Threat Research & Intelligence

Investigating the development, distribution, and capabilities of commercial mobile surveillance platforms.

Active Investigation Areas

Active Research

Android spyware detection without root access

Developing non-intrusive heuristic models and file-system diffing engines to isolate spyware payloads without requiring superuser escalation.

Ongoing

Multi-layer obfuscation unpacking in DEX and native binaries

Automating control-flow flattening recovery and decoding dynamic native libraries utilized by next-gen mercenary implants.

Active Research

Persistent surveillance mechanisms and C2 infrastructure mapping

Tracking command-and-control server networks through domain analysis, TLS certificate scanning, and telemetry correlation.

Published

Spyware family attribution and variant tracking

Documenting emerging variations in known malware families (e.g. Pegasus, Predator, Xenomorph) to support global response readiness.

Published Findings

Threat Hunting: Windows vs. Android (Or, Why You Can’t Just "Look at the Kernel")

Notes from the trenches of trying and (mostly) failing to hunt for threats on Android devices

Read Full Report →

The AndroidManifest.xml Problem Nobody Warns You About

Parsing the most important file in an APK without breaking your pipeline (From the trenches of building an automated Android malware detection pipeline)

Read Full Report →