ThreatFabric
ThreatFabric is an Amsterdam-based mobile threat intelligence and fraud detection company whose SDK and research team track banking malware, scams, and account-takeover attacks for financial institutions.
Visit Website ↗ + Add to CompareOverview
ThreatFabric was founded in Amsterdam in 2015 by a group of malware researchers and has built its business around a specific, narrow observation: most large-scale mobile banking fraud is driven by a relatively small number of malware families and campaign infrastructures that get reused and re-packaged across targets. The company’s in-house intelligence team tracks these families — banking trojans, remote access trojans (RATs), overlay/accessibility-abuse malware, and increasingly scam and social-engineering campaigns — and feeds that intelligence into a Mobile Threat Intelligence (MTI) research feed and a client-side Fraud Risk Suite (FRS) SDK that banks and fintechs embed in their mobile apps.
The SDK approach lets ThreatFabric detect device-level compromise signals (overlay attacks, screen-sharing/remote-access abuse, malware presence) at the point of a transaction, rather than relying purely on post-hoc transaction-pattern analysis. That is the company’s core differentiation versus generic fraud-scoring platforms: it combines device telemetry with a threat-research function that is actively hunting new malware families, rather than only reacting to fraud patterns after losses occur.
ThreatFabric has grown steadily rather than explosively — around $12.6M in disclosed funding over several small rounds, roughly 56-57 employees, and backing that now includes a strategic investment from OneSpan (an established digital identity/authentication vendor), alongside earlier investors Rabobank-linked funds, Motive Partners, and 10x Founders. The OneSpan relationship in particular signals the company is being positioned as a specialized threat-intelligence layer that larger identity and fraud-prevention vendors can integrate with rather than build in-house.
Innovation Matrix Assessment
The research team continuously discovers and reverse-engineers new mobile malware families before they are widely deployed, and has expanded its intelligence coverage from banking trojans into scam/social-engineering campaigns and APP fraud, indicating an active and evolving research and product pipeline.
A ten-year-old company with roughly 56-57 employees running production SDKs embedded in banking apps reaching over 60 million end users (per company disclosure) reflects genuine operational scale for a specialist vendor, though it remains a mid-sized company relative to broad fraud-platform incumbents.
The 2025 strategic investment from OneSpan, on top of earlier backing from Rabobank-affiliated funds and Motive Partners, signals a larger, more established security vendor is betting on ThreatFabric's intelligence as a component technology, which is a meaningful third-party growth signal beyond self-reported metrics.
Pairing device-level compromise detection (overlay attacks, remote-access/screen-sharing abuse) with a dedicated malware-research function is a genuinely different approach from generic post-transaction fraud scoring, and the company has been referenced in Gartner's Emerging Tech coverage for this category.
The claim of protecting 60+ million banking customers is vendor-reported and not independently audited; however, Gartner's inclusion of the company in Emerging Tech research on mobile fraud is a third-party signal of credibility, and the malware-family research the team publishes is independently verifiable technical work rather than marketing copy.
Malware-assisted mobile banking fraud, remote-access scams, and APP fraud are large and growing problems for financial institutions worldwide, making this category directly relevant to bank and fintech CISOs and fraud teams.
Why CISOs Should Care
For CISOs and fraud leaders at banks and fintechs, ThreatFabric provides device-level malware and remote-access detection at the point of transaction, backed by a dedicated threat-research team rather than only backend transaction-pattern analytics.
What Makes It Different
Most fraud platforms focus on transaction-pattern analysis after the fact; ThreatFabric leads with device-side malware and remote-access telemetry combined with proactive threat-family research, aiming to catch compromise before a fraudulent transaction completes.
The Matrix Verdict
72/100 — MEANINGFUL INNOVATOR
A credible, narrowly-focused specialist in mobile banking malware and fraud intelligence with real financial-institution deployments and a notable strategic investor (OneSpan); its core user-count claims are vendor-reported, but the underlying threat research is independently verifiable and well-regarded in the fraud-prevention community.
Editorial Note: Claims vs. Verified Findings
The '60+ million banking customers protected' figure and the effectiveness of detection are vendor-reported and not independently audited in public sources. Funding totals ($12.6M), the OneSpan strategic investment, and Gartner Emerging Tech recognition are independently corroborated through press releases and third-party research trackers (Crunchbase, PitchBook, OneSpan investor communications).
Sources
Alternatives to ThreatFabric
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…