Separate the shell from the application
360 Jiagu advertises protection against code injection, debuggers, game cheats, hijacking and data changes. In a protected package, the manifest application entry and visible DEX may belong to the shell. Useful code can be encrypted or stored in a form loaded after startup.
The analysis starts with package structure: application class, DEX size, unfamiliar assets, native libraries and supported ABIs. Runtime evidence then shows when the original classes become available and which loader owns them.
Follow execution after loading
Once the app code is present, we return to normal Android analysis. We trace the target UI action into authentication, request creation and response parsing. Integrity and environment checks remain relevant only where they affect that path.
- Record native libraries loaded during application startup.
- Watch class loaders and executable memory mappings.
- Identify the first original Android component that runs.
- Capture requests after all app and shell code has changed them.
Build from the server API specification
The final client uses the endpoint, headers, body, session and signing rules recovered from the running app. Packed code is an analysis obstacle, not a deliverable. The useful result is a stable function your system can call without repeating the loader work on every request.
Reviewed 30 August 2026 · SReverse research desk