Skip to content
Who we are

To secure tomorrow’s technology, you must first understand how today’s systems can break.

Zerodroid Labs was formed from deep expertise in mobile, IoT, web, network, and cloud security testing. We practise offensive security as a way of strengthening defences. You cannot protect a system you have never tried to break.

We publish real-world threats, build open-source tools, and contribute to bug bounty programs and the wider security conversation.

What we do

Vulnerability research across platforms

Finding memory-safety and logic flaws in the mobile, IoT, web and network stacks that ship on billions of devices.

Reverse engineering & exploit development

Taking a binary apart to understand what it really does, then proving the impact with working code.

0day discovery & responsible disclosure

Every finding goes to the affected vendor first, with a published timeline once it is fixed.

CTF creation & participation

Building challenges and competing. It is the fastest way to stay sharp on techniques that matter.

Where we work

Security is built on the little details. Let us handle them.

MobileIoT & embeddedWeb applicationsEnterprise networksCloud

How we work

Open knowledge

What we learn gets written down and published. Research kept private helps nobody but us.

Hacker ethics

We report before we publish, we never sell findings, and we only test what we are authorised to test.

Fuzz → Pwn → Repeat

Depth comes from iteration. We go back to the same targets until they give something up.

Disclosure

We report every finding to the affected vendor before publishing. Every advisory on this site carries its full timeline: when we found it, when we reported it, when it was patched, and when we published.

Work with us

Assessments and research engagements.