Program Sikkerhetsfestivalen 2026

Offensive Security

No Key Required: Bypassing Application-Layer Encryption with Frida

Tirsdag 1 · Frimurerlosjen, rom 2

EnglishDetailed 40 min

Andreas Claesson

Andreas Claesson

Principal Penetration Tester at River Security

Andreas has a background in radio electronics and mobile phone hardware development. The last 10 years he has been working as a security consultant, and currently as a Principal Penetration Tester at River Security. He is an expert in Application Security, with a special interest in IoT, electronics, mobile security, and reverse engineering.

Mobile applications have always shared extensive data with third-party advertising and analytics companies. When I revisited privacy research conducted several years ago, I found the landscape had shifted: where plaintext payloads once appeared in a proxy, we now see opaque encrypted blobs even after TLS is stripped. Application-layer encryption has become the new barrier between researchers and the data.

This talk demonstrates how to break through that barrier without ever knowing the encryption key. Using Perfect365, a beauty app with over 100 million installs, as a case study, we walk through the complete methodology: identifying double-encrypted traffic in a proxy, tracing encryption routines through heavily obfuscated Android bytecode, and instrumenting those routines with Frida to intercept data at the point it enters the cipher, before the key is applied.

The technique turns any application-layer cipher into a transparent window. We reveal what ad SDKs actually transmit across the real-time bidding supply chain: auction payloads, cross-publisher identity tokens, device fingerprints, and granular ad lifecycle telemetry. This data is encrypted precisely because it was never meant to be seen.

We also discuss how AI-assisted static analysis has fundamentally changed the pace of this research. Navigating hundreds of thousands of lines of obfuscated SDK code that would previously have taken weeks now takes hours, lowering the barrier for privacy researchers significantly.

Attendees will leave with a reusable Frida methodology applicable to any app using AES, RSA, or hybrid encryption, and a clearer picture of the data economy operating invisibly inside the apps on their devices.

  1. Inside the NPM supply chain attacks: Lessons from a worm on the loose 1 · Frimurerlosjen, rom 1
  2. Trust and Democracy in the Age of AI 10 · HeartBox ,Teatersalen
  3. No More Shadow IT: Governing Linux Desktops with Intune and Chef 10 · HeartBox, Byscenen
  4. Artikkel 32 i praksis: Slik ivaretar vi den registrerte 11- Breiseth, Storlon
  5. Bridging the gap between OT and IT - Expert Panel 2 · Home hotel Hammer, moen nede
  6. Integrert sikring i sykehusprosjekter - fra idefase til drift 2 · Home hotel Hammer, moen oppe
  7. Er konsulenten din en risiko i sikkerhetsgraderte anskaffelser? 3 · Hvelvet, Gullsalen
  8. Leverandøravhengighet i et beredskapsperspektiv: EU-kravene som kan endre forholdet til Big Tech 4 · Kommunestyresalen, Lillehammer rådhus
  9. Passkeys migration in the enterprise 5 · Kulturhuset Banken, Expedisjon
  10. "Last man standing – hvordan sikre operativ evne når digitale tjenester svikter" 5 · Kulturhuset Banken, Festsalen
  11. No organization is an island: hvordan finne det som betyr noe, når alt henger sammen med alt 5 · Kulturhuset Banken, Holbøsalen
  12. A closer look at what we suspect is vibe coded ransomware 5 · Kulturhuset Banken, Kafeen
  13. Beyond Standalone Risk Assessments: Making Cyber Risk Relevant for Management 6 · Lillehammer kino, sal 2
  14. Hvordan skape suksess med digitale kurs - en ærlig fortelling fra maritim næring 6 · Lillehammer kino, sal 4
  15. Lessons Learned and laughs from Incident Response 9 · Victoria Scandic, sal 3