DCB Fraud APKs Sleeping Longer

MCP’s fraud investigations team has noticed app malware activation patterns changing over the last 3 years. MCP identifies suspicious apps promoted to users via advertising seen in its Scanner monitoring tool. These apps are downloaded onto mobile devices to replicate the User experience. To a User, the advert and app look normal. More often than not, the app will have 100,000+ downloads and be on a popular app store such as Google.

In early 2019 70% of malware apps downloaded, generated fraud upon immediate download (payment for a service unknown or not consented to by the consumer). The first a User knows of this fraud is when a billed receipt arrives (but this is often suppressed by the app malware) or they see deduction from their mobile bill.

By 2021 this fraud pattern has changed to just 11% fraud generated within 24hrs or upon download. The incubation or sleep time before malware acts or the device is infected is increasingly over longer periods, with 23% now activating after 30 days.

Intel generated from app malware investigations is used to support investment in Shield (MCP’s auto-block anti-fraud tool), ensuring it keeps up with an ever more sophisticated app malware environment.

MCP Insight is a UK-based compliance and fraud monitoring company, specialising in mobile gateway traffic. Our clients include Mobile Operators, Regulators, Aggregators, and Merchants. We’ve been providing solutions to the mobile payments industry across 30 territories for the past six years.

related posts

Why Pakistan’s Consent Directive Signals a New Era of Verifiable Mobile Services

PTA’s recent clarification on explicit prior consent for Value-Added Services marks an important step in the continued evolution of Pakistan’s mobile ecosystem. Consumer protection and sustainable operator revenue are not opposing objectives. They depend on each other. The practical question now facing the industry is not whether consent should be obtained, but how it can be clearly evidenced when disputes arise. As markets mature, the shift moves from policy to proof. Verifiable, structured consent recording is increasingly becoming part of the governance infrastructure that supports long-term stability across the value chain.

Germany’s mVAS and Mobile Payments Market: Why Discipline Is Creating the Next Opportunity

Germany’s mVAS and mobile payments market is often described as complex, heavily regulated, and difficult to enter. In reality, it has been deliberately reshaped. What looks restrictive from the outside is, in fact, a market that chose sustainability over short-term volume. For CSPs willing to operate with transparency, differentiation, and genuine consumer value, Germany is no longer a closed door. It is a proving ground for services built to last.

Self-Regulation in Mobile Payments: Why the Smartest Players Think Beyond Conversions 

Self-regulation is often seen as friction or self-imposed limitation. But in mobile payments markets facing growing scrutiny, it may be one of the few levers left to protect long-term growth. This article explores why thinking beyond conversions isn’t idealism, it’s market survival.