Appdome unveils new mobile bot defense profile for web application firewalls

Appdome, the company protecting mobile businesses, has stated that its AI-Native MobileBOT Defense solution now offers the most comprehensive mobile bot defense profile on the market. With the new release, Appdome now offers full flexibility for mixing and matching where and how to enforce mobile app protections. Mobile businesses can enforce these protections at the client app level, network layer, or a combination of both, Appdome said.

Capable of evaluating 400+ attack vectors in Android and iOS apps, operating systems (OSes), devices, user interfaces and networks, Appdome’s MobileBOT defence profile allows network security teams to not only stop brute force bot and credential stuffing attacks, but also spear phishing, account takeover (ATO), know your customer (KYC) fraud, on-device fraud (ODF), and deepfake threats in real time across account creation, login, password reset, payment and other critical application programming interface (API) endpoints.

“Up until now, mobile bot defense has been about trying to stop brute force bot and credential stuffing attacks and inspecting the mobile device for two to three threat signals,” said Tom Tovar, co-creator and CEO of Appdome.

“This isn’t enough. Mobile brands need to stop brute force attacks, for sure, but they also evaluate mobile device, OS, application, user interface and network level threats before allowing anyone to connect to their APIs.”

Beyond classic brute force bot and credential stuffing attacks launched from bot farms, automated scripts and similar attack vectors, modern bot attacks can also include hyper-targeted ATO attacks that use AI-generated deepfake images, face cloning, liveness spoofing, and mobile Trojans to bypass biometric checks of specific users, Appdome explained. 

These attacks can also be combined with client-side malware to intercept one-time passwords (OTPs), complete Captcha challenges, hijack sessions, and exploit sensitive app flows like login, payment, and password reset. Some bot attacks even weaponise the mobile app itself—evading traditional anti-bot defenses and putting user trust, compliance, and revenue at risk.

With Appdome MobileBOT Defense, network security teams can stop brute force attacks and scan the mobile environment for any sign of deepfakes, social engineering scams, voice cloning, Trojan attacks, voice phishing (vishing), remote access Trojans (RATs), mobile device takeovers, and more before allowing a connection.

Appdome’s AI-Native MobileBOT Defense provides application-level rate limiting to eliminate the risk of weaponised and zombie applications, immutable application fingerprinting using secured client certificates to stop brute force attacks, and provides deep session risk, evaluating up to 400 configurable attack vectors in a single bot defense profile. In contrast, legacy bot defense software development kits (SDKs) aren’t protected in the app, use vulnerable cookies or JSON web tokens (JWTs) to identify apps, and monitor only a few basic threat indicators such as emulators and jailbreak/root, Appdome said. 

“Your bot defense strategy has to take AI into consideration,” said Gil Hartman, founding engineer and Field CTO of Appdome.

“Brute force bot and credential stuffing attacks are one way the attacker guesses the user name and password of the victim. With AI, guessing gets really easy, really fast and your network and API defense have to be able to repel more sophisticated ATO threats.”

Using a single MobileBOT Defense Profile, mobile brands and enterprises can evaluate up to 400+ attack vectors before allowing connections to any API, endpoint, or host. More importantly, network security teams can create separate defense profiles to address the specific threats applicable to each API. For example, network security professionals can evaluate different threats in each bot defense profile for:

- Sign-up and onboarding APIs: Detect the presence of fake users and devices signing up to your service including fake taps, clicks, swipes, gestures as well as fake location and devices.

- Sign-in and password reset APIs: Detect the presence of spyware such as keyloggers, overlay attacks, and activity monitoring, as well as ATO risk from deepfakes, automatic transfer system (ATS) malware and more.

- Payment APIs: Detect the presence of data harvesting and trojan malware, man-in-the-middle (MiTM) attacks, session hijacks, OS compromises, vishing, social engineering scams and more.

“Tailored threat evaluation per API or host across 400+ threat vectors is huge,” said a leading industry analyst. “This level of deep inspection per API allows network security professionals to turn any web application firewall into a mobile fraud fighting machine and get so much more out of their WAFs.”

Appdome said its MobileBOT Defense solution is the only anti-bot solution purpose built for mobile applications, mobile environments and mobile businesses. Specific elements include: 

- App-level rate limiting: Leverages the compute on the mobile device to throttle API requests coming from “noisy,” malware controlled or zombie mobile apps.

- Application fingerprinting: Mutual transport layer security (MTLS) pre-check authenticates the real app during the TLS handshake, allowing network security teams to deny API requests from bot farms, bot scripts and fake applications.

- Extended bot defence profiles: Evaluate session risk across up to 400+ separate threat vectors in mobile devices, OS, applications, user interface and networks to stop targeted ATOs, KYC fraud and on-device fraud on a per API basis.

- Pin to host: Uses Appdome’s secure certificate pinning to validate the authenticity of servers your application is connecting to per API.

- Dynamic API updates: Remotely update protected hosts and endpoints without a new app release.

- Zero-Trust and dynamic threat evaluation: Allows network security professionals to control when threat evaluations are performed.

- Hardened implementation in apps: Delivers tamper-proof anti-bot implementation in Android and iOS apps, free of spoofing, interception and compromise.

- Mobile app compatibility: Works seamlessly with any Android or iOS app.

- No-SDK, no server delivery: Eliminates integration work and infrastructure overhead, accelerating deployment and eliminating engineering work.

- Web application firewall compatibility: Compatible with all industry standard WAFs; no change-outs required.

“To protect Mobile APIs from bot and ATO attacks, you need a bot defense product that is purpose-built for the unique threats and challenges of your mobile app and business,” said Chris Roeckl, Chief Product Officer at Appdome. 

“You also need an anti-bot solution that works with all the web application firewalls you have today and tomorrow, otherwise it just doesn’t work.”

Hashtag: #RSA2025

Comments

Popular posts from this blog

Fortinet enhances FortiRecon to align with CTEM framework

SentinelOne recognised as a 2025 Gartner Peer Insights Customers’ Choice for XDR

AWS: AI adoption grows 20% in Singapore