NEWS
LexisNexis and Promon Pair Up to Catch Mobile Fraud Inside the App
LexisNexis Risk Solutions and Promon have allied to pair ThreatMetrix with Promon Shield under one decisioning platform, targeting six mobile attack types.
LexisNexis Risk Solutions and Promon announced a strategic alliance this week to pair LexisNexis ThreatMetrix identity intelligence with Promon Shield runtime telemetry under one fraud decisioning platform. The combination targets six mobile app attack categories that pure identity checks have struggled to catch, including tampering, malware, overlay manipulation, device tampering, reverse engineering and automated abuse. Promon’s release on the alliance and the LexisNexis press release on the alliance both confirm the Dynamic Decision Platform as the integration point.
Mobile fraud has migrated inside the app itself, where screen-overlay attacks, banking trojans and code-injection tools operate beneath the network signals most fraud platforms were built to read. The LexisNexis-Promon alliance puts both layers, identity intelligence and runtime app telemetry, inside one decisioning flow.
What LexisNexis and Promon Are Now Bundling
The alliance fuses two product lines that have lived in different stacks until now. Promon brings Promon Shield and Promon Insight, an in-app protection layer and a runtime telemetry feed that together harden mobile applications against tampering, malware and reverse engineering. LexisNexis ThreatMetrix brings the digital identity intelligence, device signals and behavioural attributes that already evaluate users across the LexisNexis Risk Intelligence Network.
The two product lines meet on the LexisNexis Dynamic Decision Platform, which orchestrates the combined capabilities for real-time fraud decisions. Promon Shield and Promon Insight stay where they are, embedded in the application at runtime, and ThreatMetrix stays where it is, evaluating identity and risk on the network side. What changes is that tamper-resistant telemetry from inside the app can now feed the same decision flow as identity signals from outside it. The companies state the combined stack covers billions of app installations and digital identities worldwide.
Promon has always believed that strong mobile security is a critical foundation for digital trust. As fraud increasingly targets the mobile app and device environment, organizations need clearer insight into whether each session can be trusted. We are bringing Promon Shield, mobile risk detection, behavioral insights and tamper-resistant telemetry into one of the world’s leading fraud intelligence platforms, helping organizations protect customers, reduce fraud losses and deliver safer mobile experiences.
Daniel Kollberg, chief executive officer at Promon, made the case in the announcement the alliance was built around. Promon’s contribution to the deal is the runtime layer that ThreatMetrix did not previously evaluate, and the Dynamic Decision Platform is where the two stacks meet.

How Mobile Fraud Moved Inside the Application
The six attack categories named in the announcement all sit in the same place: inside or directly against the application and its runtime. A partnership built around browser-traffic identity signals would have led with credential stuffing, account takeover through phishing pages, or fake-front-end websites. The LexisNexis-Promon announcement leads instead with tampering, malware, overlay attacks, device manipulation, reverse engineering and automated abuse.
Identity alone is no longer enough when attackers have moved into the runtime. Screen-overlay attacks can sit on top of a legitimate banking app and harvest credentials while the user looks at the real interface. Code-injection tools can rewrite what the app does after it has been installed and started. Device tampering and root-level access can strip out the controls the application is trying to enforce, and organisations whose fraud stack was built around user identity, device fingerprinting and behavioural biometrics now face attackers operating beneath all three layers.
The shift is captured in the announcement’s own framing. Grayson Clarke, chief commercial officer at LexisNexis Risk Solutions, said in the release that fraud prevention is increasingly dependent on understanding the full context of a digital interaction. That phrase, the full context of a digital interaction, is the strategic thesis underneath the deal: identity alone no longer carries enough signal when an attacker has moved into the runtime.
The LexisNexis-Promon announcement is not the only place this shift has surfaced. A related look at the six mobile attack types named in the alliance cross-checks the announcement against the source, and Promon’s own glossary explains how application shielding works in practice as a layered defence that modifies source, byte or binary code to resist intrusion, tampering, reverse engineering and malware attacks.
Where Promon’s Runtime Layer Meets ThreatMetrix
Each side keeps its job; the alliance does not replace either product. Promon Shield runs inside the compiled application at runtime, protecting its code and behaviour against tampering, malware, overlay attacks, device manipulation, reverse engineering and automated abuse. Promon Insight adds trusted telemetry from inside the protected app, surfacing what is happening at runtime in a stream the fraud platform can ingest.
ThreatMetrix brings the network-side layer: digital identity intelligence, device fingerprinting, behavioural attributes and a global view of how an identity has behaved across channels and sessions. LexisNexis Risk Intelligence Network is the wider data set ThreatMetrix draws from, and it is what allows the platform to recognise that a returning user on a familiar device in a familiar location is one thing, while the same identity showing up on a freshly rooted device with a fresh install is another. The Dynamic Decision Platform is the meeting point where Promon’s runtime telemetry lands alongside ThreatMetrix’s identity signals and the platform produces a single decision. The arrangement is integration, not replacement: organisations that already run ThreatMetrix can plug Promon’s signals into the same flow without standing up a parallel fraud stack. Decisioning happens in real time, inside the same clock a mobile login or transfer is operating on.
Promon’s own glossary describes how application shielding fits into that architecture, including anti-tampering, code obfuscation, encryption and runtime application self-protection. The point of the integration is to combine app-level protection and identity intelligence in one stack, instead of handling them as separate decisions after the fact. Organisations already running ThreatMetrix can extend coverage to the application runtime through the Dynamic Decision Platform rather than introducing a parallel fraud engine.
| Capability | Promon Shield and Promon Insight | LexisNexis ThreatMetrix |
|---|---|---|
| Layer protected | Inside the mobile application at runtime | User identity across digital channels |
| What it provides | In-app protection and trusted telemetry | Digital identity intelligence and risk decisioning |
| Signals used | Tamper-resistant telemetry from app runtime | Device, behavioural and identity attributes |
The Industries the Alliance Targets, and the Scale Behind It
The alliance targets the industries where mobile trust is already mission-critical. Financial services, payments, insurance, healthcare and digital banking are the sectors the two companies name together in the announcement as the primary served verticals.
Both sides bring scale that the other did not previously have. Promon operates across 500+ enterprise clients and protects more than 13 billion transactions a month, per third-party reporting on the company’s footprint. LexisNexis Risk Solutions serves customers in more than 190 countries and territories and is part of RELX, the parent group listed in London and New York. The combined stack lands inside an existing customer base that already extends from global banks to regional insurers, with Promon’s announcement framing the use case as organisations protecting sensitive digital services while preserving a smooth user experience. For app developers and security teams, one path now connects the application runtime to the fraud decision without a parallel stack.
- Financial services
- Payments
- Insurance
- Healthcare
- Digital banking
The 2026 Mobile Fraud Context Driving the Alliance
The Zimperium 2026 Banking Heist Report identified 34 active Android banking malware families targeting 1,243 financial institutions across 90 countries throughout 2025. The same report found a 67% year-over-year increase in Android malware-driven financial transactions and a 50% year-over-year increase in the use of Trojans in attacks. Banking trojan installation packages surged to 255,090 across 2025 according to Kaspersky’s full-year mobile threat report, with Kaspersky’s Q3 2025 reporting 47 million Android attacks blocked in that quarter alone. Those numbers sit behind the six attack categories the announcement names.
Android absorbs the bulk of mobile malware volume. Kaspersky’s full-year 2025 report documented 14,059,465 total Android malware and adware attacks blocked throughout the year, with new malicious installation packages running into six figures. Google Play Protect identified 27 million malicious sideloaded apps in 2025 according to Google’s own security blog, up from 13 million the year before, and the platform still faces 90 exploited zero-day vulnerabilities across the period.
iOS faces a different threat profile. Lookout recorded a 26% phishing encounter rate on iOS devices versus 12% on Android in 2024, roughly twice the exposure, while native iOS malware stayed rare because of App Store controls and restricted sideloading. The split is now structural rather than incidental, and attackers have been observed targeting iOS users with phishing pages while running malware campaigns against Android users inside the same operation. The LexisNexis-Promon alliance does not break that split apart, but it does move the application-layer defence closer to the point where either platform’s users sit.
- 14,059,465 total Android malware and adware attacks blocked in 2025 (Kaspersky)
- 255,090 banking trojan installation packages detected in 2025 (Kaspersky)
- 34 active Android banking malware families targeting 1,243 financial apps across 90 countries (Zimperium)
- 67% year-over-year increase in Android malware-driven financial transactions (Zimperium)
- 27 million malicious sideloaded apps identified in 2025 (Google)
Frequently Asked Questions
What does the LexisNexis and Promon partnership combine?
The alliance pairs Promon Shield and Promon Insight, which provide in-app protection and trusted telemetry from inside the running application, with LexisNexis ThreatMetrix, which contributes digital identity intelligence and risk decisioning. The LexisNexis Dynamic Decision Platform is the orchestration layer where both products meet, and organisations keep using either vendor’s existing stack while feeding both into the same decision.
Which attack categories does the alliance target?
The announcement names six: tampering, malware, overlay manipulation, device tampering, reverse engineering and automated abuse. All six happen inside or directly against the application and its runtime, the category of attack identity-only defences have struggled to see.
How are Promon Shield and ThreatMetrix positioned differently?
Promon Shield sits inside the mobile application at runtime, protecting its code and behaviour and surfacing tamper-resistant telemetry. ThreatMetrix evaluates digital identity across channels and contributes identity, device and behavioural signals from the network side. The Dynamic Decision Platform fuses the two signal streams into a single fraud decision in real time.
Where will the joint stack land first?
The alliance is positioned around financial services, payments, insurance, healthcare and digital banking, with both companies’ customer bases already covering large brands in those sectors. Promon reports 500+ enterprise clients and more than 13 billion transactions protected a month, while LexisNexis Risk Solutions serves customers in more than 190 countries and territories and is part of RELX.
-
AI3 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
APPS1 month agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
CRYPTO1 month agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
