Security Research
Blog
Deep dives into Android app hardening, RASP, code obfuscation, and mobile security engineering.
Mobile Threat Landscape 2026: What Actually Breaks Android Apps
Repackaging, hooking frameworks, Magisk, and AI-assisted reverse engineering — a realistic ranking of what you are defending against.
Resource Obfuscation with AndResGuard: What It Really Buys You
Renaming res/ paths is the cheapest hardening layer there is — and the one most likely to break your build if you skip the whitelist.
Protecting Native Libraries: SO Packing and Anti-Dump
Why the .so layer is both your strongest hiding place and your most fragile dependency, and how to harden it without breaking ABIs.
Anti-Tampering and the Integrity Chain
Signature self-checks, file checksums and component verification — how to detect a repackaged build before it does damage.
APK Signing Schemes V1–V4 and Why Hardening Breaks Them
What each signing scheme actually protects, how Janus-style attacks worked, and why a hardened APK must always be re-signed last.
Obfuscapk Deep Dive: Control-Flow Obfuscation
Understanding BlackObfuscator's control-flow flattening and how it protects critical application logic.
dpt-shell: Function Extraction Explained
How dpt-shell extracts DEX functions into encrypted shell code, making reverse engineering dramatically harder.
Why RASP Matters for Mobile Apps
Runtime Application Self-Protection detects and blocks attacks in real-time, beyond static obfuscation.
The 5-Layer Hardening Pipeline
Deep dive into VALLUM's 5-stage pipeline: resource shrinking, control-flow obfuscation, function extraction, RASP, and signing.
What Is Android App Hardening?
A comprehensive guide to protecting Android applications through multi-layer defense strategies.