Android and iOS

Remote-access tools and mobile transaction security

Code tampering, account abuse, data exposure and client manipulation.

Threats and abuse1 min readEditorial methods

Remote-assistance tools can support legitimate help or participate in fraud. Assess risk from the transaction and user context rather than tool presence alone.

Evaluation approach

Where platform signals indicate screen sharing or device control, consider them during sensitive operations. Explain why additional verification is required.

Application example

For a large transfer to a new recipient, assess remote-control risk alongside account behavior.

Limits and considerations

The presence of a tool does not prove malicious intent. Some users need remote assistance for their work.

A user-initiated operation can still be suspicious

Remote support and screen sharing can be legitimate. The same capabilities can help a fraudster direct a user without altering application integrity. This illustrates a limit of RASP coverage.

Assess transaction context, new recipients and account changes together in high-risk flows. A tool name alone should not trigger an accusation. Clear user information and a safe support route complement the technical signal.

Checks and decisions

  • Define transaction risk
  • Preserve legitimate support
  • Design temporary restrictions

Aim for safe completion of the risky operation rather than a permanent device ban.

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.