Skip to finding
interesting · Mobile — research

A rooted analysis device can strip Promon Shield from some protected Android apps while leaving them runnable.

Affects

Promon Shield for Mobile, a commercial runtime self-protection layer embedded in Android banking, payment and game applications.

The demonstrated method extracts protected material after runtime decryption and replaces Shield’s native implementation with compatible JNI behavior that neutralizes active checks.

Detail and 2 sources

It requires a copied APK, a rooted device, and skilled app-specific work; it does not cover Promon attestation. Promon reproduced the method and released hardened versions.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026