EXP Variant Anti-VM-Detection Strategy in vPhone-CLI: 6 Kernel and User-Space Techniques

The EXP variant in Lakr233/vphone-cli evades virtual machine detection by renaming the kern.hv_vmm_present sysctl, mangling kernel-internal string references, patching the watchdogd cache, rewriting the DeviceTree after restore, and spoofing system build versions to present the iOS guest as physical hardware.

The EXP (experimental) firmware variant in the Lakr233/vphone-cli repository extends the standard jailbreak build with a comprehensive anti-VM-detection strategy. Orchestrated by the KernelEXPPatcher class and the cfw_install_exp.sh installation script, these modifications hide the fact that the iOS guest is running inside a virtual machine while preserving critical system functionality for graphics acceleration and sandbox enforcement.

Overview of the EXP Variant Architecture

Unlike the standard jailbreak (JB) build, the EXP variant applies modifications across both kernel and user-space boundaries. The KernelEXPPatcher.swift orchestration class manages kernel-level patches, while cfw_install_exp.sh handles post-restore identity rewriting and daemon patching. Together, these components ensure that internal iOS services and external detection mechanisms receive consistent "non-VM" signals.

Kernel-Space Anti-VM Techniques

The foundation of the EXP variant's anti-VM-detection strategy rests on manipulating how the kernel advertises and queries virtualization status.

Sysctl OID Rename (kern.hv_vmm_present)

The primary mechanism occurs in KernelEXPPatchHvVmmRename.swift, where the KernelEXPPatcher.patchHvVmmRename method renames the critical kern.hv_vmm_present sysctl to kern.Xv_vmm_present.

When unprivileged processes call sysctlbyname("kern.hv_vmm_present"), the system returns ENOENT (entry not found), effectively hiding VM presence from standard detection scripts. However, the renamed sysctl remains accessible at the new OID, still returning the original value (1) for internal components that require it.

Internal Caller Mangling

Beyond the OID rename, the same patch implements byte-level string rewriting for every hard-coded reference to "kern.hv_vmm_present" inside the kernel binary. As detailed in KernelEXPPatchHvVmmRename.swift, the patch alters each occurrence by changing the first character: 'h' → 'X'.

This forces internal kernel components—including AMFI, the crypto accelerator, sandbox profiles, and APFS—to query the renamed OID automatically. External checks see a missing sysctl, while internal functionality expecting VM-aware behavior continues operating correctly.

User-Space and Daemon Patching

The EXP variant extends anti-VM camouflage into user-space to prevent consistency errors that could leak virtualization state.

Watchdogd Cache Patch

Located in cfw_install_exp.sh at step [EXP-JB-3.5] (lines 508-511), this patch targets the watchdogd daemon. A two-instruction rewrite modifies the daemon's cached hv_vmm_present value, ensuring it remains synchronized with the renamed sysctl. Without this patch, watchdogd might cache the original sysctl value, causing mismatches that reveal the VM environment to system integrity checks.

Dynamic Shared Cache Mangling

The Python script cfw_patch_hv_vmm_dsc.py mirrors the kernel's rename operation across the user-space Dynamic Shared Cache (DSC). Every DSC binary (except whitelisted system libraries) undergoes c-string rewriting to reference kern.Xv_vmm_present instead of the original OID.

This creates a selective visibility model: most applications receive non-VM responses, while a small blacklist of graphics and acceleration paths continue querying the original sysctl to enable hardware-specific optimizations. This approach provides false-negative VM detection for security tools while maintaining performance-critical code paths.

Hardware Identity Spoofing

After restoring from snapshots, the EXP variant rewrites hardware-identifying metadata to simulate physical iPhone characteristics.

DeviceTree Post-Restore Rewrite

Step [EXP-JB-6] in cfw_install_exp.sh (lines 722-749) executes immediately after VM restoration. The script rewrites devicetree.img4 to inject "device-like" properties, including camera nodes and physical product identifiers. These modifications make the virtual machine appear as genuine hardware to iOS kernel routines that inspect the DeviceTree structure during boot and runtime.

SystemVersion Build Spoofing

At step [EXP-JB-7] (lines 793-811), the installation script checks for the SPOOF_BUILD environment variable. When present, it replaces the ProductBuildVersion key in SystemVersion.plist with a user-specified build ID. This prevents services from detecting generic VM image builds that typically expose virtualized environments in enterprise or testing scenarios.

Implementation Workflow

To build and deploy the EXP variant with its anti-VM-detection capabilities:


# Enable the experimental pipeline and apply patches

make setup_machine EXP=1
make fw_patch_exp
make cfw_install_exp

Programmatically enabling EXP mode in Swift:

// Configure VM options for anti-VM detection
let options = VPhoneVirtualMachine.Options(
    variant: .exp,  // Triggers KernelEXPPatcher
    enableFrida: false
)

Manually applying the sysctl rename via Python:

from patchers.cfw_patch_hv_vmm_dsc import rename_hv_vmm_sysctl

# Apply DSC-level patches

rename_hv_vmm_sysctl('/path/to/kernelcache')

Summary

  • Sysctl renaming in KernelEXPPatchHvVmmRename.swift hides kern.hv_vmm_present from external queries while preserving it internally as kern.Xv_vmm_present.
  • Kernel string mangling redirects internal components to the renamed OID, ensuring AMFI, sandbox, and APFS functionality remains intact.
  • Watchdogd patching maintains cache consistency to prevent daemon-level VM detection leaks.
  • DSC mangling extends the sysctl rename to user-space libraries, creating selective visibility for apps versus graphics accelerators.
  • DeviceTree rewriting post-restore injects physical device properties to mask VM hardware signatures.
  • Build version spoofing via SPOOF_BUILD environment variable eliminates generic VM image identifiers from SystemVersion.plist.

Frequently Asked Questions

How does the EXP variant prevent apps from detecting virtualization?

The EXP variant renames the kern.hv_vmm_present sysctl to kern.Xv_vmm_present in both kernel and user-space DSC binaries. Standard detection calls return ENOENT, indicating the sysctl does not exist, while internal system components query the renamed OID to maintain expected behavior.

What is the purpose of mangling kernel-internal string references?

Kernel-internal caller mangling ensures that hard-coded queries for "kern.hv_vmm_present" inside AMFI, the crypto accelerator, and sandbox profiles automatically target the renamed kern.Xv_vmm_present without requiring source code changes. This preserves system functionality while preventing external detection.

Can the EXP variant spoof specific iPhone hardware models?

Yes. During step [EXP-JB-6] in cfw_install_exp.sh, the script rewrites devicetree.img4 to include physical device properties such as camera nodes and product identifiers. Additionally, setting the SPOOF_BUILD environment variable allows customization of the ProductBuildVersion in SystemVersion.plist to match specific hardware builds.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →