SReverseby Simpa Labs

Android reverse engineering · Static obfuscation

Reading code that was built to be unreadable.

Static obfuscation changes how a file looks, not what it has to do. The app has to implement real behavior, and obfuscation only hides the labels. The structure that remains is what an analysis reads, and it is a lot more than it seems.

R8 / ProGuard Control-flow String encryption VM protection
jadx view · a string is not a string
// the text is stored as numbers and decoded on first use
public static String a() {
  return new String(b.a(
      new byte[]{ 10, 22, 45, 7, 33, 61, 19, 90 }));
}

// de-obfuscated: call the decode, read the real constant
//   "/api/v1/orders"

Fig. 01 · the decode routine is the key to every string it produces

Technique to analysis

Each obfuscation maps to one repeatable move.

R8 / ProGuard name mangling and shrinking

Classes and methods become single letters, and unused code is deleted. The mapping is cross-references: find where a method is called, then follow the xref to the caller. Shrinking can also delete the entry you expected, so the entry point is found by tracing from the manifest, not by name.

Control-flow flattening

Blocks are put behind a state machine and true order is lost in source. The mapping is dynamic tracing. Run the app, watch which branch executes, and rebuild the real order from the paths that actually run.

Opaque predicates

A condition that is always true or always false is inserted to confuse the reader. The mapping is constant evaluation. Prove the branch is dead, then ignore it, and the path collapses to a straight line.

String encryption

Constants become ciphertext plus one shared decode routine. The mapping is to find that routine and force it to run. Hook it once and every constant it produces arrives in plain text.

Class encryption

Whole classes are stored encrypted and loaded at runtime. The mapping is a memory dump. Let the app load the class, then read it back from the process, and decompile the decrypted form it had to create to run.

Arithmetic obfuscation

Simple math is rewritten as a series of operations that look meaningless. The mapping is to solve the expression. Fold the constants, simplify the algebra, and the result is one integer instead of forty.

Code virtualization (VM-based protection)

The bytecode is replaced by an interpreter over custom opcodes. The mapping is the hardest one. You read the interpreter, trace the opcodes it runs, and reconstruct the original behavior from the instruction stream.

A worked example

Follow a hidden endpoint out of a flattened method.

A request path is the useful clue, because it is a string the code has to recover to build the request. Find the decode routine, force it to run, and read where the recovered path is passed. That path names the endpoint, and the method that uses it names the flow.

trace.js · forcing the decode
const decode = findByStringRef("a");
const path = decode();                  // "/v2/account/orders"
const uses = usesOf(decode);           // the flattened caller
// run it, capture the branch, rebuild the path

Fig. 02 · one resolved constant collapses a whole method

From APK to API

Start a project

The names are gone. The behavior is not.

Send the full APK. We return a fixed quote for its complete callable API reconstruction.

Projects start at $120. Most are delivered in 24 to 72 hours.

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?