Android

Android security was one of Cyfinoid’s earlier core research areas. This page remains live as an archive of that work because it led to useful tools, internship projects, training material, and practical lessons that still matter to mobile security practitioners.

Android is no longer one of our primary active research pillars. Our current active focus areas are Software Supply Chain Security, Cloud Security, and AI usage and security. Even so, the Android work remains part of our history and continues to reflect the research-driven approach that shaped the company.

Archived Research Focus

Our Android work looked at security as a full ecosystem problem rather than a narrow reverse-engineering exercise. That included application analysis, device and network considerations, development practices, and the kinds of workflows security engineers use when they need to assess real mobile apps under time pressure.

We were especially interested in making Android security analysis more practical, repeatable, and accessible through hands-on labs, vulnerable targets, and tooling that could help bridge the gap between deep analysis and everyday assessment workflows.

Community Contributions

  • APK Analysis Automation
    APK Analysis Automation
    Android, Intern-project
  • CFYVuln-Android
    CFYVuln-Android
    Android, Intern-project

What This Work Covered

  • Static and dynamic analysis of Android applications
  • Root detection bypass and instrumentation-driven testing
  • Traffic interception and application behavior analysis
  • Hybrid mobile application assessment, including React Native and Flutter
  • Threat modeling and practical defensive improvements for Android applications

Why Keep This Page Live

  • It documents an important earlier phase of Cyfinoid’s research
  • It helps previous students, collaborators, and readers find older work
  • It preserves projects and ideas that still have practical value

If you are looking for our current active research priorities, start with Software Supply Chain Security, Cloud Security, and AI usage and security.

Previous Training Sessions

Attack & Defend Android Applications c0c0n 2024

13 November 202414 November 2024
Gandhinagar, Gujrat
WS-Anant-2

Attack & Defend Android Applications BlackHat USA 2024

5 August 20246 August 2024
Virtual
bh-usa-24-android-56

Attack & Defend Android Applications BlackHat USA 2024

3 August 20244 August 2024
Virtual
bh-usa-24-android

Attack & Defend Android Applications BlackHat USA 2023

5 August 20236 August 2023
Las Vegas, USA
220706_BHUSA23_Web_Ads_Trainer_400x400-editing-1

Attack & Defend Android Applications BlackHat USA 2022

8 August 20229 August 2022
Las Vegas, USA
ad1

Attack & Defend Android Applications BlackHat USA 2022

6 August 20227 August 2022
Las Vegas, USA
ad1

Note:
Android is a trademark of Google Inc

Scroll to Top