This course is coming soon — content and pricing shown below may change before launch.
Coming SoonIntermediateAndroid Malware12h of content · 2 guided labs750 XP

Android Malware Intermediate

Advanced Android reverse engineering: obfuscated APKs, runtime hooking, and C2 protocol analysis with Frida and MobSF.

Not on sale yet. Leave your email and we will tell you the day Android Malware Intermediate opens — nothing else.

One email, only when it launches. No newsletter.

14-day money-back guarantee · No subscription · Lifetime access

Preview the student experience

No login · Free interactive demo

Try demo →

2

Guided labs

Isolated VM environment

12h

Of content

Labs + practice + exams + simulations

4

Modules

Progressive difficulty

2–4h

Per lab session

Unlimited restarts

HTKWhat's included
  • Full Intermediate course (video lessons + written content)
  • 2-4 guided labs — less guided, more complex than Beginner
  • Advanced per-module exams
  • HTK Intermediate certificate
  • Lifetime access, unlimited lab restarts
  • Expert instructor reviews your reports & assignments
159

One-time payment, no subscription

Notify me

Lab tools you will use

jadx-guiDecompilerapktoolDecompilerMobSFAnalysisADBToolingFridaInstrumentationAndroguardAnalysisdex2jarDecompilerBytecode ViewerDecompilerjadx-guiDecompilerapktoolDecompilerMobSFAnalysisADBToolingFridaInstrumentationAndroguardAnalysisdex2jarDecompilerBytecode ViewerDecompiler
JEB DecompilerDecompilerdrozerPentestObjectionInstrumentationBurp SuiteProxyAPKiDDetectionAPKLeaksReconGhidraReverse eng.radare2Reverse eng.JEB DecompilerDecompilerdrozerPentestObjectionInstrumentationBurp SuiteProxyAPKiDDetectionAPKLeaksReconGhidraReverse eng.radare2Reverse eng.

Before you start — quick answers

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Course Syllabus

4 modules · 12h of content

Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.

1

Module 1

Intermediate

Advanced Android Threat Analysis

  • Multi-stage malware: droppers, loaders, and payload delivery
  • Obfuscation techniques: ProGuard, DexGuard, string encryption
  • Advanced ADB and emulator configuration for evasive samples
  • Module exam
2

Module 2

Intermediate

Deep Static Analysis & Deobfuscation

  • Manual smali patching and repackaging techniques
  • Decrypting hardcoded strings and configuration blobs
  • Analyzing native libraries (JNI/NDK) with Ghidra
  • Module exam
3

Module 3

Intermediate

Advanced Dynamic Instrumentation with Frida

  • Frida scripting: intercepting SSL pinning and crypto functions
  • Runtime C2 protocol analysis and domain generation algorithm (DGA) extraction
  • Anti-emulation bypass techniques
  • Module exam
4

Module 4

Intermediate

Executive Report + Intermediate Certification

  • Mobile threat intelligence report: campaign attribution and IOCs
  • Detection engineering for mobile threat indicators
  • HTK intermediate certification exam

What you will learn

  • Analyze multi-stage Android malware: droppers, loaders, and payload delivery chains
  • Deobfuscate ProGuard/DexGuard-protected APKs and decrypt hardcoded strings and config blobs
  • Patch and repackage smali, and analyze native JNI/NDK libraries with Ghidra
  • Use Frida to bypass SSL pinning, hook crypto functions, and extract C2 protocols and DGA logic
  • Deliver a mobile threat intelligence report with campaign attribution, IOCs, and detection engineering

Hands-on Lab

Analyze obfuscated, multi-stage Android malware that uses dynamic class loading, encrypted C2 communication, and anti-emulation checks. Use Frida for advanced hooking, MobSF for behavioral analysis, and manual smali patching for deobfuscation.

2⬡ 2 guided labs
2–4hSession window
UnlimitedRestarts
AutoFlag validation
Experience a lab preview →

Requirements

  • ·Recommended: complete the HTK Android Malware Beginner course first, or have equivalent hands-on APK analysis experience
  • ·Working knowledge of APK structure, smali, jadx-gui, MobSF, and ADB from beginner-level analysis
  • ·Familiarity with the Android runtime (Dalvik/ART), the permissions model, and basic Frida instrumentation
  • ·Stable internet connection — the Android emulator lab environment and all tools are fully pre-configured, no local setup required

Frequently Asked Questions

Complete answers about this course, labs, certificates, and refunds

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Yes. 14-day money-back if lesson progress is below 20% and you have not completed the HTK certificate path (all lessons + labs) for that course. Details in our Refund Policy.

Yes. Once purchased, you have permanent access to all course materials and future updates.

Yes. All professional tools come pre-installed and configured in the VM, no local setup needed.

Most students complete the course in 2–4 weeks studying part-time. You set your own pace.

Start from the beginning?

Android Malware Beginner

Not ready for intermediate yet? Android Malware Beginner covers the foundational skills and guided labs you need before tackling the advanced material.

10h of content1 guided lab119
View Beginner Course →
Ready to level up?

Build real Android Malware skills

Get hands-on with real Android Malware scenarios, professional-grade tools, and validated flag objectives. No prior experience needed.

From159or 199 € for the complete path

Not on sale yet. Leave your email and we will tell you the day Android Malware Intermediate opens — nothing else.

One email, only when it launches. No newsletter.

One-time payment, no recurring chargesLifetime access, course updates included14-day money-back guarantee