Full-depth reverse engineering and adversarial security assessment of a single Android application or website — packers, obfuscation, native code, anti-tamper, and backend API surface taken apart and tested, not scanned.
Request a Scoping CallWe take a single Android application or website apart at every layer: static decompilation and taint analysis, unpacking and deobfuscation of hardened builds, native .so and JNI reverse engineering, runtime instrumentation with Frida against production builds, anti-tamper and root/emulator-detection bypass validation, proprietary protocol and cryptographic scheme reconstruction, and full backend API authentication, authorization and business-logic testing. Coverage maps to OWASP MASVS L1 and L2 and the MASTG.
Automated mobile scanners stop at the manifest and unobfuscated Java. Real risk lives below that line: in packed DEX, native libraries, custom cryptography, and anti-analysis defenses built specifically to defeat tooling. Every automated finding is reviewed by a researcher and no unvalidated tool output ships in the report. This depth is what separates a $50,000–$800,000 engagement from a checklist scan.
Our methodology is verifiable in public, not asserted behind NDAs. Published work includes a complete mathematical reverse engineering of Arxan/Digital.ai string encryption (72.7% decryption rate), a cryptographic analysis of the Alipay APK signing chain (15 proof-of-concept attacks; 28 RSA keys recovered via Batch GCD), a Frida-based TLS pinning bypass on a production banking application, and memory-forensics recovery of decrypted code from packed, anti-detection apps. These were independent analyses — not client engagements.
Engagements are priced per single APK or website from $50,000 to $800,000 USD, delivered in 5–10 business days. Placement in the range is driven by hardening (packing, obfuscation, native code), backend API surface, and the depth of adversarial testing required. Scope and fixed fee are confirmed in writing before work begins; billing is 50% on signing and 50% within 30 days of report delivery.
From $50,000 to $800,000 USD per single target. The final fixed fee is set after scoping, driven by hardening, backend API surface, and required testing depth, and confirmed in writing before work begins.
5–10 business days per target. The exact delivery date is confirmed before work begins.
Yes. Unpacking, deobfuscation, native .so and JNI analysis, and anti-tamper / root / emulator-detection bypass validation are core to the engagement — see our published Arxan/Digital.ai and packed-app memory-forensics research.
No. Reverse engineering works from the shipped binary or the live website. Source access, if available, is used to deepen coverage but is not required.
Assessing an application or website you own or are authorized to test is standard security practice. A mutual NDA is executed before we receive any binary, and engagements are contracted under a written statement of work covering scope and authorization.
View all audit services — APK, Web3, IoT, automotive
Singapore-based. Fixed fee, 5–10 business day delivery. AI-assisted pipeline with human expert review.