Shahzaib Ali
Android Reverse Engineer · @apkators
Profile
I'm a Reverse Engineer based in Islamabad with 5+ years dismantling Android applications for a living. My day-to-day is static & dynamic analysis — pulling apart obfuscated APKs in Jadx/Ghidra/IDA Pro, instrumenting live processes with Frida, and intercepting traffic through Burp Suite to recover hidden REST/GraphQL endpoints, signature algorithms and encryption schemes. I've reverse engineered 60+ apps, extracted APIs from platforms like TikTok, Snapchat, SnackVideo, YouTube, WhatsApp & LinkedIn, and rebuilt their private request-signing logic in clean Python. Currently a Reverse Engineer at DSS (Defence Solution & System), and a Level 2 / 5.0★ freelancer trusted by 38+ clients worldwide.
Experience
Android Reverse Engineer
2021 – PresentDSS — Defence Solution & System
Reverse engineered 60+ Android apps end-to-end. Extracted and reconstructed private APIs from major platforms (TikTok, SnackVideo, Snapchat, YouTube, WhatsApp, LinkedIn and more). Implemented hidden request-signing algorithms and encryption/decryption schemes in code, built Frida instrumentation and SSL-unpinning tooling, and automated everything in Python. Daily driver of Apktool, Jadx, Burp Suite, IDA Pro, Ghidra and Postman.
Reverse Engineering & Mobile Consultant
2021 – PresentFreelance — Fiverr & Upwork
Level 2 Seller with a 5.0★ rating across 38+ reviews. Deliver APK reverse engineering, API extraction, MITM/SSL-pinning bypass and mobile app consultation to clients across the US, EU and Asia. Average response time: 1 hour.
Android Developer
2020 – 2021Keswa Techsol
Built native Android apps with REST API integration, modern architecture (MVVM), Flask-based backends and Firebase. This dev foundation is exactly what makes tearing apps apart second nature.
Selected Work
Social API Extraction Suite
Confidential · OngoingReversed the private request-signing algorithms of major social platforms (TikTok, Snapchat, SnackVideo, YouTube) and rebuilt them as clean, well-tested Python wrappers — signatures, tokens and pagination fully replicated for reliable automated access.
Universal SSL-Unpinning Toolkit
ConfidentialA drop-in Frida/Objection toolkit that defeats certificate pinning, root and emulator detection across the vast majority of Android apps — giving full MITM visibility in Burp Suite within seconds.
APK Crypto & Native Reversal
ConfidentialReverse engineered custom AES/RSA layers and .so native libraries in Ghidra & IDA Pro, recovering keys and HMAC schemes hidden deep in JNI code, then reproduced the full encrypt/decrypt flow in code.
Anti-Bot Signature Generator
ConfidentialReplicated device attestation and anti-bot signatures so client automation could pass server-side integrity checks — turning a hard-blocked endpoint into a stable, scriptable API.
Skills
Education
University of the Punjab
Bachelor of Computer Science (CGPA 3.80 / 4.00)
2017 – 2021
Punjab College
Intermediate in Computer Science (ICS)
2015 – 2017
Certifications
Android Reverse Engineering & Malware Analysis
Udemy · 2023
Frida & Dynamic Instrumentation for Mobile
Udemy · 2022
Object Oriented Programming (C++)
Soft Solutions · 2017
Languages
English · Urdu