SReverseby Simpa Labs

Android protocol reconstruction · Custom binary

Android custom binary protocol reverse engineering

We turn the APK’s raw socket traffic into a named, tested API with message schemas, session state, encryption and every application workflow.

TCP and UDP do not describe the messages

TCP gives the app an ordered byte stream. It does not preserve application message boundaries. One message can arrive across several reads, and several messages can arrive in one read. UDP keeps datagram boundaries but leaves delivery, ordering and retries to the application. The APK must contain the rules that turn those bytes into useful messages.

We find the socket code and trace both sides of its buffer. Reads reveal how the app detects a complete frame. Writes reveal the exact header, payload and checksum sent for each action. Common boundaries include a fixed header, a length prefix, a delimiter or a type-specific fixed size.

Recover the wire format field by field

We compare many messages while changing one input at a time. Stable bytes point to magic values and protocol versions. Counters reveal sequence fields. Repeated lengths reveal nested records. Code inspection confirms byte order, signed values, strings, padding, checksums and optional sections.

  • Document connection setup, DNS, ports, TLS and certificate rules.
  • Recover frame boundaries, message types and field layouts.
  • Map request IDs, acknowledgements, retries and duplicate handling.
  • Trace compression, checksums, encryption and key changes.
  • Rebuild login, heartbeats, reconnects and every business message.

State is part of the protocol

Custom protocols often have a strict order: greeting, version check, key exchange, login, capability setup and normal commands. A correct message sent in the wrong state will fail. We model this as a clear client state machine and test startup with no saved session, reconnect, expired session and interrupted transfer paths.

When native JNI code builds the packet, we trace the input and output at that boundary and then port the algorithm. If the app uses a device key or server challenge, the delivered client creates the same current value instead of copying bytes from an old capture.

The full delivery

You receive a callable API for the full APK in Python and JavaScript/TypeScript, plus a Postman collection. The clients cover every recovered endpoint and workflow. They create fresh signatures, encrypt requests, decrypt responses, keep authentication and session state, and follow the same request order as the app.

Each client includes clear input models, parsed outputs, refresh behavior, uploads, downloads, streaming events and useful errors where the app uses them. We test the delivery against the live service so it runs without copied requests or old tokens.

Reviewed 30 August 2026 · SReverse research desk

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?