Shamiko Zygisk Module Guide
Developed by the LSPosed team, Shamiko is the gold standard for stealth root hiding. It conceals Magisk daemon sockets, modified mount namespaces, and root artifacts from aggressive enterprise security scanners, banking apps, and heuristic anti-cheat engines.
The Shamiko DenyList Paradox Explained
Unlike standard Magisk DenyList (which disables Zygisk in target processes), Shamiko maintains Zygisk hooks in target processes to actively hide root binaries, isolated mount namespaces, and `su` sockets. To use Shamiko properly, you must configure your target apps in Magisk DenyList, but you MUST keep "Enforce DenyList" turned OFF in Magisk Settings.
Step-by-Step Installation & Configuration Guide
Step 1: Enable Zygisk in Magisk
- Open Magisk App -> tap the gear icon in the top right.
- Toggle ON: Zygisk.
- Toggle OFF: Enforce DenyList (Critical: Shamiko enforces hiding itself).
- Tap Configure DenyList -> Select all banking apps, Google Play Services, and games you wish to hide root from.
Step 2: Flash Shamiko Module
- Download the latest Shamiko release zip (v1.1.1+ for 16KB kernel support).
- In Magisk App -> tap Modules -> Install from storage -> select the Shamiko zip.
- Reboot your device.
Step 3: Verify Shamiko Status
After rebooting, open the Magisk App -> Modules tab. Under Shamiko, you should see:
"Shamiko is working in blacklist mode" (or whitelist mode).
Blacklist vs Whitelist Mode
- Blacklist Mode (Default): Hides root from apps selected in Magisk DenyList. All other apps have normal root access.
- Whitelist Mode: Hides root from EVERY app on the phone except those explicitly granted root access in Magisk Superuser permissions. To enable whitelist mode, create an empty file at:
/data/adb/shamiko/whitelist.
How Shamiko Evades Modern Anti-Root Scanners
Modern banking applications and MDM enterprise management software (such as Microsoft Intune, AirWatch, and MobileIron) do not simply look for /system/bin/su or /system/app/Superuser.apk. Instead, advanced detection frameworks utilize native C/C++ code (frequently obfuscated with OLLVM) to scan /proc/self/mounts, inspect memory maps in /proc/self/maps, probe for open Unix domain sockets associated with Magisk's daemon, and inspect process environment variables.
Standard Magisk DenyList operates by reverting mount namespaces and unloading Zygisk from the target process. However, because Zygisk is completely detached, it cannot dynamically falsify system responses. Shamiko overcomes this fundamental limitation by maintaining an active, in-process hook within the target application. It intercepts system calls (including openat, readlinkat, stat, and ptrace) to actively filter out any trace of Magisk binaries, Zygisk shared libraries, and modified mount points.
Configuration Troubleshooting
If a banking application continues detecting root with Shamiko active:
- Check Magisk Settings: Double-check that "Enforce DenyList" is DISABLED. Enabling this setting blocks Shamiko from loading its interceptor hooks into target apps.
- Reset App Data: Target banking applications frequently cache root detection flags in local private storage (
/data/data/<package>/). Clear the app's cache and data via Android Settings before retesting. - Check 16KB Page Size Compatibility: On Android 15 and 16 preview devices running modern kernels, verify that you are running Shamiko v1.1.1 or later, which includes native 16KB memory page size compatibility.
Related Guides & Next Steps
Explore interconnected tutorials, module guides, and developer references related to this topic:
Bypass Banking Root Detection
TroubleshootMaster guide to defeating banking app heuristics and MDM.
Play Integrity Fix (PIF)
ModuleAttain valid device integrity fingerprints alongside Shamiko.
LSPosed Zygisk Framework
ModuleHook Java methods and isolate apps with Hide My Applist.
Checked against official upstream release Shamiko v1.1.1 on Magisk v30.7 Zygisk (February 23, 2026).