SReverseby Simpa Labs

Android reverse engineering · Integrity and anti-tamper

Anti-tamper that fails safe, or fails quietly.

A tamper check compares a file against a value the author recorded, then decides what to do when they do not match. The choice is what matters. Some checks stop the app. Some let it run and break a single feature later, so nothing obvious happens at first.

Signature Dex hashes Native hashes Resource hashes Soft brick
check.kt · the branch
// the app reads its own signing certificate
val sig = pkgInfo.signatures.first().toByteArray()
val mine = app.expectedSignature()

// the constant-time compare. Either it throws, or it does not.
if (!MessageDigest.isEqual(sig, mine)) {
  throw SecurityException("tampered")   // fails safe, or
  return null                          // fails quietly, later
}

Fig. 01 · the whole protection is one decision, and it is easy to find

Two ways to fail

Loud, or quiet. The difference changes your approach.

Fail loudly (fails safe)

  1. Open a modified build
  2. Check runs against the file
  3. Mismatch found
  4. App refuses to continue
  5. An error appears, nothing runs

Fail quietly (soft brick)

app opens normally
check fails, result ignored
one feature breaks hours later
the failing call is hidden

Fig. 02 · the quiet one is the hard one to see

A loud check is easy to notice and easy to locate. A quiet check can pass your first test because nothing appears broken, then a server call goes wrong in a build that looks identical to the release. The reliable way to find it is to compare the network output of a modified build against a known-good baseline.

The checks

Where the comparisons live, and how you read them.

APK signature verification

The app reads its signing certificate through PackageInfo.signatures and compares bytes. Search for a comparison against a stored digest after a call to getPackageInfo. The workaround is to read the value the app computed and reuse it, not to change the file that produced it.

Self-integrity over dex

The app hashes its own classes.dex and compares the result with a constant. Search for a MessageDigest that reads the app's own assets or its own file descriptor. The check runs on a copy, so you point it at the original dex instead of the modified one.

Native file hashes

The same pattern appears in .so files, often read from the native library's own code region. A scan loop over the module base, or a read of the file back off disk, ends in a compare. The workaround is to keep the bytes it reads unchanged while changing behavior elsewhere.

Resource hash checks

Assets, layouts and raw resources are hashed too, so a repackaged resource fails the check. The workaround is to patch the code that calls the affected resource rather than replace the resource, keeping the expected hash intact.

The route

Read what the app reads, then reuse it.

An integrity check is local. It decides whether the running image is the released one. The app still has to talk to its server, and in many apps the value the check verifies is the same value that goes into a request header or a signature.

We trace the integrity check to its inputs and callers, then compare an unmodified run with the failing run. That shows whether the check stops execution, changes a request value or reports a result to the server.

reproduce.py · the value in flight
import sreverse

sig = sreverse.read_signature(apk)   # the app's own certificate digest
cl  = sreverse.client(cert=sig)
token = cl.login(device_id, secret)   # same flow, outside the UI

Fig. 03 · a signature is often also a request parameter

Start a project

Something breaks only in the modified build.

Send the full APK. We locate every relevant check and return a fixed quote for the complete API reconstruction.

Projects start at $120. Most are delivered in 24 to 72 hours.

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?