
Course 42 - Mobile Malware Analysis Fundamentals | Episode 14: Architecture and Essential Toolkits
About this episode
- Network Architecture: Building isolated networks that prevent malware from reaching corporate or personal systems while still allowing controlled observation of malicious network traffic.
- Hardware Requirements: Allocating sufficient CPU, RAM, and storage to support multiple virtual machines, analysis tools, memory captures, and large malware samples.
- Operating Systems: Selecting appropriate host and guest operating systems for the platforms being investigated.
- Physical Devices: Maintaining real iOS and Android devices when necessary, since certain behaviors cannot be accurately reproduced through virtualization alone.
- Snapshots and Gold Images: Creating clean baseline environments that can quickly be restored after malware execution.
- Documentation: Recording network configurations, hardware specifications, installed tools, and experimental changes to make investigations reproducible.
- Hopper for disassembly and reverse engineering.
- MobSF for automated mobile application security analysis.
- Additional utilities for inspecting application packages, binaries, metadata, and embedded resources.
- LLDB for debugging and inspecting running processes.
- Needle for iOS security assessment and runtime analysis.
- Cydia Impactor and AppSync for application installation and sideloading in appropriate research environments.
- Android Guard for examining and transforming Android applications.
- JEB for advanced reverse engineering and decompilation.
- MobSF for automated security analysis.
- Droser for interacting with Android application components at runtime.
- FSmon for monitoring filesystem activity.
- Volatility for memory-forensics investigations when memory artifacts are relevant.
- Burp Suite for intercepting and analyzing HTTP/HTTPS traffic.
- Wireshark for packet-level network analysis.
- Charles Proxy for monitoring and debugging application traffic.
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
Get every episode summarized
Each time CyberCode Academy publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
597 searchable segments. Every word is indexed and playable.
Full transcript
CyberCode Academy — Course 42 - Mobile Malware Analysis Fundamentals | Episode 14: Architecture and Essential Toolkits. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Shop vans and Albertsons for fresh savings every time you shop! This week at vans and Albertsons, get fresh boneless, skinless chicken breasts for 1.99 per pound limit 10 pounds, and locally grown grape-ary cotton candy grapes are 2.99 per pound with digital coupon. Plus, 24 packs of Canada Dry or 7-up 12-ounce cans are 4.99 limit 1 with digital coupon. Enjoy fresh and delicious savings for every meal! Hurry in! These deals won't last! Visit vans or Albertsons.com for more deals and ways to save! Kitchen and bathroom professionals know what goes behind the tile matters. That's why trade pros trust Fiber-Sement Party Backer Board to keep tile firmly in place, resist cracking, and help block moisture. Chosen in over 40 million kitchen and bathrooms. Party Backer Board. What the best build on? Shop now at participating Home Depot, Lowe's, and floor into core stores. For more information, visit jameshardy.com slashhardybacker.
Rubric is the security and AI operations company. Build for what happens after an attack hits. Not just the moments before. AI has turned the threat landscape into quicksand, moving too fast for any human to fully predict. That's why an agentic cyber resilience platform matters. Automated recovery, clean data, a business that keeps moving, no matter what hits. One platform, not a patchwork of stitched together tools and gaps. Wait for the next attack. Secure and accelerate your business at rubric.com. Again, rubric.com. Imagine for a second that you are a, well, a digital detective. Oh, I like that visual. Right. You're sitting in this dim room. The glow of the monitors is lighting up your face and on the desk right in front of you sits this single, highly suspicious mobile app. Just waiting to be opened. Exactly. I mean, maybe it looks like a harmless calculator utility or, you know, a fun little puzzle game. You just download on a whim. But you have a sinking feeling about it. Yeah. A really bad feeling. Like it's secretly scraping your contact data or tracking your GPS location or maybe
it's hiding malicious code that's just waiting for a command to strike. And I mean, you can't exactly just ask the app what it's doing. No, definitely. You have to completely dissect it yourself. Right. And to perform that kind of digital surgery, you need a highly specialized operating room. A secure lab. Exactly. Yeah. You need an environment where you can safely prod poke and just tear this thing apart without letting whatever malicious code is inside, you know, escape into your own network. Which is our exact mission for today's deep dive. We are building a mobile malware analysis lab from the ground up. Yeah. We're going to equip you with the exact software tool bag you need to pry open iOS and Android applications. We'll show you how to separate the harmless code from the real threats and understand exactly what is happening under the hood. And you know, building a truly secure lab means thinking about a lot of things. Your hardware like whether you use physical test phones or virtual emulators and of course your networking.
Right. Ensuring it's completely isolated so the malware cannot phone home or infect your personal devices. Exactly. But today our lens is focused entirely on the software side of the equation. We are mapping out the specific tools of the trade you need installed on your forensic workstation. But get started. I think we have to look at what is known as static analysis. And let's begin our investigation on the iOS side of things. That was good. I like to think of static analysis as looking at the architectural blueprints of a house without actually walking through the front door. That is a really great way to look at it. Yeah. You are mapping out the structure, finding out where the windows and doors are located. But you aren't like turning on the lights, running the water or stepping on any potential booby traps. The analogy holds up perfectly actually. You are analyzing the code at rest. Right. Before it actually does anything. Exactly. Before you ever execute a potentially dangerous piece of software, you absolutely must examine its static code to understand the landscape. But on iOS, I mean apps are compiled down into a machine readable format, right?
Yeah, they are. You can't just read the code like a book. So you need to pull the application apart and translate it back into something human readable. Precisely. You need a disassembler. Brings us to a bit of a dilemma for anyone building a lab. There are a few major disassemblers on the market, but IDA Pro is basically the industry heavyweight champ. Oh, absolutely. It's the name everyone here is first. But I look at the price tag for an IDA Pro license. And I mean, it feels like you need a corporate budget just to open the door. Yeah, it is a massive financial investment. It's usually reserved for large enterprise security teams or dedicated reverse engineering firms. Overkill for an independent researcher. Totally overkill if you're just setting up a lab. On the total opposite end of the spectrum though, you have Guidra. Oh, right. Guidra was actually developed by the NSA and released to the public for free, wasn't it? Yeah, completely free. Free sounds great, but I imagine there's a catch. The catch is definitely the user experience. I mean, Guidra is an absolute powerhouse, but in the grand scheme of reversing tools,
it's still finding its footing in the mobile space and the interface. It has a remarkably steep learning curve. If you are just starting out, it can feel like trying to fly a space shuttle before you've learned to drive a car. Oh, wow. Okay. So where is the sweet spot for our digital detective then? What do we actually put in our tool bag? The primary recommendation here is a tool called Hopper. It just hit that perfect middle ground. Hopper. Yeah, it's a highly affordable, deeply powerful, and crucially for analyzing Apple devices, you can get specific iOS scripts designed to work seamlessly with it. So Hopper actually understands the specific ways iOS applications are structured. Exactly. It's tailored for it. Oh, and I should mention binary ninja and radar are also solid alternatives out there. Good to know. Well, let's talk about that iOS structure for a second because there is a specific tool called class dump that seems entirely built around it. Oh, class dump is essential. But why do we need a dedicated tool just to dump classes? Well, it has to do with how Apple applications are historically built.
iOS apps are largely written in a language called Objective-C or increasingly Swift. Right. And Objective-C is an object oriented language, but unlike some languages that compile down a pure stripped machine code, it relies on something called runtime reflection. Run time reflection. What does that mean in practice? It means it actually keeps a map of its own structure, like the names of its classes, its methods, its variables embedded right inside the code. Oh, I see. So it literally brings its own blueprint with it. Precisely. And class dump simply reads that embedded map and generates a clean text file showing you all that underlying architecture. That sounds incredibly useful. It is. If you see a class named say user location tracker with a method called send to server, you immediately know where to focus your investigation. You don't have to guess. It is the absolute best tool for that specific job. Without a doubt. Okay. This is a tool mentioned here called JTool, which is framed as an upgrade to an older utility called OTool. But if OTool already analyzes object files, why do we care about an upgrade?
That entirely comes down to cognitive load. OTool is a classic foundational utility shore. But when you run it, it spits out an incredibly dense, unformatted wall of text. Just a total nightmare to read. Exactly. JTool is a modern port that cleans up that output. I mean, when you are staring at terminal screens for eight hours a day, trying to find a single anomalous line of code. Formatting and readability are not just nice to have. No, they are forensic necessities. You will miss things if the formatting is garbage. That makes total sense. And speaking of readability, iOS uses a very specific file format for its executables called Mako. Yup, Mako. It's the foundation of how Apple software runs. Right. So, as files, we have a tool called MakoView. I assume this does something similar to JTool, but with a graphical interface. That's the key. MakoView gives you a clean, visual, graphical user interface to explore those binaries. So no command line. Exactly. Instead of typing command line prompts to see different sections of the file, you can just
click through the headers, the load commands, and the binary structure, you know, just like navigating a regular file explorer. It makes orienting yourself inside a complex Mako file much more intuitive. Way more intuitive. Now, I want to bring up a tool that really surprised me. MobSF or the mobile security framework. Ah, yes. MobSF. Anyone who has dabbled in mobile analysis knows MobSF as the undisputed king of Android static analysis. It's an automated all-in-one framework. It is. But apparently, it's highly recommended for iOS now as well. Yeah, it catches a lot of people off guard because it was so deeply associated with Android for years. I always thought of it as just an Android tool. Most people do. Yeah. But the developers have built out fantastic parsing capabilities for iOS binaries now. Really? How does it work for iOS? You basically feed it an iOS app, and it will automatically extract the property list files, analyze the security flags on the binary, and give you a really solid, automated, initial assessment of the app security posture.
That's amazing. Just a quick automated overview before you dive in manually. Exactly. So much time. Wait, I have to stop us here. We're talking about disassembling code, mapping classes, and feeding binaries into framework. Yeah, we've got a whole toolkit going. But Apple tightly controls its ecosystem. If you download an app from the app store, it is protected by FairPlay DRM encryption. Ah, right. The encryption problem. The app is completely scrambled on the hard drive. If I pull an encrypted app off an iPhone and drop it into Hopper, isn't it just going to look like digital static? Yes. That is the fundamental roadblock of iOS analysis. If you look at the app file at rest, it is completely unreadable. Apple's DRM ensures that. So how can any of these static analysis tools possibly work? I mean, we don't have Apple's master decryption keys. We don't need the keys if we exploit how the operating system itself functions. Wait, what do you mean? Think about it. For the iPhone to actually run the app, the phone's processor has to be able to read the
code right. Right. The exact moment you tap the app icon and it launches, the iOS operating system decrypts the code and loads it into the phone's active memory or RAM. Oh, it has to unmask itself to run. Exactly. And that is where a brilliant tool called dump decrypted comes into play. How does that work? Well, you run the app on a customized jailbroken iPhone. When the operating system decrypts the app into memory, dump decrypted steps in, pauses everything and essentially scoops that clean, unencrypted code straight out of the RAM. Just grabs it right out of memory. Yep. And saves it to a new file on your machine. Now you have a clean binary that you can drop into hopper. That is a fascinating workaround. So all right, we've mapped the house with our static tools. Kitchen and bathroom professionals know what goes behind the tile matters. That's why Trade Pro's trust Fiber cement party backer board to keep tile firmly in place, resist cracking and help block moisture. Chosen in over 40 million kitchens and bathrooms, party backer board, what the best build on.
Shop now at participating Home Depot, Lowe's and floor into core stores. For more information, visit jameshardy.com slashhardybacker. Rubric is the security and AI operations company. Build for what happens after an attack hits. Not just the moments before. AI has turned the threat landscape into quicksand, moving too fast for any human to fully predict. That's why an agentic cyber resilience platform matters. Automated recovery, clean data, a business that keeps moving no matter what hits. One platform, not a patchwork of stitched together tools and gaps. Don't wait for the next attack. Secure and accelerate your business at rubric.com. Again, rubric.com. Kitchen and bathroom professionals know what goes behind the tile matters. That's why trade pros trust fiber cement, party backer board to keep tile firmly in place, resist cracking and help block moisture. Chosen in over 40 million kitchens and bathrooms, party backer board, what the best build on.
Shop now at participating Home Depot, Lowe's and floor into core stores. For more information, visit jameshardy.com slashhardybacker. We know the layout. We have the blueprints, but blueprints won't tell you if the pipes are going to burst when you turn on the water to catch malware in the act like to see what networks it tries to connect to or what files it modifies. We have to actually turn it on. Right. We're moving into dynamic analysis. Static analysis tells you what the code might do. Dynamic analysis tells you what the code actually does in real time. But to dynamically analyze an iOS app, you have to get it onto your test device first. Yeah. And you can't just use the app store. No, you have to side load it. App loading is essentially tricking the device into accepting an application that hasn't been officially blessed by Apple servers. Exactly. And for that, we need a specific set of tools, things like city, impactor, app sync, I device installer, or iOS deploy. Yeah, those tools handle the complex cryptographic signing requirements behind the scenes.
They allow you to push that modified or decrypted application back onto a physical test device so you can run it. But doing this usually requires a jailbrook and device rate. We need root access to bypass the operating system standard protections. Absolutely. You can't do deep dynamic analysis without a jailbreak. For years, Cityo was the absolute king of managing software on jailbroken phones. But the landscape has shifted, right? Sileo seems to be the modern standard. Yeah, software architectures evolve and Cityo eventually just showed its age. Sileo is the newer package manager. It's actually built off the foundations of Cityo, but specifically modernized to work on newer iOS versions and 64-bit architectures. So it's how you install all your underlying forensic tools directly onto the iPhone itself. Exactly. It's your hub. Okay, once we have that root access and the app is running, we need debuggers to watch it. The two big names here are LLDB and GDP. Right, the heavy hitters. Both let you pause the app, look at the memory, and step through the code line by line.
But LLDB is heavily favored. Why choose one over the other if they basically do the same thing? It comes down to modern architecture support and, again, user experience. LLDB is the default debugger for Apple's own development ecosystem. So it just understands modern iOS, but it's much better. Yes. But honestly, the biggest quality of life feature, LLDB supports robust color-coded output and deep Python scripting. Color coding. That sounds almost trivial when we're talking about advanced malware analysis. It sounds trivial until you're debugging a complex application for six straight hours. They're point. When you're staring at terminal windows, having memory addresses in one color, executable commands in another and variables in a third, I mean, it makes a massive difference in cognitive fatigue. Because GDP just gives you what? Monochrome text? Yeah. Traditionally, it's just walls of monochrome text, which leads to eye strain and you just start missing details. Oh, I should note, there is another dynamic tool called reveal that exists to help visualize the app's user interface as it runs.
But it's a paid commercial tool, so we aren't highly recommending it for someone bootstrapping a lab from scratch. Right. We want to focus on accessible tools that give you the highest return on investment for your time. And for dynamic analysis, the real power comes from dynamic frameworks. Right. Frameworks like Cycrypt, Frida, Objection, and Needle. Those are the gold standards. These aren't just debuggers. These let you actively inject your own code into the malware while it's running. You can hook into functions and change their behavior on the fly. It's incredibly powerful. But wait, I have to jump in here with a massive warning for anyone setting these up. Oh, the Python issue. Yes. Looking at the operational requirements for tools like Needle or Objection, they are heavily, heavily reliant on Python. They are. And that introduces a significant infrastructure risk to your lab machine. If you just start globally installing all these different Python-based security tools on your main operating system, you will destroy your machine's ecosystem. It will be a total mess. One tool demands Python 2.7.
Another strictly requires Python 3. One needs version 1.0 of a specific cryptography library and another needs version 2.0. And if you install them all in the same place, the dependencies just overwrite each other. Suddenly nothing runs. It is a harsh lesson every analyst learns, usually the hard way. You must use Python virtual environments. Isolate every single tool into its own self-contained bubble. It takes a few extra minutes to set up, but it will save you days of rebuilding a corrupted lab machine. Consider yourselves warned, seriously. All right, let's shift our focus. We've spent a lot of time dissecting Apple's walled garden, but what happens when we jump the fence over to Android? It's an entirely different operating system built on completely different architectural principles. Because that means throwing out almost everything in your toolkit and starting fresh. Basically, yeah. You cannot use an iOS disassembler on an Android application. They speak completely different languages. Right. Android apps are primarily built using Java or more recently Kotlin. And for static analysis on Android, one tool stands above the rest as an absolute foundational
powerhouse Android guard. Oh, Android guard is fantastic. Because it's written in Python, it is highly accessible for writing custom scripts. Which we just learned to put in a virtual environment. Exactly. But yeah, it is incredibly well maintained, deeply documented and packed with features specifically designed to tear apart Android application packages, commonly known as APK files. What exactly does it do with the APK? It maps the permissions, finds the hidden certificates, and just rips out the core code for you to look at. But there's a unique roadblock with Android. Because Java is a relatively well understood language, it's notoriously easy to decompile. Right. You can turn the machine code back into readable Java fairly easily. And malware authors know this. So they scramble the code before they release it. Yes. This is the concept of opuscation. Imagine trying to read a novel where the author has systematically replaced every character's name, every location, and every verb with a random, meaningless barcode.
That sounds impossible to read. It is. You compile an opuscated app. Instead of seeing clearly named functions like Steel User Password, you see function A, variable B. It is deliberately designed to confuse the analyst and hide the logical flow. So how do we solve the scramble? How do we turn the barcodes back into something we can actually read? You've reached for de-appuscation tools. This is where utilities like Classy Shark and the class named de-appfuscator become vital. What do they do exactly? They use pattern recognition and structural analysis to trace those scrambled, meaningless names and untangle them. They map the relationship so you can slowly rebuild a readable structure. All right. So once you've untangled the web, you need to actually read the underlying logic. That's where JADX comes in, right? Yes. JADX is a highly reliable Java decompiler that translates the raw, delved byte code back into clean, readable Java code. But you have to be prepared for edge cases, I assume. Oh, always. Sometimes you aren't dealing with a standard application file.
Sometimes you pull a file off an Android device that has been heavily optimized specifically for that device's unique hardware runtime. So JADX can't read it. Not natively. Yeah. To analyze those, you need a specialized translation tool called O2Dex. It takes those highly optimized hardware specific files and converts them back into standard DEX files. The generic format that JADX and Andregard actually understand. Exactly. So you're constantly translating things back into a language your tool speak. Now I noticed another utility in the Andreg tool bag called Sine. Why do we need a cryptographic signing tool just to look at malware? Because of Android's internal security mechanisms. Just like iOS, Android will flat out refuse to install an application if it doesn't have a valid cryptographic signature. But if you are analyzing a piece of malware, its certificate might be expired intentionally broken or stripped out completely. Exactly. And that's where the sign tool comes in. It allows you to artificially inject a brand new test certificate into the malware.
So you are basically giving the app a fake ID. Pretty much. A fake ID which tricks the Android test device into letting you install it. Brilliant fake IDs for malware. Oh, I also see Android Studio on the list. I have to ask. Android Studio is the official development software used by engineers to build apps. It is. It is a reverse engineer using a developer tool to tear them down. It is a fair question. While it is built for creation, it is incredibly useful for destruction too. How so? Well, it has highly robust built-in emulators. So you can spin up fake Android phones of any size or version in seconds. Oh, that's handy. Very. It also has incredibly powerful log viewing capabilities, which are crucial for watching an app's behavior and deep debugging features. But I imagine running an entire operating system emulator inside a development environment takes a huge toll on your computer. Oh, it is a massive resource hog. Android Studio will eat your machine's ram for breakfast. Good to know. Yeah, if your frantic lab machine isn't heavily spessed with a lot of memory, running
Android Studio will do another analysis will bring your system to a grinding halt. You have to keep a close eye on your system resources. So we've cracked the Android code statically. We've unscramble the obfuscation. Now, just like with iOS, we need to catch the malware in the act. We need to watch it run dynamically. And there are two main theaters of war when watching Android malware run. What it's doing locally in the device's memory and what is whispering over the internet. Let's start with memory. The standout tool here is volatility. Volatility is just an unparalleled memory forensics framework. How does it work? When malware is running, it often has to decrypt its darkest secrets, things like encryption keys for ransomware, stolen passwords, or hidden command instructions. And it stores them temporarily in the device's ram to use them. And volatility lets you grab that. Yeah, it allows you to dump that active memory and search through it. It is literally like freezing time and extracting the malware's active thoughts at that exact millisecond. That is incredibly cool.
And to interact with the app while it runs, we also use Java specific debuggers like Ann Bug and JDB. Right, along with frameworks like Droser and Frostmon, which monitors every single time the malware touches the file system. And it is worth noting that Frida and objection, the dynamic conjection frameworks we discuss for iOS, they work phenomenally well on Android too, right? They really do. The knowledge transfers perfectly between the two platforms. That's great. But freezing memory and watching files only tells you half the story. Mobile malware rarely acts in isolation. No. It's almost always designed to communicate with a remote command and control server. It needs to send your stolen data back to the attacker. Who is it talking to and what data is it sending? To figure that out, we have to intercept the network traffic. And this is actually a beautifully cross-platform skill. It really is. The network interception techniques we use for Android are the exact same ones we use for iOS. Network interception is arguably the most critical and often the most revealing part of
dynamic analysis. Definitely. The heavy hitters for this job are burp suite and mint proxy. These are men in the middle tools. Right. I like to think of a man in the middle attack like a correct post office. The malware thinks it's sending a sealed letter directly to its creator server. But we configure the test phone so that all of its traffic routes through our laptop first. So we act as the post office. Exactly. We intercept the envelope, carefully open it, read the stolen data inside, and then we can choose to pass it along to the server to see how the server responds. Or we can just burn the letter and drop the connection. You control the entire flow of information. You can even modify the data before sending it along to see if you can trick the attacker server into revealing more about itself. It's so clever. And to capture the broader network, picture like not just the specific HTTP traffic, but all the raw data packets flying back and forth, you rely on tools like Wireshark, TCP dump, and Charles Proxy. Yeah. They record everything on the wire.
So you have a permanent forensic record of the exact sequence of communication. And just for pure operational ease, it's worth having a graphical FTP and SSH client like CyberDuck installed. Oh, definitely. It just makes the constant chore of moving files, scripts, and memory dumps back and forth between your forensic computer and your test devices much faster. Well, we have covered a massive amount of architectural ground today. We really have. The big takeaway here is understanding balance. Having a successful malware analysis lab isn't just about downloading one or two magic tools. It requires carefully balancing your hardware, ensuring your networking is fiercely isolated, and then mastering this exact software tool bag we've just unpacked. You need the right tool for the specific obstacle in front of you. Exactly. And speaking of having the right tool for the obstacle, let's do a quick review exercise to reinforce how these pieces fit together for you listening at home. Oh, let's hear the scenario. Okay, imagine you're handed a suspicious mobile app. You've isolated your network and you know it's an Android app, but when you run it through
Android, the Java code is completely scrambled. Instead of function names, you're just seeing meaningless letters. The barcode analogy. Exactly. Based on what we discussed, which two tools are you going to reach for first to unscramble those class names? Think back to how we translate that barcode back into English. The answer is classy shark and the class name deabfuscator. Those are your go-to tools for untangling the obfuscation web and getting back to readable logic. Spot on. So we've outlined the ultimate digital detective toolkit, but I want to leave you with a final, somewhat provocative thought to mull over. Okay, I'm listening. We spent a lot of time today talking about workarounds. We talked about side loading, jail breaking, faking certificates, and bypassing encryption just to make these analysis tools function. Right. Jumping through all those oops. But Apple and Google are constantly relentlessly updating their mobile operating systems to block these exact techniques, always in the name of user security.
Which begs a really difficult question. Who is really winning the arms race? Is it the security researchers trying to build these labs to understand the threats and protect us? Is the increasingly lockdown nature of these mobile ecosystems actually benefiting the malware authors? Exactly. Are these strict OS protections just giving attackers dark encrypted corners to hide in where researchers can't easily follow? That's a scary thought. It's that dim room again. You have the malicious app on the desk. You have your complete tool bag ready to go. The real question is, will the phone's own security system even let you open it? Think about that the next time your device insists on a mandatory security update. Rubric is the security and AI operations company. Build for what happens after an attack hits. Not just the moments before. AI has turned the threat landscape into quicksand, moving too fast for any human to fully predict. That's why an agentic cyber resilience platform matters. Automated recovery, clean data, a business that keeps moving no matter what hits. One platform, not a patchwork of stitched together tools and gaps.
Don't wait for the next attack. Secure and accelerate your business at rubric.com. Again, rubric.com.
More episodes
More from CyberCode Academy

Course 42 - Mobile Malware Analysis Fundamentals | Episode 13: Designing and Arc...
CyberCode Academy

Course 42 - Mobile Malware Analysis Fundamentals | Episode 12: Dynamic Analysis...
CyberCode Academy

Course 42 - Mobile Malware Analysis Fundamentals | Episode 11: Dynamic Analysis...
CyberCode Academy

Course 42 - Mobile Malware Analysis Fundamentals | Episode 10: The Essentials of...
CyberCode Academy