You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

检测并阻止应用在Clone App、Multi App Space类虚拟安卓环境运行

检测并阻止应用在Clone App/Multi App Space类虚拟环境运行的实用方案

针对这类虚拟环境的检测,单一的包名、签名校验容易被绕过,需要结合多维度特征检测,以下是可落地的实现方案:

1. 系统属性特征检测

虚拟环境通常会在系统属性中留下特殊标记,通过读取这些隐藏属性可以快速识别:

import android.os.SystemProperties;

public static boolean hasVirtualEnvProps() {
    String[] suspiciousKeys = {"ro.virtualenv", "ro.fake.device", "persist.sys.cloned_app", "ro.multiuser.virtual"};
    for (String key : suspiciousKeys) {
        String value = SystemProperties.get(key);
        if (value != null && !value.trim().isEmpty()) {
            return true;
        }
    }
    return false;
}

如果是非系统应用无法直接调用SystemProperties,可以通过反射读取:

public static String getSystemProp(String key) {
    try {
        Class<?> clazz = Class.forName("android.os.SystemProperties");
        return (String) clazz.getMethod("get", String.class).invoke(null, key);
    } catch (Exception e) {
        return null;
    }
}

2. 应用路径异常检测

虚拟环境下的应用数据目录通常会包含特定关键词,比如clone、virtual等,对比应用的实际安装路径:

public static boolean isAbnormalAppPath(Context context) {
    String dataDir = context.getFilesDir().getParentFile().getAbsolutePath();
    String[] suspiciousKeywords = {"clone", "virtual", "space", "multi", "fake"};
    for (String keyword : suspiciousKeywords) {
        if (dataDir.toLowerCase().contains(keyword)) {
            return true;
        }
    }
    return false;
}

3. 进程环境变量检测

部分虚拟环境会向进程注入特殊环境变量,遍历当前进程的环境变量查找特征:

public static boolean hasVirtualEnvEnvVars() {
    Map<String, String> envMap = System.getenv();
    for (String key : envMap.keySet()) {
        String lowerKey = key.toLowerCase();
        if (lowerKey.contains("clone") || lowerKey.contains("virtual") || lowerKey.contains("space")) {
            return true;
        }
    }
    return false;
}

4. 动态签名校验(进阶)

静态签名校验容易被篡改,改为在多个关键流程节点(如启动、支付、核心功能入口)动态校验签名哈希:

import android.content.pm.PackageInfo;
import android.content.pm.PackageManager;
import android.content.pm.Signature;
import android.util.Base64;
import java.security.MessageDigest;

public static boolean isSignatureValid(Context context) {
    try {
        PackageInfo pkgInfo = context.getPackageManager()
                .getPackageInfo(context.getPackageName(), PackageManager.GET_SIGNATURES);
        Signature signature = pkgInfo.signatures[0];
        MessageDigest md = MessageDigest.getInstance("SHA-256");
        md.update(signature.toByteArray());
        String currentSignatureHash = Base64.encodeToString(md.digest(), Base64.NO_WRAP);
        // 替换为你的应用合法签名的SHA-256哈希值
        String validHash = "你的应用签名SHA-256哈希";
        return currentSignatureHash.equals(validHash);
    } catch (Exception e) {
        return false;
    }
}

5. 硬件信息一致性校验

虚拟环境可能伪造硬件标识,多次读取同一硬件信息并对比是否存在不一致:

import android.provider.Settings;

public static boolean isHardwareInfoInconsistent(Context context) {
    String firstAndroidId = Settings.Secure.getString(context.getContentResolver(), Settings.Secure.ANDROID_ID);
    // 短暂延迟后再次读取
    try {
        Thread.sleep(1000);
    } catch (InterruptedException ignored) {}
    String secondAndroidId = Settings.Secure.getString(context.getContentResolver(), Settings.Secure.ANDROID_ID);
    return firstAndroidId == null || !firstAndroidId.equals(secondAndroidId);
}

组合检测与阻止逻辑

将上述检测方法组合使用,只要命中任意一项就执行阻止操作:

public void enforceAntiVirtualEnv(Context context) {
    boolean isInVirtualEnv = hasVirtualEnvProps() 
            || isAbnormalAppPath(context) 
            || hasVirtualEnvEnvVars() 
            || !isSignatureValid(context) 
            || isHardwareInfoInconsistent(context);
    
    if (isInVirtualEnv) {
        Toast.makeText(context, "应用不支持在虚拟环境运行", Toast.LENGTH_LONG).show();
        // 彻底退出应用
        ((Activity) context).finishAffinity();
        System.exit(0);
    }
}

建议在Application的onCreate方法、启动页onCreate方法中调用该检测逻辑,避免应用在虚拟环境中继续运行。

内容的提问来源于stack exchange,提问作者Tatheer Fatima

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 11:47:04