Skip to content
Malware analysis

Mobile malware analysis sandbox for iOS and Android, with AI agents

Run suspicious apps on observable virtual iOS and Android devices you can revert to a snapshot. Watch what they do, keep the evidence, and let AI agents handle the interaction and evidence capture.

Built for defensive threat research: a mobile malware analysis sandbox where every run starts clean and can be repeated from the same starting point.

Access is reviewed. Defensive use only.
Illustrative virtual device used to observe a fictional sample.
Illustrative example: a fictional sample on a virtual device, with one observation.
Sample: demo-sample-07 (fictional)
Network
3 destinations
Files
12 changes
Permissions
2 requested
Screens
9 captured

Why mobile malware is hard to analyse

The sample is rarely the hard part. The environment is.

iOS is locked down.

iOS malware analysis needs a level of access that ordinary phones don’t give you.

Analysis phones are scarce and hard to trust.

Physical devices are slow to reset, and reusing one after a suspicious sample is a risk in itself.

Behaviour hides behind interaction.

Many samples show nothing until someone signs up, taps through prompts or uses the app for a while.

Evidence is scattered.

Files, traffic, logs and screens all tell part of the story. An Android malware sandbox that covers only one of them leaves you stitching the rest together by hand.

Observable by design

The first question is “what does it do?” The sandbox is built to show you, then return to a clean snapshot.

Samples run on virtual devices, not on your real phones or your workstation. Network traffic is monitored during analysis runs, and every run can start from a clean snapshot and return to it afterwards. Network controls are a requirement to discuss: ask us in the demo, and see our security page for the questions to raise.

  • Virtual devices, separate from your real devices
  • Network traffic monitored during analysis runs
  • Revert to a clean snapshot after each run
Security and data handling
Conceptual analysis context linking a virtual device with traffic observations and a snapshot reference.
Analysis context: the virtual device, the traffic observations taken from it and a snapshot reference. A concept view, not a diagram of isolation controls.

What you can observe in a mobile malware analysis

Six views of one run, for static and dynamic analysis side by side.

01

Runtime behaviour.

What the app starts, accesses and asks for while it runs.

02

Files and data.

What it writes, changes or reads on the device.

03

Network traffic.

Network traffic monitoring shows where the app connects and what it sends.

04

System activity.

Process and system-level activity, down to the kernel.

05

Screens.

What a user would have seen at each point of the run.

06

The app package.

Inspect the package with your own static tools alongside the dynamic runs.

Platform overview

How an analysis runs

Five stages of mobile malware analysis, from clean device to report.

Each stage is an outcome, not a procedure. Because the device is virtual, the whole run can be repeated from the same starting point.

Sample-analysis workflow from a prepared baseline to interaction, observations and review.
  1. Prepare
  2. Load sample
  3. Interact
  4. Observe
  5. Review
Prepare a baseline, load the sample, interact with it, observe and review. A dotted path from Review back to Prepare means a new experiment from the baseline.
  1. Start clean.

    A fresh iOS or Android virtual device starts from a known snapshot, so nothing left over from a previous run skews the result.

  2. Load the sample.

    Bring in the app under analysis without touching a real phone.

  3. Interact like a user.

    An agent, or an analyst, uses the app the way a target would, so behaviour that waits for interaction has a chance to appear.

  4. Collect the evidence.

    Behaviour, traffic, file changes and screens are gathered from the same run.

  5. Report, rewind, rerun.

    Get a draft report, then roll back and run again under different conditions.

AI agents that play the victim

Some samples only show their hand to a user. The agent can be that user.

recuritylab has an MCP server and an API built in, so an AI agent can operate the virtual device: tap through onboarding, answer permission prompts, and use the app the way a target would. That interaction is what makes automated malware analysis useful on mobile. You give the brief in plain language:

“Open the app, go through setup as a new user, use it for five minutes, and summarise every network destination and permission it asked for.”

The agent runs the session, collects the evidence and drafts the analysis summary. The analyst reviews it, digs further where it matters, and draws the conclusions.

The agent

  • user-like interaction
  • evidence capture
  • first-pass summary

The analyst

  • interpretation
  • classification
  • response and reporting
How the agents work
you ▸ set up as a new user, use for 5 min, list destinationsagent ▸ restore snapshot "clean-android"agent ▸ open demo-sample-07 · complete onboardingagent ▸ permission prompt: contacts · granted for analysis● network capture runningagent ▸ 3 destinations: cdn.example.com, api.example.net, 192.0.2.44agent ▸ 2 permissions requested · 9 screens capturedagent ▸ draft summary ready for review
Illustrative session with a fictional sample and reserved example domains and addresses.

Evidence and reporting

One report your detection and response teams can use.

Each run produces a draft malware analysis report that brings the evidence together: a behaviour summary, network destinations, file and data changes and screenshots, for your analysts to review before it feeds detection and response work. The report references the snapshot behind the run; how long snapshots and results are kept is something we agree with you. Need indicators in a particular format, or the output in the tools you already use? Ask us.

  • Behaviour summary and network destinations
  • File and data changes, with screenshots
  • Indicator formats and exports: ask us
  • A snapshot reference for each run
Illustrative sample-analysis draft containing behavior notes, fictional network observations and a snapshot reference.
Illustrative draft for a fictional sample: behaviour notes, a network observation for the reserved domain example.com and a snapshot reference, waiting for analyst review.

Who uses it

Teams that need to know what a mobile app really does.

Threat intelligence teams.

Mobile threat research on iOS and Android samples, with evidence you can share internally.

SOC and incident response.

Analyse the app behind a mobile incident without risking another device.

Mobile security vendors.

Validate that detections fire on the behaviour they are meant to catch.

Investigators protecting at-risk users.

Mobile spyware analysis on behalf of journalists, NGOs and others at risk, always with the consent of the device owner.

Testing apps your own organisation builds? See app pentesting. Training analysts? See training.

Physical-device sandboxes vs virtual devices

Where a virtual malware sandbox fits.

Physical phones give real hardware but are slow to reset and hard to scale. An emulator-based sandbox scales well but covers Android only. The table compares categories, not vendors.

iOS coverageAndroid coverageReset to a clean stateParallel runsUser-like interactionDeep system visibility
Physical analysis phonesYes, with the right devicesYes, with the right devicesManual and slowLimited by hardwareManual or scriptedDepends on access level
Emulator-based Android sandboxesNoYesYesYesScriptedVaries
recuritylab virtual devicesYesYesSnapshotsAsk usAI agents + MCPSystem and kernel introspection
Detailed comparisons

Deployment and data handling

Many threat teams can’t send samples to a shared cloud. recuritylab offers flexible deployment options — ask us. Tell us where samples and artifacts must stay, and we’ll discuss the setup that meets that requirement.

Security

Defensive use only

recuritylab is for analysing threats in order to protect users and organisations. Every account starts with a demo and a review of the request, samples are handled under our acceptable use policy, and the platform may not be used to develop, improve or distribute malware. We may decline requests that don’t fit.

Acceptable use policy

FAQ

What is a mobile malware analysis sandbox for iOS and Android?

It is an observable environment where a suspicious mobile app runs on a virtual device instead of a real phone, and the device can be reverted to a snapshot afterwards. recuritylab provides virtual iOS and Android devices for this, with snapshots to start every run clean, visibility into behaviour, files, traffic and system activity, and AI agents that interact with the app and draft the report.

Can I analyse iOS malware without a physical iPhone?

Yes. Analysis runs on virtual iOS devices with the access level analysis requires, so you don’t need to source, prepare or reset physical iPhones.

Does it support Android too?

Yes. iOS and Android samples run on the same platform, with the same snapshots, agents, evidence collection and reports.

Is the sample isolated from my network?

Samples run on virtual devices, separate from your real devices, with their network traffic monitored, and every run can start from a clean snapshot. Network controls and deployment depend on your policy and need confirmation for your setup: ask us in the demo, and see our security page for the questions to raise.

What does the report include?

A draft with a behaviour summary, network destinations, file and data changes and screenshots, plus a reference to the snapshot behind the run. Ask us about indicator formats, how long results are kept, and exporting them to the tools you already use.

Can AI agents interact with the app like a user?

Yes. Agents operate the device over the built-in MCP server or the API: they go through onboarding, respond to prompts and use the app as a target would, then summarise what happened. An analyst reviews the result and draws the conclusions.

How do I get access?

Book a demo. Every request is reviewed, and use is governed by our acceptable use policy. There is no self-serve signup and no published pricing.

See what a suspicious app really does, on a device you can revert

Access is on request and set up after a demo. We don’t publish pricing.

Book a demo