← Back to CoderGeek

Research Notes

Field write-ups from authorized Android reverse-engineering engagements — native hardening, dynamic analysis, protocol reversing, and device-level virtualization. All work is for authorized research, CTF, and apps I own or am contracted to test.

Native Hardening / Deprotection

VMP on Android Native Libraries: Internals, Tooling, and a Devirtualization Lab

How virtual-machine protection compiles critical code into custom bytecode, the 2026 devirtualization toolchain, and a hands-on lab: build a tiny VM, then write a lifter to tear it back down.

VMPDevirtualizationNative RE
Read →

Reversing Promon SHIELD: From Emulator Detection to an Xposed Data-Only Patch ↗

Full-chain RASP / app-shielding counter-engineering — from emulator and root detection through to a data-only Xposed patch that leaves the app untouched.

RASPPromon SHIELDXposed
Read →
Dynamic Analysis

Reversing VMP + OLLVM with a Frida Boundary-Hook Harness

Don't read obfuscated native code — watch its exits. A three-layer (libc / JNI / Java) Frida hooking methodology with a worked log walkthrough reconstructing an environment-check routine.

FridaOLLVMAnti-Obfuscation
Read →
Protocol Reverse Engineering

Reversing the UPI Wallet Protocol: From OTP Login to Transaction History

A common interface model across India's mainstream UPI wallets (Amazon Pay, PhonePe, Paytm, etc.) — from OTP login flow through transaction-history retrieval.

UPIProtocol REFintech
Read →
Virtualization Environment

Why Account-Matrix & Cloud-Phone Operators Need a Device-Level Android VM

From platform device fingerprints and risk control, reverse-deriving what a compliant Android virtual machine must provide: custom kernel, Framework-layer fingerprint control, per-instance isolation, sensor and network consistency.

VirtualizationCloud PhoneAnti-Detect
Read →

Have a hardened target to analyze?

Authorized VMP / OLLVM / RASP analysis, protocol reversing, and bypass engineering. Quote within 24 hours.

Get a Quote