What challenges did the client face, and why were they critical?
The bank was observing a growing risk of fraud carried out using mobile malware. Customer devices were infected, among other ways, through the installation of fake applications, smishing campaigns, and downloading applications from outside official app stores.
Incident analysis showed that device infection often preceded a fraud attempt by several hours or even days. During this time, the malware remained inactive or carried out preparatory activities, creating a period of apparent silence that cybercriminals used to launch an attack when the customer was least vigilant. At the same time, criminals were constantly creating new or modified variants of malicious software.
As a result, new samples emerged that had not yet been described in IOC databases and could evade detection based solely on signatures. The bank needed a solution that would, on the one hand, identify known malware campaigns and, on the other, detect new threats and enable protective measures before a fraud attempt was made.
Key challenges
- rapid changes in malicious software that outpaced the bank’s ability to manually update detection rules in signature databases.
- distributed sources of intelligence and organizational silos, with the SOC, anti-fraud, and mobile application teams working with separate data sets.
- lack of context from the device environment, making it impossible to assess whether an apparently legitimate transaction was being performed in an environment showing signs of infection.
- delayed response, insufficient prevention, and a lack of immediate, real-time customer protection.
- the need for a clear operational signal that the bank could use to perform additional verification or to restrict or suspend a transaction.
What did we implement, and how did it work in practice?
Two cooperating security layers were implemented and incorporated into a single decision-making process. The first layer was Android Malware Threat Intelligence (AMTI), which supplied the bank’s platforms with up-to-date, comprehensive intelligence on signatures, campaigns, and IOCs, allowing alerts to be automatically correlated with ongoing attacks. This intelligence is continuously developed and updated by the PREBYTES SIRT team based on daily threat analysis and the handling of real security incidents.
The second layer was the AntiMalware for Mobile library embedded in the application, which dynamically assessed the risk level on the customer’s device by analyzing symptoms characteristic of malicious software activity. This made it possible to detect new or modified malware variants that had not yet been described in signature databases.
Based on signals from the library and insights from AMTI, the bank implemented flexible response scenarios – from enhanced session monitoring and additional authentication to suspending high-value transactions to new beneficiaries in high-risk cases. This approach supports compliance with DORA and NIS2 requirements for ICT risk management, threat detection, incident response, and strengthened operational resilience.
What were the results, and what changed in day-to-day operations?
The way cyber threat intelligence was used changed completely. It was no longer treated solely as retrospective, “after-the-fact” knowledge, but became an input supporting the bank’s decision-making before a transaction was executed.Instead of relying exclusively on the identification of known applications installed on the device, the system dynamically assessed whether there were indications that the customer might be at risk at that specific moment.
The implementation shifted the bank’s response from containing incidents or analysing losses to deep, automated prevention, making optimal use of the time window between device infection and the actual execution of fraudulent activity.On this basis, the bank established a continuous, structured process that correlates criminal campaigns, smartphone-based detection, authentication decisions, and defensive mechanisms within a single, coherent workflow jointly managed by the SOC and anti-fraud teams.
Results after implementation:
- significantly broader detection coverage for extensively modified malware variants and new campaigns without known signatures;
- an increase of more than 30% in the effectiveness of detecting high-risk transactions before authorization, achieved by combining malware campaign intelligence with the security context of the customer’s device;
- operationalization of activities through the direct integration of data and reports, including feeds and indicators of compromise, into the bank’s protection and decision-making processes;
- greater selectivity through the adjustment of the anti-fraud response to the strength of the signal, for example by applying minimally intrusive measures to low-level alerts;
- improved incident analysis between teams working with standardized data, as well as the release of time previously spent on manual processes and handling customer complaints.
Do you have any questions after reading the case study? Contact us.