Connect with us

NEWS

LexisNexis and Promon Pair Up to Catch Mobile Fraud Inside the App

LexisNexis Risk Solutions and Promon have allied to pair ThreatMetrix with Promon Shield under one decisioning platform, targeting six mobile attack types.

Published

on

LexisNexis Risk Solutions and Promon announced a strategic alliance this week to pair LexisNexis ThreatMetrix identity intelligence with Promon Shield runtime telemetry under one fraud decisioning platform. The combination targets six mobile app attack categories that pure identity checks have struggled to catch, including tampering, malware, overlay manipulation, device tampering, reverse engineering and automated abuse. Promon’s release on the alliance and the LexisNexis press release on the alliance both confirm the Dynamic Decision Platform as the integration point.

Mobile fraud has migrated inside the app itself, where screen-overlay attacks, banking trojans and code-injection tools operate beneath the network signals most fraud platforms were built to read. The LexisNexis-Promon alliance puts both layers, identity intelligence and runtime app telemetry, inside one decisioning flow.

What LexisNexis and Promon Are Now Bundling

The alliance fuses two product lines that have lived in different stacks until now. Promon brings Promon Shield and Promon Insight, an in-app protection layer and a runtime telemetry feed that together harden mobile applications against tampering, malware and reverse engineering. LexisNexis ThreatMetrix brings the digital identity intelligence, device signals and behavioural attributes that already evaluate users across the LexisNexis Risk Intelligence Network.

The two product lines meet on the LexisNexis Dynamic Decision Platform, which orchestrates the combined capabilities for real-time fraud decisions. Promon Shield and Promon Insight stay where they are, embedded in the application at runtime, and ThreatMetrix stays where it is, evaluating identity and risk on the network side. What changes is that tamper-resistant telemetry from inside the app can now feed the same decision flow as identity signals from outside it. The companies state the combined stack covers billions of app installations and digital identities worldwide.

Promon has always believed that strong mobile security is a critical foundation for digital trust. As fraud increasingly targets the mobile app and device environment, organizations need clearer insight into whether each session can be trusted. We are bringing Promon Shield, mobile risk detection, behavioral insights and tamper-resistant telemetry into one of the world’s leading fraud intelligence platforms, helping organizations protect customers, reduce fraud losses and deliver safer mobile experiences.

Daniel Kollberg, chief executive officer at Promon, made the case in the announcement the alliance was built around. Promon’s contribution to the deal is the runtime layer that ThreatMetrix did not previously evaluate, and the Dynamic Decision Platform is where the two stacks meet.

How Mobile Fraud Moved Inside the Application

The six attack categories named in the announcement all sit in the same place: inside or directly against the application and its runtime. A partnership built around browser-traffic identity signals would have led with credential stuffing, account takeover through phishing pages, or fake-front-end websites. The LexisNexis-Promon announcement leads instead with tampering, malware, overlay attacks, device manipulation, reverse engineering and automated abuse.

Identity alone is no longer enough when attackers have moved into the runtime. Screen-overlay attacks can sit on top of a legitimate banking app and harvest credentials while the user looks at the real interface. Code-injection tools can rewrite what the app does after it has been installed and started. Device tampering and root-level access can strip out the controls the application is trying to enforce, and organisations whose fraud stack was built around user identity, device fingerprinting and behavioural biometrics now face attackers operating beneath all three layers.

The shift is captured in the announcement’s own framing. Grayson Clarke, chief commercial officer at LexisNexis Risk Solutions, said in the release that fraud prevention is increasingly dependent on understanding the full context of a digital interaction. That phrase, the full context of a digital interaction, is the strategic thesis underneath the deal: identity alone no longer carries enough signal when an attacker has moved into the runtime.

The LexisNexis-Promon announcement is not the only place this shift has surfaced. A related look at the six mobile attack types named in the alliance cross-checks the announcement against the source, and Promon’s own glossary explains how application shielding works in practice as a layered defence that modifies source, byte or binary code to resist intrusion, tampering, reverse engineering and malware attacks.

Where Promon’s Runtime Layer Meets ThreatMetrix

Each side keeps its job; the alliance does not replace either product. Promon Shield runs inside the compiled application at runtime, protecting its code and behaviour against tampering, malware, overlay attacks, device manipulation, reverse engineering and automated abuse. Promon Insight adds trusted telemetry from inside the protected app, surfacing what is happening at runtime in a stream the fraud platform can ingest.

ThreatMetrix brings the network-side layer: digital identity intelligence, device fingerprinting, behavioural attributes and a global view of how an identity has behaved across channels and sessions. LexisNexis Risk Intelligence Network is the wider data set ThreatMetrix draws from, and it is what allows the platform to recognise that a returning user on a familiar device in a familiar location is one thing, while the same identity showing up on a freshly rooted device with a fresh install is another. The Dynamic Decision Platform is the meeting point where Promon’s runtime telemetry lands alongside ThreatMetrix’s identity signals and the platform produces a single decision. The arrangement is integration, not replacement: organisations that already run ThreatMetrix can plug Promon’s signals into the same flow without standing up a parallel fraud stack. Decisioning happens in real time, inside the same clock a mobile login or transfer is operating on.

Promon’s own glossary describes how application shielding fits into that architecture, including anti-tampering, code obfuscation, encryption and runtime application self-protection. The point of the integration is to combine app-level protection and identity intelligence in one stack, instead of handling them as separate decisions after the fact. Organisations already running ThreatMetrix can extend coverage to the application runtime through the Dynamic Decision Platform rather than introducing a parallel fraud engine.

Capability Promon Shield and Promon Insight LexisNexis ThreatMetrix
Layer protected Inside the mobile application at runtime User identity across digital channels
What it provides In-app protection and trusted telemetry Digital identity intelligence and risk decisioning
Signals used Tamper-resistant telemetry from app runtime Device, behavioural and identity attributes

The Industries the Alliance Targets, and the Scale Behind It

The alliance targets the industries where mobile trust is already mission-critical. Financial services, payments, insurance, healthcare and digital banking are the sectors the two companies name together in the announcement as the primary served verticals.

Both sides bring scale that the other did not previously have. Promon operates across 500+ enterprise clients and protects more than 13 billion transactions a month, per third-party reporting on the company’s footprint. LexisNexis Risk Solutions serves customers in more than 190 countries and territories and is part of RELX, the parent group listed in London and New York. The combined stack lands inside an existing customer base that already extends from global banks to regional insurers, with Promon’s announcement framing the use case as organisations protecting sensitive digital services while preserving a smooth user experience. For app developers and security teams, one path now connects the application runtime to the fraud decision without a parallel stack.

  • Financial services
  • Payments
  • Insurance
  • Healthcare
  • Digital banking

The 2026 Mobile Fraud Context Driving the Alliance

The Zimperium 2026 Banking Heist Report identified 34 active Android banking malware families targeting 1,243 financial institutions across 90 countries throughout 2025. The same report found a 67% year-over-year increase in Android malware-driven financial transactions and a 50% year-over-year increase in the use of Trojans in attacks. Banking trojan installation packages surged to 255,090 across 2025 according to Kaspersky’s full-year mobile threat report, with Kaspersky’s Q3 2025 reporting 47 million Android attacks blocked in that quarter alone. Those numbers sit behind the six attack categories the announcement names.

Android absorbs the bulk of mobile malware volume. Kaspersky’s full-year 2025 report documented 14,059,465 total Android malware and adware attacks blocked throughout the year, with new malicious installation packages running into six figures. Google Play Protect identified 27 million malicious sideloaded apps in 2025 according to Google’s own security blog, up from 13 million the year before, and the platform still faces 90 exploited zero-day vulnerabilities across the period.

iOS faces a different threat profile. Lookout recorded a 26% phishing encounter rate on iOS devices versus 12% on Android in 2024, roughly twice the exposure, while native iOS malware stayed rare because of App Store controls and restricted sideloading. The split is now structural rather than incidental, and attackers have been observed targeting iOS users with phishing pages while running malware campaigns against Android users inside the same operation. The LexisNexis-Promon alliance does not break that split apart, but it does move the application-layer defence closer to the point where either platform’s users sit.

  • 14,059,465 total Android malware and adware attacks blocked in 2025 (Kaspersky)
  • 255,090 banking trojan installation packages detected in 2025 (Kaspersky)
  • 34 active Android banking malware families targeting 1,243 financial apps across 90 countries (Zimperium)
  • 67% year-over-year increase in Android malware-driven financial transactions (Zimperium)
  • 27 million malicious sideloaded apps identified in 2025 (Google)

Frequently Asked Questions

What does the LexisNexis and Promon partnership combine?

The alliance pairs Promon Shield and Promon Insight, which provide in-app protection and trusted telemetry from inside the running application, with LexisNexis ThreatMetrix, which contributes digital identity intelligence and risk decisioning. The LexisNexis Dynamic Decision Platform is the orchestration layer where both products meet, and organisations keep using either vendor’s existing stack while feeding both into the same decision.

Which attack categories does the alliance target?

The announcement names six: tampering, malware, overlay manipulation, device tampering, reverse engineering and automated abuse. All six happen inside or directly against the application and its runtime, the category of attack identity-only defences have struggled to see.

How are Promon Shield and ThreatMetrix positioned differently?

Promon Shield sits inside the mobile application at runtime, protecting its code and behaviour and surfacing tamper-resistant telemetry. ThreatMetrix evaluates digital identity across channels and contributes identity, device and behavioural signals from the network side. The Dynamic Decision Platform fuses the two signal streams into a single fraud decision in real time.

Where will the joint stack land first?

The alliance is positioned around financial services, payments, insurance, healthcare and digital banking, with both companies’ customer bases already covering large brands in those sectors. Promon reports 500+ enterprise clients and more than 13 billion transactions protected a month, while LexisNexis Risk Solutions serves customers in more than 190 countries and territories and is part of RELX.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending