Technology enthusiast and mobile security researcher experienced in pentesting of mobile apps. Reach out at secfatal@proton.me for technical consultation.
Join the FatalSec community. We have created this new space to continue sharing content, research, tooling, and discussions around reverse engineering, mobile security, pentesting, and low-level internals.
Stay active, share knowledge, and keep learning.
t.me/ eb4DfS4aXuZlM2Y9
Hey folks!
I've been getting a lot of DMs for guidance, so decided to take action on it.
I'm excited to help folks out and give back to the community via Topmate. Don't hesitate to reach out if you have any questions or just want to say hi!
topmate.click/klvge
Ever injected a Frida script just to watch the app instantly crash?
Modern RASP actively hunts your hooks. In this video, we build a memory trap, catch the scanner, and deploy a live ARM64 patch to completely blind it.
Watch the teardown: youtu.be/yipcDMRHBG4
Standard inline hooks triggering Android RASP?
In this video we use Renef to hook imported functions via PLT/GOT manipulation, leaving function prologues untouched to evade memory detections.
Watch here:
youtu.be/ssqe9PEqTYI@Nethella@androidmalware2
Syscall Tracer🔥🔥
Sometimes it’s useful to observe the system calls happening inside a given target process. Especially if the target includes some kind of Frida detection, root detection, or any other kind of Runtime Application Self-Protection (RASP).
frida.re/news/2026/03/09/fri…
#AndroidSecurity#RASP#ReverseEngineering
Frida blocked by advanced RASP?
New Video of "Defeating Modern RASP" is live on FatalSec!
Watch us bypass GarudaDefender using the Renef framework, stealthy process injection, and Lua Java hooks.
Watch Here: youtu.be/zAQ1iYnpUQg
"Dr. Bytecode or: How I Learned to Stop Worrying and Obfuscate Java"
A tale about how @farenain started his journey in Java software obfuscation.
blog.quarkslab.com/how-to-wr…
Cracked @8kSec Challenge 3 by digging deep into Swift memory layouts and spoofing GPS location.
We analyze struct offsets, decode metadata, and use Frida to teleport past the location anti-cheat.
Watch here: youtu.be/8bF6YZLC6Sw
🚨 REcon 2026 is LIVE!
🚀 Call for papers and registration are now open!
Join the world's top reverse engineers & exploit devs in Montreal:
🛠 Trainings: June 15-18 (19 hands-on classes – AI agents, kernel exploits, Rust/Go reversing, fault injection & more!)
📅 Conference: June 19-21
Tickets & early bird now open → recon.cx
Shoutout to the legends teaching: @SinSinology@KyleMartin@MalachiJonesPhD@andreyknvl@mr_phrazer@yarden_shafir@DrCh40s@pulsoid
more elite instructors! See website for all trainers and session info.
Limited spots – see you in MTL! #REcon2026#ReverseEngineering
#BytecodeEmulator
Just open-sourced a Dalvik bytecode emulator 🎉
It's useful for string decryption and static analysis of Android apps/malware. No need to run a full Android environment - just point it at an APK and a method to emulate.
GitHub: github.com/fatalSec/DaliVM
#MobileSecurity#SecurityResearch
Bypassing Android System Library Integrity Checks!
Learn how to defeat checks that flag your Frida hooks. We dive deep into system libraries memory modification techniques.
Don't let integrity checks stop your research.
youtu.be/8FZYmsDUj-c
Unlock iOS reverse-engineering skills with the @8kSec Challenge2 — a hands-on guide to static analysis & runtime manipulation.
Dive in, level up, and break new ground in mobile security!
Watch here: youtu.be/c8UkuOxTWCk#iOSHacking#ReverseEngineering#8KSEC
Our journey with the #iOS emulator continues.
We show how we reached the home screen, enabled multitouch, unlocked network access, and started running real apps 👉 eshard.com/posts/emulating-i…
Attention @kalilinux users! In the coming day(s), apt update is going to fail for pretty much everyone.
The reason? We had to roll a new signing key for the Kali repository. You need to download and install the new key manually: offs.ec/4lUEtak