Well, it totally depends:
If somebody is just a "script kiddy", using cheap browser emulations and publicly available Python/PHP scripts. And if somebody has no clue about reverse engineering, SSL unpinning, tools like WireShark, traffic inspection, decryption and the disassembling of native...