# SocialBox-Termux: A Brute-Force Framework for Android Security Testing

> SocialBox-Termux is a shell-based brute-force attack framework adapted for Termux on Android, targeting Facebook, Gmail, Instagram, and Twitter. It installs via a setup script and runs on Android without a root requirement, but it carries real legal risk when used against accounts that are not your own.

**samsesh/SocialBox-Termux** — SocialBox is a Bruteforce Attack Framework [ Facebook , Gmail , Instagram ,Twitter ] , Coded By Belahsan Ouerghi Edit By samsesh for termux on android

- Repository: https://github.com/samsesh/SocialBox-Termux
- Stars: 4,552 · Forks: 519
- Language: Shell
- License: MIT
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/samsesh-socialbox-termux

## What SocialBox-Termux Is and Who It Is For

SocialBox-Termux is an adaptation of the SocialBox brute-force framework, edited by samsesh specifically for Termux on Android. The original SocialBox was coded by Belahsan Ouerghi and targets four social platforms: Facebook, Gmail, Instagram, and Twitter. The Termux variant packages that same functionality for Android's Termux environment, which provides a Linux-like shell on Android without requiring root access.

The repository description frames it plainly as a bruteforce attack framework for those four platforms. The README does not describe it as anything other than what it is. It is a tool for security researchers, penetration testers, and developers who need to test the password policies or brute-force resistance of their own accounts or systems they are authorized to test.

Using this tool against accounts you do not own or have explicit permission to test is illegal under computer fraud laws in most jurisdictions, and the MIT license covers only redistribution rights. The license does not grant permission to attack third-party services.

The intended platform is Termux running on Android. The README documents testing only on that combination. There is a separate SocialBox repository (github.com/samsesh/SocialBox) for those who want to run the framework on other operating systems.

## How the Framework Operates on Termux

SocialBox-Termux is a collection of shell scripts. The main entry point is SocialBox.sh, which coordinates the attack. The repository top-level directory includes instainsane/ and tweetshell/ subdirectories, which are the platform-specific modules for Instagram and Twitter respectively. A .whitesource file at the root indicates the project has been scanned by a software composition analysis tool.

The framework operates by sending repeated authentication requests to the target platforms using a wordlist or generated password variations. Each platform module handles the specific authentication flow for that service. Social media platforms implement rate limiting, account lockout, and CAPTCHA systems that work against brute-force attempts, which is why the README documents running the tool with Tor connected for anonymity.

The README notes that Tor should be connected when using a VPN. This reduces the risk of the originating IP being blocked after a small number of failed attempts. Without Tor, a large number of rapid authentication failures will typically trigger the target platform's rate limiting and lock the tool out before a successful guess occurs.

The install-sb.sh script handles the dependency setup: installing the required Termux packages and configuring the modules before the first run.

## Installing SocialBox-Termux on Android

Installation requires Termux on Android and an internet connection. Open Termux and run the following commands to install Git, clone the repository, make the installer executable, and run it:

```bash
apt-get update
apt-get install git
git clone https://github.com/samsesh/SocialBox-Termux.git
cd SocialBox-Termux
chmod +x install-sb.sh
./install-sb.sh
```

The install-sb.sh script runs the dependency installation. After it completes, launch the framework with:

```bash
./SocialBox.sh
```

The framework presents a menu for selecting which platform to target. Before running, the README recommends connecting Tor to mask the originating IP. The tool has no configuration file documented in the README; all setup happens through the installer and the runtime menu.

## Limitations and Legal Risks

The most significant limitation is not technical but legal. Unauthorized access to computer systems is a criminal offense in most countries, and brute-forcing a social media account you do not own falls squarely into that category. The Computer Fraud and Abuse Act in the United States, the Computer Misuse Act in the United Kingdom, and equivalent laws elsewhere treat unauthorized authentication attempts as criminal activity regardless of whether the attempt succeeds.

On the technical side, modern social media platforms have invested heavily in brute-force defenses. Facebook, Gmail, Instagram, and Twitter all implement account lockout after a small number of failed attempts, rate-limit login requests per IP address, require CAPTCHA completion after suspicious activity, and use device fingerprinting to flag new authentication sources. These defenses mean that a brute-force approach against a real account with a non-trivial password is extremely unlikely to succeed even under the best conditions.

The repository has no documented update mechanism for the platform modules. Social media authentication endpoints change over time, and a module that worked against an older API version may fail against a current one without updates to the relevant shell scripts.

The README does not document Windows or macOS support. Use on those systems requires the separate SocialBox repository.

## How SocialBox-Termux Compares to Hydra

Hydra (THC-Hydra) is a general-purpose network login cracker that runs on Linux, macOS, and Windows. It supports a wide range of protocols: SSH, FTP, HTTP form authentication, SMTP, SMB, and many others. Hydra is designed as a command-line tool with a specific syntax for specifying target, port, service, and wordlist.

SocialBox-Termux is narrower and more focused. It targets only four specific social media platforms and is designed for Android Termux specifically. Its shell-based design requires no compilation step and presents a menu-driven interface, which reduces the command-line knowledge required to operate it compared to Hydra.

The trade-off is generality versus simplicity. Hydra can test any network service that accepts a username and password; SocialBox-Termux tests only social platforms. A security researcher who needs to test SSH logins or FTP authentication will need Hydra or a similar general-purpose tool. A researcher specifically testing social media password policies on an Android device will find SocialBox-Termux more immediately operational.

## Authorship, License, and Repository Status

The framework has a multi-author history documented in the README. The original Facebook, Gmail, Instagram, and Twitter modules were written by different contributors: Imad and @fikrado for Facebook, Ha3MrX for Gmail, thelinuxchoice for both Instagram and Twitter. samsesh assembled them into the SocialBox project and created the SocialBox-Termux adaptation for Android.

The project is released under the MIT license, which permits distribution, modification, and use with no restriction beyond preserving the license notice. The MIT license says nothing about the legality of the activities the tool performs.

The last push to the repository was on 2026-06-19. The repository has no GitHub releases; the current state of the master branch represents the latest version. The contact links in the README point to the maintainer's YouTube and social media accounts for support questions.

## Conclusion

SocialBox-Termux is a narrow tool built for one specific job: running automated password guessing against social media accounts from an Android device running Termux. Security researchers and platform testers who own the accounts under test and understand how to route traffic through Tor have a clear use case. Using it against accounts you do not own is illegal in most jurisdictions regardless of the MIT license, which covers only redistribution rights, not permission to attack third-party systems. Verify that your Termux environment is on a recent Android version before installing, since the README documents testing only on Termux for Android with Tor connected.

## FAQ

### What is SocialBox and what does it do?

SocialBox is a brute-force attack framework that sends repeated password guesses against social media accounts on Facebook, Gmail, Instagram, and Twitter. SocialBox-Termux is the variant adapted for Termux on Android.

### How do I install SocialBox-Termux on Android?

Open Termux, run apt-get update and apt-get install git, then clone the repository with git clone. Make install-sb.sh executable with chmod +x and run it. After the installer finishes, launch the framework with ./SocialBox.sh.

### What is the difference between SocialBox-Termux and SocialBox?

SocialBox-Termux is adapted specifically for Termux on Android. The SocialBox repository (github.com/samsesh/SocialBox) is the version for other operating systems. Both target the same four social platforms but are packaged for different environments.

## Sources

- [Issues](https://github.com/samsesh/SocialBox-Termux/issues)
- [License: MIT](https://github.com/samsesh/SocialBox-Termux/blob/master/LICENSE)
- [README](https://github.com/samsesh/SocialBox-Termux/blob/master/README.md)
- [samsesh/SocialBox-Termux on GitHub](https://github.com/samsesh/SocialBox-Termux)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/samsesh-socialbox-termux
