This course is coming soon — content and pricing shown below may change before launch.
Coming SoonBeginnerAndroid Malware10h of content · 1 guided lab500 XP

Android Malware Beginner

Master reverse engineering of malicious APKs: real lab with jadx-gui, MobSF, and Frida in an isolated environment.

Not on sale yet. Leave your email and we will tell you the day Android Malware Beginner opens — nothing else.

One email, only when it launches. No newsletter.

14-day money-back guarantee · No subscription · Lifetime access

Preview the student experience

No login · Free interactive demo

Try demo →

1

Guided lab

Isolated VM environment

10h

Of content

Labs + practice + exams + simulations

4

Modules

Progressive difficulty

2–4h

Per lab session

Unlimited restarts

HTKWhat's included
  • Full Beginner course (video lessons + written content)
  • 1-2 guided hands-on labs in an isolated VM
  • Per-module exams
  • HTK Beginner certificate
  • Lifetime access, unlimited lab restarts
  • Expert instructor reviews your reports & assignments
119159

One-time payment, no subscription

Notify me

Lab tools you will use

jadx-guiDecompilerapktoolDecompilerMobSFAnalysisADBToolingFridaInstrumentationAndroguardAnalysisdex2jarDecompilerBytecode ViewerDecompilerjadx-guiDecompilerapktoolDecompilerMobSFAnalysisADBToolingFridaInstrumentationAndroguardAnalysisdex2jarDecompilerBytecode ViewerDecompiler
JEB DecompilerDecompilerdrozerPentestObjectionInstrumentationBurp SuiteProxyAPKiDDetectionAPKLeaksReconGhidraReverse eng.radare2Reverse eng.JEB DecompilerDecompilerdrozerPentestObjectionInstrumentationBurp SuiteProxyAPKiDDetectionAPKLeaksReconGhidraReverse eng.radare2Reverse eng.

Before you start — quick answers

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Course Syllabus

4 modules · 10h of content

Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.

1

Module 1

Beginner

Android Ecosystem Fundamentals & Mobile Threats

  • Android architecture: Dalvik/ART, permissions, app sandbox
  • Mobile threat landscape: spyware, bankers, Android RATs
  • Essential tools: ADB, emulator, jadx-gui, apktool
  • Module theory exam
2

Module 2

Beginner

Static Analysis of APKs

  • APK internal structure: AndroidManifest, smali, resources
  • Decompilation with jadx-gui: reading Java/Kotlin code
  • Detecting suspicious permissions and malicious code smells
  • Module exam
3

Module 3

Beginner

Dynamic Analysis & Instrumentation

  • Installation and execution in isolated emulator with ADB
  • Automated analysis with MobSF: traffic, APIs, behavior
  • Introduction to Frida: hooking critical functions in real time
  • Module exam
4

Module 4

Beginner

Final Report + Certification Exam

  • Documenting mobile IOCs: hashes, C2 domains, abused permissions
  • Writing the complete APK analysis report
  • HTK final certification exam

What you will learn

  • Build a reproducible APK triage and reverse-engineering workflow
  • Decompile and read Java/Kotlin code from real malicious APKs with jadx-gui
  • Detect abused permissions, suspicious behaviors, and mobile IOCs
  • Use professional tools: jadx-gui, apktool, MobSF, ADB, Frida
  • Deliver a structured APK analysis report with hashes, C2 domains, and abused permissions

Hands-on Lab

Disassemble and analyze a real malicious APK in a fully isolated Android emulator. Use jadx-gui for static decompilation, MobSF for automated analysis, and Frida for dynamic hooking. Flags are automatically validated when you discover malicious behaviors.

1⬡ 1 guided lab
2–4hSession window
UnlimitedRestarts
AutoFlag validation
Experience a lab preview →

Requirements

  • ·Modern web browser
  • ·Stable internet connection
  • ·No local installation required
  • ·Basic technical English recommended

Frequently Asked Questions

Complete answers about this course, labs, certificates, and refunds

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Yes. 14-day money-back if lesson progress is below 20% and you have not completed the HTK certificate path (all lessons + labs) for that course. Details in our Refund Policy.

Yes. Once purchased, you have permanent access to all course materials and future updates.

Yes. All professional tools come pre-installed and configured in the VM, no local setup needed.

Most students complete the course in 2–4 weeks studying part-time. You set your own pace.

Ready for the next level?

Android Malware Intermediate

You've covered the fundamentals. Android Malware Intermediate builds on this course with more complex real-world scenarios, higher-difficulty labs, and advanced analysis workflow.

12h of content2 guided labs159
View Intermediate Course →
Ready to level up?

Build real Android Malware skills

Get hands-on with real Android Malware scenarios, professional-grade tools, and validated flag objectives. No prior experience needed.

From119or 199 € for the complete path

Not on sale yet. Leave your email and we will tell you the day Android Malware Beginner opens — nothing else.

One email, only when it launches. No newsletter.

One-time payment, no recurring chargesLifetime access, course updates included14-day money-back guarantee