Debugging an app for any security issues/backdoors/viruses -- 2
Budget: ₹12,500 – ₹37,500 INR
About the Role
We are seeking a highly skilled Android Security Analyst to conduct a comprehensive security audit of an Android application (APK format). The primary objective is to identify vulnerabilities, hidden backdoors, malicious code, data exfiltration risks, or any security weaknesses that could compromise user data or system integrity.
This is a critical role focused on application security, reverse engineering, and malware analysis.
Key Responsibilities
Perform static and dynamic analysis of the provided APK file
Detect:
Backdoors or hidden communication channels if any
Malicious code or injected payloads
Unauthorized data collection or transmission
Hardcoded credentials or API keys
Suspicious permissions usage
Obfuscated or encrypted hidden logic
Analyze network calls and backend communication endpoints
Evaluate encryption implementation and secure storage practices
Identify privilege escalation or root exploitation risks
Provide a detailed vulnerability report with:
Severity classification (Low / Medium / High / Critical)
Technical explanation
Exploitation risk
Recommended remediation steps
Required Skills & Qualifications
Strong experience in Android security testing
Proficiency in tools such as:
JADX / APKTool
Frida
MobSF
Burp Suite
Wireshark
IDA / Ghidra
Knowledge of:
Android architecture and permissions model
Reverse engineering
Malware analysis
Network traffic interception
Secure coding practices
Experience identifying:
Data exfiltration patterns
C2 (Command & Control) behavior
Suspicious background services
Dynamic code loading
Understanding of OWASP Mobile Top 10 vulnerabilities
Deliverables
Full security audit report (PDF format)
Risk summary for non-technical stakeholders
Proof-of-concept (if exploit is possible)
Remediation recommendations
Good to Have
CEH / OSCP / Mobile Security Certification
Experience auditing healthcare or data-sensitive applications
Experience reviewing closed-source third-party APKs
Engagement Type
Project-based audit
NDA required
Strict confidentiality and secure handling of APK file
We are seeking a highly skilled Android Security Analyst to conduct a comprehensive security audit of an Android application (APK format). The primary objective is to identify vulnerabilities, hidden backdoors, malicious code, data exfiltration risks, or any security weaknesses that could compromise user data or system integrity.
This is a critical role focused on application security, reverse engineering, and malware analysis.
Key Responsibilities
Perform static and dynamic analysis of the provided APK file
Detect:
Backdoors or hidden communication channels if any
Malicious code or injected payloads
Unauthorized data collection or transmission
Hardcoded credentials or API keys
Suspicious permissions usage
Obfuscated or encrypted hidden logic
Analyze network calls and backend communication endpoints
Evaluate encryption implementation and secure storage practices
Identify privilege escalation or root exploitation risks
Provide a detailed vulnerability report with:
Severity classification (Low / Medium / High / Critical)
Technical explanation
Exploitation risk
Recommended remediation steps
Required Skills & Qualifications
Strong experience in Android security testing
Proficiency in tools such as:
JADX / APKTool
Frida
MobSF
Burp Suite
Wireshark
IDA / Ghidra
Knowledge of:
Android architecture and permissions model
Reverse engineering
Malware analysis
Network traffic interception
Secure coding practices
Experience identifying:
Data exfiltration patterns
C2 (Command & Control) behavior
Suspicious background services
Dynamic code loading
Understanding of OWASP Mobile Top 10 vulnerabilities
Deliverables
Full security audit report (PDF format)
Risk summary for non-technical stakeholders
Proof-of-concept (if exploit is possible)
Remediation recommendations
Good to Have
CEH / OSCP / Mobile Security Certification
Experience auditing healthcare or data-sensitive applications
Experience reviewing closed-source third-party APKs
Engagement Type
Project-based audit
NDA required
Strict confidentiality and secure handling of APK file