case study icon

Malware detected, fraud stopped – how do Android Malware Threat Intelligence and AntiMalware for Mobile protect bank customers?

Effective protection against mobile malware combines signature-based detection with dynamic, on-device threat detection. In this case study, we show how these solutions protect a bank and enable it to respond even before a fraud attempt occurs.

Case study cover about fraud detection in banking.

Implementation context

  • Client: a large commercial bank operating in the European market and serving more than 5 million active mobile application users.
  • Area: counteracting malware campaigns targeting Android devices, preventing account takeover (ATO), and reducing transactional fraud.
  • Integration: enriching SIEM/SOC platforms and anti-fraud systems with data from Android Malware Threat Intelligence and implementing the AntiMalware for Mobile library directly in the banking application.
  • Result: correlating intelligence about current threats with a signal indicating malware detection on a customer’s device, enabling earlier action to reduce the risk of fraud.

What challenges did the client face, and why were they critical?

The bank was observing a growing risk of fraud carried out using mobile malware. Customer devices were infected, among other ways, through the installation of fake applications, smishing campaigns, and downloading applications from outside official app stores.

Incident analysis showed that device infection often preceded a fraud attempt by several hours or even days. During this time, the malware remained inactive or carried out preparatory activities, creating a period of apparent silence that cybercriminals used to launch an attack when the customer was least vigilant. At the same time, criminals were constantly creating new or modified variants of malicious software.

As a result, new samples emerged that had not yet been described in IOC databases and could evade detection based solely on signatures. The bank needed a solution that would, on the one hand, identify known malware campaigns and, on the other, detect new threats and enable protective measures before a fraud attempt was made.

Key challenges

  • rapid changes in malicious software that outpaced the bank’s ability to manually update detection rules in signature databases.
  • distributed sources of intelligence and organizational silos, with the SOC, anti-fraud, and mobile application teams working with separate data sets.
  • lack of context from the device environment, making it impossible to assess whether an apparently legitimate transaction was being performed in an environment showing signs of infection.
  • delayed response, insufficient prevention, and a lack of immediate, real-time customer protection.
  • the need for a clear operational signal that the bank could use to perform additional verification or to restrict or suspend a transaction.

What did we implement, and how did it work in practice?

Two cooperating security layers were implemented and incorporated into a single decision-making process. The first layer was Android Malware Threat Intelligence (AMTI), which supplied the bank’s platforms with up-to-date, comprehensive intelligence on signatures, campaigns, and IOCs, allowing alerts to be automatically correlated with ongoing attacks. This intelligence is continuously developed and updated by the PREBYTES SIRT team based on daily threat analysis and the handling of real security incidents.

The second layer was the AntiMalware for Mobile library embedded in the application, which dynamically assessed the risk level on the customer’s device by analyzing symptoms characteristic of malicious software activity. This made it possible to detect new or modified malware variants that had not yet been described in signature databases.

Based on signals from the library and insights from AMTI, the bank implemented flexible response scenarios – from enhanced session monitoring and additional authentication to suspending high-value transactions to new beneficiaries in high-risk cases. This approach supports compliance with DORA and NIS2 requirements for ICT risk management, threat detection, incident response, and strengthened operational resilience.

What were the results, and what changed in day-to-day operations?

The way cyber threat intelligence was used changed completely. It was no longer treated solely as retrospective, “after-the-fact” knowledge, but became an input supporting the bank’s decision-making before a transaction was executed.Instead of relying exclusively on the identification of known applications installed on the device, the system dynamically assessed whether there were indications that the customer might be at risk at that specific moment.

The implementation shifted the bank’s response from containing incidents or analysing losses to deep, automated prevention, making optimal use of the time window between device infection and the actual execution of fraudulent activity.On this basis, the bank established a continuous, structured process that correlates criminal campaigns, smartphone-based detection, authentication decisions, and defensive mechanisms within a single, coherent workflow jointly managed by the SOC and anti-fraud teams.

Results after implementation:

  • significantly broader detection coverage for extensively modified malware variants and new campaigns without known signatures;
  • an increase of more than 30% in the effectiveness of detecting high-risk transactions before authorization, achieved by combining malware campaign intelligence with the security context of the customer’s device;
  • operationalization of activities through the direct integration of data and reports, including feeds and indicators of compromise, into the bank’s protection and decision-making processes;
  • greater selectivity through the adjustment of the anti-fraud response to the strength of the signal, for example by applying minimally intrusive measures to low-level alerts;
  • improved incident analysis between teams working with standardized data, as well as the release of time previously spent on manual processes and handling customer complaints.

Do you have any questions after reading the case study? Contact us.

See more deployments in this industry: Banking
Close window
Get STARTED

Get all of the things today!

Free, no obligation consultation. You can either give us a call, or complete the form if you prefer email.

Via phone
Give us a call and ask, we won’t hassle.

+44 7915-525-434

Let us know how we can reach you

More about a privacy policy can be found here.
Thank you!

Your submission has been received! We will contact you shortly.
Close window
Oops! Something went wrong while submitting the form.
Not now, close window