ShizuStore

AvarionX

phsycologicalFudge

4.1.5 · GitHub

Download APK
Privacy Android 7.0+ 13 hours ago MPL-2.0
275 ShizuStore
4.8k GitHub
64 Stars
35 MB Size

More about this app

On-device antivirus with local malware/APK scanning, download monitoring and DNS filtering; Shizuku powers ransomware-style behaviour monitoring

AvarionX Security logo

AvarionX Security

Android malware protection without ads, tracking, or locked core features.

AvarionX combines local malware scanning, optional hash-based cloud intelligence, download monitoring, DNS filtering, APK analysis, and Guardian Mode for ransomware-style behaviour detection.

Release Downloads License VX-TITANIUM

Buy me a coffee

What is AvarionX?

AvarionX Security is an Android antivirus built around user privacy.

It can scan files and APKs directly on your device, monitor new downloads, check known malicious domains, and use optional cloud intelligence for hash lookups. The app does not use ads, analytics, or paid protection tiers.

Cloud checks are optional. When enabled, AvarionX sends file hashes for lookup, not the file contents.

Protection layers

Layer What it does
VX-TITANIUM Local malware scanning engine for files and APKs.
VTTI Cloud Also known as Titanium Cloud. A proprietary cloud Intelligence Platform, including hash checking for AvarionX, and sample analysis for full files
Real-Time Protection Monitors new downloads and recently added files.
Guardian Mode Watches for ransomware-style file behaviour.
APK analysis Checks installed or selected APKs for suspicious indicators. and creates a detailed report

The Engine's Architecture

AvarionX Antivirus (CS Security) operates through a multi-layered detection pipeline powered by VX-Titanium.

  1. Cloud Hash Layer: A fast check on an extremely large historical and current corpus of over 200 million unique malware hashes
  2. Hash Layer: Comparing both SHA256 and MD5 fingerprints against known malware lists
  3. Signature Layer: Custom byte signitures checked against apk containers, dex and native libraries.
  4. Heuristic Layer: Machine learning based behaviour analysis for APKs

Machine Learning (ML+)

AvarionX Security includes a dual ML system named ML+

  • Legacy MUniverse Tag: Suspicious applications that meet the scoring system's requirements are dubbed with a MUniverse (Malware Universe) tag in app versions 4.0.8x and below
  • Current versions use an upgraded heuristics model, with the tag: Andr/VXgen2

Guardian Mode

By utilizing shizuku, Guardian Mode can monitor app behaviour that android would normally keep out of reach. When an app starts changing files, AvarionX monitors it, assessing the likelihood on destructive behaviour. Guardian Mode is currently focused on ransomware-style behaviour. More behaviour categories will be added in future updates.

Screenshots

AvarionX protection menu
Home screen
AvarionX home screen
Features list
AvarionX Cleaner Pro
Scanning mode
AvarionX Smart Scan
APK Analyser
AvarionX Cleaner Pro
Scanning mode
AvarionX Smart Scan
APK Analyser
AvarionX dark mode
Settings Screen

Privacy model

AvarionX is designed to avoid unnecessary data collection.

  • No advertisements
  • No tracking or analytics
  • No HTTPS traffic decryption
  • No content inspection
  • No file uploads for cloud checks (unless 'Share Malicious APKs' is turned on)
  • Hash-only cloud lookups when VTTI is enabled
  • Local scanning works offline

Guardian Mode Demo

Watch demo video

Close

How Shizuku is used

Can monitor ransomware behavior, manage apps and run terminal Linux via Shizuku with `pm`, `am` and `/proc` reads

This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.

How this app uses Shizuku

Shizuku powers background threat monitoring plus cleaner and terminal features.

  • Detect ransomware behavior: background monitoring polls running processes, per process I/O and CPU use, file creates, modifies and deletes in shared storage, and open files holding storage paths, then scores them for encryption like activity and automatically stops the offending app with a threat notification.
  • Check device context: the monitor reads lock screen state with dumpsys window and device admin apps with dumpsys device_policy to factor into its threat scoring.
  • Uninstall apps: a package chosen in the app manager is removed silently with the pm uninstall --user 0 shell command through Shizuku.
  • Force stop threats and apps: a package chosen in the app manager, or a process flagged as a threat by the monitor, is stopped with the am force-stop shell command through Shizuku (with kill -9 as the monitor fallback).
  • Clear app data and caches: a package chosen in the app manager is wiped with pm clear, and all app caches can be trimmed at once with pm trim-caches 999G through Shizuku.
  • Set up terminal Linux: the Alpine environment for the in app terminal is extracted to shared temporary storage with shell privilege, creating symlinks and fixing permissions through Shizuku, and new terminal sessions run as shell through Shizuku.

Android APIs or commands used

  • ps -A -o PID,UID,NAME
  • /proc/[pid]/io
  • /proc/[pid]/stat
  • /proc/[pid]/status
  • /proc/[pid]/fd
  • pm uninstall --user 0
  • pm clear
  • pm trim-caches 999G
  • am force-stop
  • kill -9
  • dumpsys window
  • dumpsys device_policy
  • ln -sf
  • chmod -R 777

Notable details

Without Shizuku, batch uninstall falls back to the normal system uninstall flow where each app needs separate confirmation, and the terminal Alpine setup can still install locally without elevated privilege. The unknown sources entry only opens the system settings screen and performs no privileged action.

Close

Changelog

What's new for version 4.1.5

AvarionX Antivirus v4.1.5

  • Ported part of AvarionX VPN. Now, you can connect to a VPN node within the Antivirus suite.
  • Fixed the infinite cancellation bug from scanning.
  • Backend changes to the engine including database size, now shrunk from 9mb to 1mb (ish)

Discord

Close

Permissions

19 permissions requested

  • android.permission.READ_EXTERNAL_STORAGE
  • android.permission.WRITE_EXTERNAL_STORAGE
  • android.permission.MANAGE_EXTERNAL_STORAGE
  • android.permission.FOREGROUND_SERVICE
  • android.permission.PACKAGE_USAGE_STATS
  • android.permission.QUERY_ALL_PACKAGES
  • android.permission.POST_NOTIFICATIONS
  • android.permission.INTERNET
  • android.permission.ACCESS_NETWORK_STATE
  • com.android.vending.BILLING
  • android.permission.RECEIVE_BOOT_COMPLETED
  • android.permission.FOREGROUND_SERVICE_SPECIAL_USE
  • moe.shizuku.manager.permission.API_V23
  • android.permission.REQUEST_DELETE_PACKAGES
  • android.permission.READ_MEDIA_IMAGES
  • android.permission.READ_MEDIA_VIDEO
  • android.permission.READ_MEDIA_AUDIO
  • android.permission.WAKE_LOCK
  • com.colourswift.cssecurity.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Close

Sources

2 sources

4.1.5 arm64-v8a GitHub · com.colourswift.cssecurity
Selected Download
4.1.4 armeabi-v7a GitHub · com.colourswift.cssecurity
Download