apk-decompilers.md (9084B)
1 --- 2 title: "APK decompilers" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/apk-decompilers.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/apk-decompilers.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # APK decompilers 14 15 The comparative decompilation guide in the references provides further details on the tools and their tradeoffs.<sup>[[3]](#references)</sup> 16 17 ### JD-Gui<sup>[[4]](#references)</sup> 18 19 As the pioneering GUI Java decompiler, **JD-Gui** allows you to investigate Java code within APK files. It's straightforward to use; after obtaining the APK, simply open it with JD-Gui to inspect the code. 20 21 ### Jadx<sup>[[5]](#references)</sup> 22 23 **Jadx** offers a user-friendly interface for decompiling Java code from Android applications. It's recommended for its ease of use across different platforms. 24 25 - To launch the GUI, navigate to the bin directory and execute: `jadx-gui` 26 - For command-line usage, decompile an APK with: `jadx app.apk` 27 - To specify an output directory or adjust decompilation options: `jadx app.apk -d <path to output dir> --no-res --no-src --no-imports` 28 29 #### AI-assisted static analysis with jadx-mcp 30 31 [**jadx-mcp**](https://github.com/0xdad0/jadx-mcp) is a jadx-gui plugin that exposes the analysis model of the currently loaded APK, DEX, or JAR as 27 schema-validated MCP tools over Streamable HTTP. Unlike copying decompiled text into an LLM, the client can request Java or Smali, methods and fields, decoded manifest components and resources, cross-references, and jadx rename operations as structured results.<sup>[[14]](#references)</sup> 32 33 The plugin targets jadx-gui 1.5.6 and requires jadx to run on Java 17 or later. Install its fat JAR, open the target in jadx-gui, start the server from **Plugins → jadx-mcp: Settings...**, and register the default endpoint with an HTTP-capable MCP client:<sup>[[14]](#references)</sup> 34 35 ```bash 36 jadx plugins --install-jar jadx-mcp-0.1.0.jar 37 claude mcp add --transport http jadx-mcp http://localhost:8090/mcp 38 ``` 39 40 A compact Android review/deobfuscation loop is:<sup>[[14]](#references)</sup> 41 42 1. Call `status`, then inspect `get_android_manifest`, `get_manifest_component`, `get_main_activity_class`, `get_strings`, and selected resource files to map exported entry points, deep links, hardcoded endpoints, and security configuration. 43 2. Use `search_classes`, `search_method_by_name`, or `search_classes_by_keyword`, then retrieve only the relevant class/method source or Smali. Supply a `signature` fragment to method tools when overloads are ambiguous. 44 3. Follow `xrefs_to_class`, `xrefs_to_method`, and `xrefs_to_field`, retrieving method source at each hop to reconstruct call paths and field-access flows. 45 4. Rename inferred symbols with `rename_class`, `rename_method`, `rename_field`, or `rename_package`, reload, and repeat. These aliases use jadx's normal deobfuscation system; `rename_variable` is session-local and is not stored in saved `.jadx` metadata. 46 47 Paginated tools accept `offset` and `limit` (default 50, maximum 500). Prefer targeted queries over `get_main_application_classes_code`, whose full-source responses are token-heavy.<sup>[[14]](#references)</sup> 48 49 > [!WARNING] 50 > The server has **no authentication**. Its safe default is `127.0.0.1:8090`; Origin/Host validation helps against browser and DNS-rebinding access but does not authenticate network clients. Never bind it to `0.0.0.0` or a LAN address, and do not port-forward the endpoint: connected clients can extract loaded code/resources and mutate project aliases.<sup>[[14]](#references)</sup> 51 52 ### GDA Android Reversing Tool<sup>[[6]](#references)</sup> 53 54 **GDA**, a Windows-only tool, offers extensive features for reverse engineering Android apps. Install and run GDA on your Windows system, then load the APK file for analysis. 55 56 ### Bytecode Viewer<sup>[[7]](#references)</sup> 57 58 With **Bytecode-Viewer**, you can analyze APK files using multiple decompilers. After downloading, run Bytecode-Viewer, load your APK, and select the decompilers you wish to use for simultaneous analysis. 59 60 ### Enjarify<sup>[[8]](#references)</sup> 61 62 **Enjarify** translates Dalvik bytecode to Java bytecode, enabling Java analysis tools to analyze Android applications more effectively. 63 64 - To use Enjarify, run: `enjarify app.apk` This generates the Java bytecode equivalent of the provided APK. 65 66 ### CFR<sup>[[9]](#references)</sup> 67 68 **CFR** is capable of decompiling modern Java features. Use it as follows: 69 70 - For standard decompilation: `java -jar ./cfr.jar "app.jar" --outputdir "output_directory"` 71 - For large JAR files, adjust the JVM memory allocation: `java -Xmx4G -jar ./cfr.jar "app.jar" --outputdir "output_directory"` 72 73 ### Fernflower<sup>[[10]](#references)</sup> 74 75 **Fernflower**, an analytical decompiler, requires building from source. After building: 76 77 - Decompile a JAR file: `java -jar ./fernflower.jar "app.jar" "output_directory"` Then, extract the `.java` files from the generated JAR using `unzip`. 78 79 ### Krakatau<sup>[[11]](#references)</sup> 80 81 **Krakatau** offers detailed control over decompilation, especially for handling external libraries. 82 83 - Use Krakatau by specifying the standard library path and the JAR file to decompile: `./Krakatau/decompile.py -out "output_directory" -skip -nauto -path "./jrt-extractor/rt.jar" "app.jar"` 84 85 ### Procyon<sup>[[12]](#references)</sup> 86 87 For straightforward decompilation with **procyon**: 88 89 - Decompile a JAR file to a specified directory: `procyon -jar "app.jar" -o "output_directory"` 90 91 ### frida-DEXdump<sup>[[13]](#references)</sup> 92 93 This tool can be used to dump the DEX of a running APK in memory. This helps to beat static obfuscation that is removed while the application is executed in memory. 94 95 ### androidReverse 96 97 **androidReverse** is an **on-device Android reverse-engineering suite**: useful when you need to triage an APK directly from a phone/tablet **without ADB or a desktop workstation**.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 98 99 Useful workflow: 100 101 - **Extract** `.apk`, `.xapk`, and split `.apks` from **installed apps** or storage, then inspect Java/Kotlin, Smali, resources, and `lib/*.so` in the same session. 102 - **Compare the same class across multiple engines** instead of trusting a single decompiler output. It includes **Jadx**, **Jadx Fallback**, **Jadx IR**, **CFR**, **Procyon**, **JD-Core**, **Krakatau**, and **Vineflower**. In practice, use **Jadx/CFR/Procyon** for readability and switch to **Krakatau** or **Jadx IR** when obfuscation, malformed bytecode, Kotlin artifacts, lambdas, or flattened control flow make the reconstructed Java suspicious. 103 - **Validate resources/manifests** when normal viewers fail: the suite decodes **binary AXML** and parses **ARSC** tables, which is useful to recover **permissions**, **exported components**, **intent filters**, **deep links**, **feature flags**, **URLs**, and other strings hidden in resources. 104 - **Pivot into native code** when the real logic lives in JNI: it embeds **radare2** for **pseudo-C**, **assembly**, **hex**, **CFGs**, **call graphs**, and **xrefs**, which is handy to inspect JNI entry points, anti-analysis checks, crypto routines, and string decryption inside Android `.so` files. 105 - For **Flutter** apps, prefer its **Unflutter** support; for **Unity** apps, inspect the recovered **`il2cpp` metadata** instead of relying only on Java decompilation. 106 107 This is especially practical for **field triage**, **mobile malware static analysis**, and **quick review of customer-provided APKs** when you only have an Android device available. 108 109 ## References 110 111 - [1] [androidReverse repository](https://github.com/UltraSina/androidReverse) 112 - [2] [androidReverse latest release (release11 / version 11, June 21, 2026)](https://github.com/UltraSina/androidReverse/releases/tag/release11) 113 - [3] [How to Break Your JAR in 2021 - Decompilation Guide for JARs and APKs](https://eiken.dev/blog/2021/02/how-to-break-your-jar-in-2021-decompilation-guide-for-jars-and-apks/#cfr) 114 - [4] [JD-GUI repository](https://github.com/java-decompiler/jd-gui) 115 - [5] [Jadx repository and usage](https://github.com/skylot/jadx) 116 - [6] [GDA Android Reversing Tool](https://github.com/charles2gan/GDA-android-reversing-Tool) 117 - [7] [Bytecode Viewer releases](https://github.com/Konloch/bytecode-viewer/releases) 118 - [8] [Enjarify repository](https://github.com/Storyyeller/enjarify) 119 - [9] [CFR repository](https://github.com/leibnitz27/cfr) 120 - [10] [JetBrains Java decompiler engine](https://github.com/JetBrains/intellij-community/tree/master/plugins/java-decompiler/engine) 121 - [11] [Krakatau repository](https://github.com/Storyyeller/Krakatau) 122 - [12] [Procyon repository](https://github.com/mstrobel/procyon) 123 - [13] [FRIDA-DEXDump repository](https://github.com/hluwa/FRIDA-DEXDump) 124 - [14] [jadx-mcp: MCP server plugin for jadx-gui](https://github.com/0xdad0/jadx-mcp)