interesting · Mobile — research
A rooted analysis device can strip Promon Shield from some protected Android apps while leaving them runnable.
Affects
Promon Shield for Mobile, a commercial runtime self-protection layer embedded in Android banking, payment and game applications.
The demonstrated method extracts protected material after runtime decryption and replaces Shield’s native implementation with compatible JNI behavior that neutralizes active checks.
Detail and 2 sources
It requires a copied APK, a rooted device, and skilled app-specific work; it does not cover Promon attestation. Promon reproduced the method and released hardened versions.