App & Device Protection

RASP SDK

A secure login does not guarantee a secure session. Banking malware, overlay attacks, and remote access tools operate after authentication — bypassing every control applied at login. This page explains what the threat looks like and how the RASP SDK — Ektar’s runtime app protection SDK — stops it.
 

The attack happens after the customer logs in. Most banks have no defence at that layer.

Banking trojans and malware targeting mobile apps grew 196% in 2024. Once a customer’s device is compromised, fraudsters can intercept credentials, overlay fake screens on top of the banking app, inject fraudulent transactions, or control the device remotely — all while the customer believes they are using their bank’s legitimate app. These attacks are invisible to authentication controls and network-level monitoring.

CBUAE has now mandated that banking sessions be suspended automatically when malware or screen-sharing is detected — a specific, enforceable requirement that most banks currently have no way to meet.

0

Banking malware growth (2024)

anking trojans targeting mobile apps. The customer’s phone has become the primary attack surface.

0 %

Banks with runtime session protection

CBUAE mandates malware-triggered session suspension. Most banks currently have no solution for this.

Real-time

When attacks happen

Overlay and RAT attacks operate during live sessions. Detection must happen in the same timeframe — not during post-session analysis.

Use Cases Addressed

What Banks Need

Fraud no longer waits for a customer to make a mistake. Overlay attacks, remote access trojans, and repackaged app clones now target the device itself — often before a single credential is entered. Banks need real-time, on-device detection that stops these threats at the source and satisfies CBUAA’s session-suspension requirements without added friction for legitimate users.

Overlay attack prevention

Detect fake screens placed on top of the banking app before the customer enters any credentials.

Remote access tool (RAT) blocking
Detect when a fraudster has taken control of the customer’s device and is operating it remotely.
Malware and trojan detection
Identify banking trojans at the device level, even when they run silently in the background.
App integrity assurance
Detect tampered, repackaged, or injected versions of the banking app before they can execute.
CBUAE session suspension compliance
Automatically suspend and alert when malware or screen-sharing is detected, as required by regulation.

What RASP SDK Detects

Device-level threats

Rooted and jailbroken devices — manufacturer security removed; banking app protection undermined

Emulators and device farms — industrial-scale account takeover attempts blocked at the device level

Remote access tools (RATs) — fraudsters controlling the device in real time, invisibly to the customer

Banking malware and trojans — credential theft and OTP interception at the device level

App-level threats

Overlay attacks — fake screens placed on top of the banking app to steal credentials

App tampering and reverse engineering — security controls stripped, vulnerabilities exposed

Runtime injection — transaction values or account numbers altered mid-session

Screen capture and screenshot attacks — session data exfiltrated without the customer’s knowledge

Fake and repackaged banking apps — counterfeit apps distributed to harvest credentials at scale

What Happens When a Threat Is Detected

Automatic Response

The SDK suspends the banking session automatically — before the fraudster can act. The customer sees a generic security prompt. The bank’s fraud team receives an alert. No human decision is required in real time. No customer data is exfiltrated. The threat is neutralised at the point of detection.

CBUAE Notice 3057

Regulatory Alignment

Explicitly requires that banking sessions be suspended when malware or screen-sharing is detected. The RASP SDK implements this requirement precisely. Banks deploying RASP SDK are compliant with this mandate. Banks that do not deploy a runtime protection solution are not.

Integration Notes

Integration

The RASP SDK is distributed as a native library for iOS and Android. It embeds directly into the banking app as part of the build process — no server-side changes required. Typical deployment timeline: 4–6 weeks. Integrates with ekShield for automatic session suspension on malware detection.

Live Deployment

Proven in Production

RASP SDK is live at UAE’s 3rd largest bank, protecting the mobile and online banking experience for 2M+ digital customers. Ektar continues to expand threat detection capabilities in active collaboration with this anchor client.

Get Started Today

Talk to us about (RASP SDK)

This page explains the problem, what the regulation requires, and how Ektar solves it.