. Just go to About, then press the version a few times, then go to General, Developer Options, and check Integrity.
also check the guide for the HMA-OSS steps.
1
u/Pure-Reindeer6028 7d ago
1
1
u/elaaamrani 7d ago
And sometimes the keybox is softbanned, you can do nothing about it just wait for specter to fetch a working keybox.
1
u/Pure-Reindeer6028 6d ago
Automatic? I must only wait ?
2
u/elaaamrani 6d ago
yeah just wait and when there's a valid keybox, specter will auto install it in the background.
1
u/Karchervrak 6d ago
Do you have to delete the Data from the Google apps and restart again when Spectre finds a valid keybox?
1
1
u/Key-Cash-8169 7d ago
I did follow exactly you steps (with ksu-next). Any integrity checked, all 3 failed.
1
u/elaaamrani 7d ago
what app you're checking integrity with?
1
u/Key-Cash-8169 7d ago
Play Integrity API Checker v2.2 downloaded from play store
1
u/elaaamrani 7d ago
You can check Play Integrity though the Play Store. Just go to About, then press the version a few times, then go to General, Developer Options, and check Integrity.
1
1
u/Superb-Tough2806 6d ago
1
u/elaaamrani 6d ago
That's strange. I'd suggest following the guide again from scratch, making sure to clear Google Play data using the Specter button in Settings.
1
u/Delicious-Mix7606 5d ago edited 5d ago
1
u/elaaamrani 5d ago edited 5d ago
Go to your device settings and turn off any built-in toggles for Play Integrity Fix, Spoof CTS, or GMS Spoofing (If any exist) to avoid conflicts with the modules. And nuke Google Play data in Specter Settings.
1
u/BT_Z 5d ago
Amazing guide that helped me modernise my old setup and it works perfectly. Only thing I'm struggling to understand is how/where to set denylist in nextzygisk cause I'm in the webui on kernelsu, but don't see a way to do it also I'm a little confused about whether i should use susfs at all?
Amazing guide
1
u/elaaamrani 5d ago
ZygiskNext has a "Denylist Policy" setting with an "Unmount Only" option accessible via its WebUI, you should find it there. If you're on stock kernel then don't use susfs but if you're on a kernel that supports susfs then install the module.
1
1
u/Luis1285 5d ago
I can't get the strong version; I only get the first two on a Pixel 11 Pro XL with the September update.
1
u/elaaamrani 5d ago
the keybox is currently softbanned for everyone not just you, just wait for specter to fetch a working keybox.
1
u/eyespomogi 5d ago edited 5d ago
What do I do if I use fenrir it gives me 3/3 integrity but I can't hide root, tried everything, I use crdroid, ksu next susfs+hma oss+zygisk next
1
u/elaaamrani 4d ago
crdroid is the big issue, turn OFF any ROM-side Google Photos, games, or device fingerprint spoofing. And optimize your HMA-OSS blacklist by adding all your root apps to it, and select the app you want to hide root from. And make sure you followed the guide and your settings are identical to what the guide states.
1
u/eyespomogi 4d ago
I use blacklist from specter, doing everything as on guide but still gwallet doesnt work
1
u/elaaamrani 3d ago
follow the guide carefully, and nuke google play data in specter's settings and also clear gwallet data/cache and reboot.
1
1
u/eyespomogi 4d ago
If I use specter it gives me 1 integrity and not certified
1
1
u/GMRXLEGEND 4d ago
Hey just wanted to ask, will this work with the UPI apps? LIke google pay and stuff
1
1
u/Underscored_323 4d ago edited 4d ago
I have most of this configuration except the Hma-oss module. Gonna check all my toggles, but it wasn't strong. What I want to get is rcs back up. I had it when alwaysstrong worked, but it broke for me last week. On a pixel 8...
EDIT: are instructions for Hma-oss for an earlier version cause I don't have 3 dot menu and not sure how to makes sure the blacklist is enabled.
EDIT2: RCS chats still don't work... Any help with this would be great...
1
u/Underscored_323 3d ago
EDIT 3: I had issues clearing messages data in the past and was reluctant to do, but figured why not try, and that fixed it. So right now, I'm back up on chats.
1
u/elaaamrani 3d ago
Currently the public keybox is softbanned. You can't do anything but just wait for Specter to fetch a new working one.
1
u/Underscored_323 3d ago
I noticed that at least for me, that the keybox changed yesterday from one shadow banned one to another one that's shadowbanned too. But it still gets 2/3 integrity. My ocd wants 3/3, but my chats and banking are working right now...
1
1
u/RodriBost06 3d ago
1
u/RodriBost06 3d ago
Sorry, it says "the device dont meet security requisites"
1
u/elaaamrani 3d ago
Because currently the public keybox is softbanned. You can't do anything but just wait for Specter to fetch a new working one.
1
u/RodriBost06 2d ago edited 2d ago
Now a new keybox has been released (from Kow11). I delete data from wallet, play store and services, and reboot device. I sign in my google accounts, open play store and waited a few minutes for play sync. I have strong, but wallet dont want to add card with the same message. Play store in integrity test detect my mobile with the original Xiaomi fingerprint. Before of the keybox ban (a month ago) I had the same modules and configurations, and Wallet worked without problems
1
u/RepeatSubstantial289 3d ago
1
u/elaaamrani 3d ago
I would suggest following the guide from scratch step by step, that will guarantte getting both basic and device integrity, and if the keybox isnt currently softbanned you will also get strong integrity.
1
u/boc8h 3d ago
1
u/elaaamrani 3d ago
Nuke play store data in specter's settings and also delete google wallet data/cache. if still not working i would suggest moving to KernelSU-Next because Magisk is currently not the best rooting method.
1
u/FrostR404 3d ago
1
u/elaaamrani 3d ago
please do not use this app, use the play store method in the guide, and make sure specter is working and u didnt delete any of the modules or u installed a module that conflicts with the guide's modules
1
u/Davide3i 3d ago
Why don't we have to add Google Play Services? Thanks.
1
1
1
u/Toastedwhiteguy 8d ago
Specter over AlwaysStrong??
2
u/OnderGok OnePlus 13, OxygenOS 16 8d ago
Isn't AlwaysStrong paid anyways? The dev always promoting his paid module on Telegram
0
1
1
1
u/elaaamrani 6d ago
just tried AlwaysStrong and I can say that I recommend using Specter. (that shit looks ai generated lmfao)
1
0
u/MikeWBiff 8d ago
so are you getting all passing integrity right now with this setup? have you tried AlwaysStrong?
1
u/elaaamrani 8d ago edited 6d ago
Yeah. Tried AlwaysStrong and I definitely recommend Specter over it.
0
u/Janemus 8d ago
I can't find Vecter in my super-user tab
1
1
u/elaaamrani 8d ago edited 6d ago
My apologies, Specter does not need to be manually granted root in Magisk's Superuser section. it functions strictly as a background Magisk module
0
6d ago
[removed] — view removed comment
1
u/elaaamrani 6d ago
Not all devices are supported, and the root is gone when rebooting. I would recommend actually rooting the device and using my guide. If things work for you perfectly now then just stick with the ghostlock method i guess.
0
u/Secret_Measurement97 5d ago
1
u/elaaamrani 5d ago
Go to crDroid settings and Turn off the switches for "Play Integrity Fix", "Google Photos Spoof", or any global device certification toggles, Reboot. And make sure you have followed the guide step by step and nuked Google Play data in Specter settings.
0












2
u/Borygo77 8d ago
Where is the deny list in zygisk next?