ud

Frautect mobile app, fraud protection on Android

An Android security app for Frautect that finds fake, cloned and dangerous apps, keeps watch in the background, and warns people the moment something risky appears.

Year
2025–2026
Type
Android app (company project)
Built with
React Native, Expo, Kotlin, Android foreground services, Firebase, TypeScript

The problem

Fake loan apps, cloned banking and payment apps, and banking trojans that impersonate real apps are a common way people in India get defrauded. Most people never notice what is installed on their own phone, or when a setting quietly changes. Frautect’s app puts a fraud check in their pocket.

How it grew

I started the app at Frautect in July 2025 as an Expo prototype and have built it out since. The first version listed installed apps and showed reported fraud apps and safe alternatives. The current version is a full Android security app with native Kotlin parts.

What it does

  • Finds fake and cloned apps. It scans every installed app and checks each one’s installer and signing certificate against Frautect’s threat database, which catches re-signed copies that look identical to the real app.
  • Background Monitoring. A native Android foreground service warns the moment a risky app is installed or updated. It also watches for device risks: USB debugging turned on, a new accessibility service or device administrator, a proxy, or an open Wi-Fi network. It restarts after a reboot and shows a persistent notification while it runs.
  • Instant warnings. A full-screen alert appears over other apps when a dangerous app is detected, with a one-tap option to uninstall it.
  • Scam reports and link checks. People can report scams with screenshots and verify links that were shared with them.
  • On-device checks. Wi-Fi safety and fake-GPS detection run on the phone itself.
  • Accounts. Sign-in with Google or a one-time email code.

Privacy and Play Store compliance

Because the list of installed apps counts as sensitive data, the app asks for clear consent before it reads or sends anything. I built the first-run consent flow in English and Hindi. It is stored per account and versioned, nothing is scanned without a yes, and consent can be withdrawn in settings at any time. Optional permissions each get their own short explanation before Android asks for them.

How it is built

LayerChoice
AppReact Native with Expo and Expo Router, TypeScript
Native AndroidKotlin modules and a foreground service for background monitoring
Device dataInstalled apps, installers and signing certificates; my npm package came out of this work
Accounts and analyticsGoogle sign-in, email one-time codes, Firebase
LanguagesEnglish and Hindi