GDA is a Dalvik bytecode decompiler and Android analysis tool
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, data decryption, and encryption, etc.
At a glance
- What is it?
- GDA (GJoy Dex Analyzer) is a C++ Dalvik bytecode decompiler and reverse analysis platform for APK, DEX, ODEX, OAT, JAR, class, and AAR files, with malware behavior, privacy, and vulnerability analysis.
- Who is it for?
- GDA (GJoy Dex Analyzer) is a C++ Dalvik bytecode decompiler and reverse analysis platform for Android APK, DEX, ODEX, OAT, JAR, class, and AAR files. It runs without a Java VM, decompiles samples quickly, and adds defensive analysis features such as malicious behavior detection, privacy leaking detection, a static vulnerability scanner, and taint analysis.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 175 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What GDA is and the files it handles
GDA stands for GJoy Dex Analyzer. The README describes it as a powerful Dalvik bytecode decompiler implemented in C++ with fast analysis and low memory and disk use, and a strong ability to decompile APK, DEX, ODEX, OAT, JAR, class, and AAR files. Dalvik bytecode is the format Android applications run in, so a decompiler turns that low-level code back into a readable form for study. GDA is presented as both a decompiler and a broader reverse analysis platform for examining Android software. Because it is native and written in C++, the tool avoids the overhead of a managed runtime, which the README connects to its low memory and disk use.
Decompilation without a Java VM
GDA is completely native software that runs without any setup and without a Java virtual machine. The README states it works in any recent Windows system and in virtual machine systems with no extra configuration. That matters for analysis work because the tool can be dropped onto a clean machine and used right away, which is useful when triaging a suspicious sample. The project began in 2013 and released version 1.0 in 2015 on the GDA website, so it has a long history of Android-focused analysis. A virtual machine system is noted as a supported place to run it, which fits a separated environment used for safe analysis.
Malware and privacy behavior analysis
For defensive research, GDA lists features aimed at understanding what an app does. The README names malicious behavior detection, privacy leaking detection, and sensitive information extraction among its capabilities. Malicious behavior scanning works by following API chains, which means it traces how the app reaches sensitive actions through the Android API. Privacy leaking detection and sensitive information extraction help an analyst see where personal data might leave the app. These are analysis features used to review apps for unsafe or unexpected behavior, which is the core of defensive mobile security work.
Vulnerability scanning and taint analysis
The README describes a static vulnerability scanner based on a stack state machine and a dynamic rule interpreter, and a separate static vulnerability scanner listed under assisted-analysis utilities. Taint analysis appears twice: one mode previews the behavior of variables, and another traces variables back to their source. Taint analysis is a static technique that follows how data flows through a program, so an analyst can see whether untrusted input reaches a sensitive sink. These scanners support reviewing an app for weaknesses without running it on a device, which lets an analyst study a sample that might be unsafe to execute.
Interactive analysis features
GDA offers interactive features that help an analyst move through a sample. The README lists cross-references for strings, classes, methods, and fields; searching across those elements; comments on Java code; and renaming of methods, fields, and classes to make the recovered code easier to read. Results can be saved in a GDA database file. Deobfuscation, packer recognition, multi-DEX support, and a call-graph view help with apps that were protected or split across files. Deep URL extraction and association of permissions with modules add context for triage. The README also lists lower-level features such as a dual decompiler mode and smali instruction patching, though the documented strengths center on analysis.
Running GDA in GUI and CLI modes
GDA runs in two modes. In GUI mode you drag a file onto the window and analysis starts. In CLI mode the tool exposes options for headless work on a sample. The README shows the command line options that focus on analysis tasks such as the package name, the attack surface, packer detection, certificate information, and full decompilation:
>gda.exe
-sh src_file --> start a Shell
-sv src_file port --> start a Server
-h --> help
------------------------------------------------------------
>gda.exe -h
Usage:gda.exe [option] [apk_file] [-o output_file]
option:
-h help
-x show AndroidManifest.xml
-p app package name
-P permission
-i apk base info
-a attack surface
-k packer
-s all the strings
-S referenced strings
-c cert information
-d decompile all code
------------------------------------------------------------
>gda.exe -sv text.apk 12345
File Loading...
GDA Server listening on port 12345...
>client_gda.py helpThe -p, -a, -k, and -d flags map to reading the package name, the attack surface, packer detection, and decompiling all code, which are the kinds of checks an analyst runs during review.
Platform support and the false positive note
The README states GDA runs only on Windows and needs no installation beyond opening the binary. It also carries a false positive note: GDA is protected by an authorized VMProtect, which can trigger warnings in some antivirus tools, and the README states the program has no malicious behavior. Embedded helpers such as ADB and a memory dump tool, plus vulnerability rules and taint rules, account for the extra files some scanners flag. For analysts, this means adding GDA to an allow list is the recommended step before use on a analysis workstation.
Editorial conclusion
GDA (GJoy Dex Analyzer) is a C++ Dalvik bytecode decompiler and reverse analysis platform for Android APK, DEX, ODEX, OAT, JAR, class, and AAR files. It runs without a Java VM, decompiles samples quickly, and adds defensive analysis features such as malicious behavior detection, privacy leaking detection, a static vulnerability scanner, and taint analysis. With GUI and CLI modes, packer recognition, and a call-graph view, GDA is built for triaging and reviewing Android software on Windows.
Frequently asked questions
Is it possible to decompile an Android app?
Yes. GDA is described in its README as a Dalvik bytecode decompiler implemented in C++ with a strong ability to decompile APK, DEX, ODEX, OAT, JAR, class, and AAR files. It is a native tool that runs without a Java VM, so decompiling an Android app is one of its core functions.
What tools can I use for reverse engineering Android apps?
GDA is one option. Its README presents it as a reverse analysis platform that, beyond basic decompiling, offers malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, and taint analysis for reviewing Android software.
How can I convert an APK file to source code?
GDA decompiles APK and related files back toward readable source. The README states it is a Dalvik bytecode decompiler with a strong ability to decompile APK, DEX, ODEX, OAT, JAR, class, and AAR files, and the GUI mode starts analysis by dragging a file into the window.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/charles2gan-gda-android-reversing-tool)