OTP Capture
MFA defeated via screen recording.
Threat Intelligence
Affected: Mobile Banking · MFA flows · Corporate banking
Screen recording malware, accessibility services and MediaProjection abuse capture banking screens — exfiltrating OTPs, balances and transaction confirmations.
High
OTP Theft Risk
Screen recording
Yes
GDPR Relevance
PII on screen
Low
Fix Complexity
FLAG_SECURE
Common
Audit Finding Rate
Missing on 1 screen
Attack chain
Typical exploitation path in mobile banking
Kill Chain
End-to-end attack timeline observed in mobile banking incidents.
Malware obtains recording or a11y access.
User opens app — sensitive UI visible.
Screens streamed to attacker C2.
OCR or manual extraction of codes.
Attacker completes transfer with OTP.
Business Impact
Operational, financial and regulatory consequences for BFSI.
MFA defeated via screen recording.
Balances and account numbers leaked.
Uncontrolled processing of personal data.
SOC Intelligence
Typical APK assessment findings mapped to this threat.
Detection
Four-phase governance pipeline — deterministic evidence only.
Phase 1
Phase 2
Phase 3
Mitigation
Layered defenses with coverage, effort and effectiveness ratings.
Protects: Screenshot / most recording
Effort
Low
Effectiveness
78%
All auth, OTP, payment screens.
Protects: Active MediaProjection
Effort
Medium
Effectiveness
65%
Combine with RASP on Android 14+.
Regulatory Intel
Compliance confidence and mapped control counts per jurisdiction.
CBUAE
12 mapped controls
View mandate →RBI
9 mapped controls
View mandate →MAS
11 mapped controls
View mandate →EBA / PSD2
10 mapped controls
View mandate →Framework Alignment
How this threat maps across MASVS, OWASP Mobile, PCI DSS, PSD2, NIST and DORA.
| Control | MASVS | OWASP Mobile | PCI DSS | PSD2 | NIST | DORA |
|---|---|---|---|---|---|---|
| Screen protection | ● | ◐ | ○ | ◐ | ● | ● |
Executive Summary
Board-ready risk dimensions and impact heatmap.
Lower = higher residual risk
Impact heatmap
OTP theft
L: 75%
I: 88%
Vendor Intel
RASP, attestation and device-trust solutions for banking programs.
Best for banking RASP
Enterprise
Banking: excellent
Pros
Limitations
Strong API integrity
Enterprise
Banking: excellent
Pros
Limitations
APK Preview
Sample assessment output for Screen Capture exposure.
Risk score
45
/ 100
1 critical findings
Related Intel
FAQ
SEO-optimized answers for security and governance teams.
It prevents screenshots and most screen recording on protected activities but should be combined with recording detection for comprehensive protection.
Take action
Upload your Android banking app for evidence-backed threat intelligence — no hallucinated findings.