Dubai · United Arab Emirates

Security consulting for teams that ship software — mobile, wireless, offensive, and defensive.

Cormorant Cyber is an independent consultancy helping product teams find, understand, and fix security issues across mobile, wireless, and peripheral attack surfaces — with hands-on reversing, malware triage, penetration testing, and blue-team hardening.

Android reverse engineering APK & malware analysis Pentest & blue team Bluetooth / HID / wireless Evidence-preserved work

Capabilities

Services

Focused, hands-on engagements covering the mobile attack surface — from the app layer down to the radio.

Mobile App Security Assessment

Deep technical review of Android applications and their surrounding infrastructure.

  • Android reverse engineering & APK disassembly
  • ADB / Shizuku privileged workflow testing
  • Tamper-resistance & hardening review
  • Actionable findings with fix guidance

Android Malware Triage & Analysis

Determine what a suspicious app actually does — quickly, safely, and with evidence.

  • Static & dynamic malware analysis
  • Behavioral sandbox review of APKs
  • Indicators of compromise (IOC) extraction
  • Plain-language write-ups for stakeholders

Wireless & Bluetooth Security Analysis

Examination of wireless attack surface for devices, peripherals, and IoT products.

  • Bluetooth HCI traffic capture & analysis
  • BLE / wireless protocol review
  • Peripheral & input-device security testing
  • Fix-oriented protocol recommendations

Evidence-Preserved Investigations

Forensically sound examination where chain-of-custody and integrity matter.

  • Evidence-preserved device examination
  • Data recovery & forensic triage
  • Documented, reproducible methodology
  • Defensible reporting

Penetration Testing & Blue Teaming

Full-lifecycle offensive and defensive engagements across network, wireless, and cloud surfaces.

  • Recon, vulnerability scanning & exploitation
  • Post-exploitation, pivoting & C2
  • SIEM, monitoring & network hardening
  • AD / cloud / container security review

HID & Peripheral Security

Trust analysis for keyboards and input devices — the attack surface most hosts take for granted.

  • BLE peripheral identity reconnaissance
  • HID descriptor & report analysis
  • Keystroke-injection & spoofing assessment
  • Verifiable-device design guidance

About

An independent practitioner

Cormorant Cyber is the solo consultancy of Casey Chambers, an Android and mobile security specialist based in Dubai, UAE. Cormorants are coastal birds that dive deep to hunt — the name reflects a working style of going below the surface of an app or device to see what is actually there.

The practice is built on real, reproducible technical capability: Android reverse engineering, APK disassembly, ADB and Shizuku privileged workflows, malware triage, penetration testing and blue teaming, Bluetooth HCI capture, HID and peripheral security research, and evidence-preserved digital investigations — all documented openly in the public research corpus below.

Engagements are direct: one practitioner, no account-manager layer, clear scope, and findings you can act on. Work is available globally, with a base in the UAE timezone.

Research

Open work, public by default

Techniques and tooling developed in client work are published openly so the community can review, reuse, and verify them.

Every project is presented as-is for research and defensive education. Adversarial tooling is published for the blue team — to understand what defenders are up against.

Contact

Let's talk about your mobile attack surface

Whether it's an app you're shipping, a sample you need triaged, or a device you want examined — the first conversation is free and confidential.

Dubai, UAE · Responses within one business day