Research

Original security research from Ostorlab

Mobile and banking security studies, vulnerabilities we disclosed, what our AI agents found, and the open-source tools we maintain. Every item links to the full write-up or code, so your team can check the details.

Items shown: 26

Original research

Studies of mobile banking apps, vulnerabilities we found and reported, and threat research on banking malware.

Banking report series

Mobile banking security, studied over time

Two editions of our study of mobile banking apps. Read them together to see how protections and common weaknesses evolve.

AI agents at work

Vulnerabilities found by our AI engine during agentic penetration testing, in mobile apps first, then in the APIs behind them.

Techniques

Practical write-ups for mobile security practitioners: obfuscation, instrumentation, reverse engineering and pinning.

Benchmarks and test apps

Deliberately vulnerable apps and benchmarks you can run to evaluate any mobile security tool, including ours.

Open source

Tools we build and maintain in the open.

Plus more than 30 open-source agents, including Nmap, ZAP, Nuclei, Tsunami, OpenVAS, Semgrep and TruffleHog.Browse the agents (opens in a new tab)

See what our research finds in your app

Ostorlab's agentic penetration testing builds on this research to test every release of your mobile app.