Guardsquare published research and supporting code showing that reverse engineering Flutter applications is feasible despite Dart obfuscation and limited tooling. The work details methods for recovering meaning from compiled Flutter binaries, including renaming obfuscated Dart functions and improving decompilation workflows with reFlutter, Frida, and IDA Pro. Guardsquare also released a demonstration repository containing sample obfuscated and non-obfuscated app artifacts, memory-dump processing scripts, and IDA Python utilities to import data, create Dart objects, add cross-references, and improve decompiled output, while warning that some stack-pointer patching can produce incorrect code in functions using both X15 and SP.
The research aligns with the availability of Doldrums, an open-source Flutter/Dart reverse engineering tool for Android that parses the libapp.so binary and extracts class information from Dart isolate snapshots. Doldrums, described as beta software for Dart 2.10 releases, can dump class definitions and absolute code offsets for native functions, helping analysts inspect Flutter Android applications even though some deserialization routines and class metadata remain incomplete. Together, the publications and tools show a maturing ecosystem for analyzing Flutter binaries and reducing the barriers to inspecting protected mobile apps.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Guardsquare published a GitHub repository with scripts, sample files, and instructions to reproduce experiments on reverse engineering Flutter applications. The repository covers renaming obfuscated Dart functions and improving Dart decompilation workflows using tools such as reFlutter, Frida, and IDA Pro.
Guardsquare published a blog post on the current state and future of reversing Flutter apps. The reference identifies it as a Flutter reverse engineering and decompiler guide.
A GitHub repository for Doldrums was published, describing a beta tool that parses Flutter Android libapp.so files and dumps Dart classes from isolate snapshots. The repository states support for Dart 2.10 releases and notes missing deserialization routines and some class information.
A blog post titled "Reverse engineering Flutter for Android - A Moment of Insanity" was published, documenting work-in-progress research into reversing Flutter Android applications. It predates the existing 2022 timeline entries on Flutter reverse engineering tooling and guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceguardsquare.com
Open sourcegithub.com
Open sourcerloura.wordpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.