What it looks like when your fraud team, not your release schedule, sets the pace of your response.
When a fraud team identifies a new banking trojan targeting their app, the risk sits in the time between spotting it and responding to it on users’ devices. If extending detection depends on the next app release, that time is measured in weeks.
This month, we’re introducing DexProtector 16.1.113, with stronger Runtime Engine protection on Android, performance improvements for Flutter applications, and better compatibility for protected frameworks on iOS.
We then follow a bank’s fraud team as they investigate unfamiliar malware samples, add detection rules in Alice, and apply an approved response on the device through over-the-air (OTA) updates, without waiting for a new release.
What's new with Licel's solutions?
What’s new in this month’s DexProtector releases?
Stronger Runtime Engine protection on Android.
New internal safeguards increase resistance to tampering and analysis, reinforcing the engine that delivers protection inside the application.
Better performance for Flutter applications.
Applications that use Native Library Encryption with large Flutter binaries benefit from performance improvements.
Improved iOS compatibility and network checks.
Protected frameworks work more reliably when loaded in extension processes, while Public Key Pinning and Certificate Transparency checks benefit from performance improvements.
Runtime protection is one side of the picture. The other is how quickly your team can respond when a new threat appears.
From investigation to on-device response
A bank’s fraud team identifies several unfamiliar Android packages during an investigation. Using their own tools, including AI to support sample analysis, the analysts validate the evidence and confirm remote access, overlay, and keylogging capabilities in one sample. The banking app already uses DexProtector, and the team wants to extend detection to these newly identified threats.
With Extended Anti-Malware and the custom malware database integration already in place, the team adds the new samples in Alice under a Report policy. Alice delivers the approved database updates OTA to connected apps, extending detection without a new app release. The team then reviews detections alongside fraud cases to assess exposure and decide where stronger responses are justified.
Accessibility services provide another part of the picture. DexProtector detects enabled untrusted accessibility services, including those provided by apps not yet classified as malware. Banking trojans can abuse these capabilities to read screen content or automate taps. The team investigates these findings while accounting for legitimate assistive tools: an accessibility finding alone does not establish malicious behavior.
After reviewing the evidence, the team moves confirmed malware samples into a Report+Close category. Alice delivers the approved update, and DexProtector applies the response on the device: detecting the identified package, reporting it to Alice, and closing the protected banking app. The team verifies the response on a test device and manages accessibility policies separately.
The investigation also informs backend fraud decisions and a review of complementary Data Leakage Prevention controls. With the integration already deployed, the bank’s own fraud team has moved from investigation to an updated on-device response, without waiting for a new application release.
From the Alice data: We see reports from devices with more than one installed application identified as malware or a potentially harmful application (PHA). Reviewing all findings helps teams avoid overlooking another relevant app while investigating the first.
Explore the new DexProtector page
We've refreshed the DexProtector page to show how its protections work together, from application hardening and runtime protection to malware detection, Data Leakage Prevention, and Mobile API Protection, with links to the technical documentation for your next steps.
Whether you're reviewing an existing configuration or planning a new deployment, the page provides a clear starting point for protecting your applications and their users.
Meet us in Edinburgh
We’ll be exhibiting at the PCI SSC Europe Community Meeting in Edinburgh International Conference Centre, from 20-22 October. If you’re attending, come and talk to us at stand 29 and find out how payment apps can respond to new mobile threats without having to wait for the next release.
Thanks for reading this edition of the Licel Layers Bulletin. We'll be back next month with more product improvement updates and threat intelligence insights.