AppSuit MacroBlockProtecting your service from automated attacks,
blocked at the source with AppSuit MacroBlock

A security solution that detects·blocks macros and automated input during mobile app execution in real time Fundamentally defends against automation-based service abuse such as ticket scalping, fraudulent reservations, and repeated transaction manipulation

Fake hands, a million macros
Data is deceived, and your business is eroded

Automated macros behave like real users and distort your data. With repeated input and virtual touches they seize reservations, payments, and transactions ahead of legitimate customers, which destabilizes the revenue structure and erodes customer trust

STAGE 01 · Introduction

Rise of automated macro attacks

Legitimate macro apps distributed on official app stores are abused to automatically manipulate the service repeatedly.

STAGE 02 · Repetition

Service abuse based on repetitive input

Second-by-second repetitive input monopolizes ticketing·reservations·purchases, blocking legitimate users' opportunity to use the service.

STAGE 03 · Concealment

Hard to distinguish from legitimate users

Because macro apps are legitimate apps rather than malicious code, detection itself is impossible with conventional AV (antivirus).

STAGE 04 · Damage

Compromised service integrity

When automated fraud is repeated, service fairness is compromised and legitimate users' trust collapses.

* Because macros leverage legitimate apps rather than malicious code, they cannot even be detected without a dedicated behavior detection solution.

Three-stage defense that blocks automated attacks

Rather than merely detecting macro threats, it immediately blocks them per policy and analyzes abnormal patterns.

DETECT

Macro behavior detection

  • Macro app signature detection
  • Touch-pattern-based detection
  • Virtual input detection
  • ADB connection detection

CONTROL

Automated input blocking

  • Instant blocking
  • Notification response
  • Policy customization

ANALYZE

Abnormal pattern analysis

  • Repetitive input pattern analysis
  • Device integrity checks
  • Rooting & emulator detection

Protection areas

Blocks macro behavior in the four areas most vulnerable to automated attacks.

Service protection

  • Reservation systems
  • Ticketing services
  • Checkout screens

Financial protection

  • Repeated transaction blocking
  • Fraudulent transfer prevention
  • Authentication flow protection

Games & points

  • Auto-play blocking
  • Reward monopoly prevention
  • Fairness protection

Platform protection

  • Abuse prevention
  • Service integrity
  • Legitimate user protection

Behavior-based precision detection + policy-based instant response

It detects automated behavior and responds flexibly even to modified attacks. Blocking·notification·threshold methods can be freely customized per the client's policy.

DETECTION

Behavior-based precision detection

Signature + pattern-based detection

Detects in real time whether major macro app signatures such as FRep, FRep2, and Touch Macro are present and whether specific touch patterns are being repeated.

Virtual input + ADB detection

Detects virtual touch events that are not real user touches, along with automated behavior via ADB·remote programs.

Detects automated behavior rather than the app itself to respond to modified attacks

RESPONSE

Policy-based instant response

Instant blocking method

Blocks app usage or restricts service access immediately upon detection, fundamentally preventing damage from automated attacks.

Threshold-based blocking method

Minimizes false positives with a threshold setting that blocks only when automated behavior persists beyond a certain duration.

Blocking·notification·threshold methods can be customized per the client's policy

Three simple steps, protection starts right after installation

Easily added to your existing development environment via an SDK · library approach.

Works instantly as an in-app library with no separate server

Embedded in the client's app via an SDK · library approach. It operates as an in-app (library) form with no separate server integration.

SDK approachNo server requiredPolicy customization
STEP 01

Add the SDK · library

Easily applied to your existing development environment via an SDK · library approach

Add the MacroBlock library file to your Android app development environment

STEP 02

Configure policy

Customizable to fit the client's security policy

Set the detection scope and response method (blocking·notification·threshold) according to the guide.

STEP 03

Application complete

Works instantly in an in-app form with no separate server integration

Complete the embedding of security features through the app build

Proven technology, certified trust

The core differentiators of AppSuit MacroBlock that keep automated attacks under control.

  • User-behavior-based detection

    Analyzes actual input patterns rather than a simple app list to precisely judge whether activity is automated.

  • Normal vs. abnormal input

    Distinguishes real touches from virtual input to block only macros, without false positives.

  • Minimal impact on service UX

    Responds selectively to automated behavior only, without affecting legitimate users.

  • Multi-angle composite detection

    Combines varied signals — touch patterns, virtual input, ADB, rooting — to detect automation.

  • Flexible policy customization

    Blocking, thresholds, and notification methods can be configured to fit your policy.

  • Continuous update response

    Responds to new macros and OS changes to defend against the latest automated attacks.

Positioning within the AppSuit product suite

MacroBlock focuses on blocking automated behavior at the 'Process' stage — between user input and output.

InputKeypadInput data protection
ProcessAV · MacroBlockMalware·automation blocking
OutputAnti-CaptureScreen data protection

Positioning within the AppSuit product suite

Areas covered by MacroBlock

  • Macro app detection
  • Automated input blocking
  • Abnormal pattern analysis

Handled by other modules

  • Keypad — Data encryption·input protection
  • AV — Malware detection·analysis
  • Anti-Capture — Screen capture blocking

Optional service

Integrate with AppSuit Radar for real-time monitoring

MacroBlock customers can additionally integrate Radar to centrally monitor detection data.

AppSuit Radar

Unified monitoring

  • AppSuit

    Premium

  • AppSuit

    Air

  • AppSuit

    AV

  • AppSuit

    RemoteBlock

  • AppSuit

    MacroBlock

  • AppSuit

    VPNBlock

Features available when AppSuit MacroBlock is integrated with AppSuit Radar

  • Real-time threat monitoring
  • Unified dashboard
  • Policy-based response
  • Monthly reports

Quality certifications and intellectual property

MacroBlock's security reliability has been verified based on official certifications.

Quality certification

GS (Good Software) Certification Grade 1

A product awarded the highest grade of the software quality certification granted by the Telecommunications Technology Association (TTA). With verified functionality·reliability·security, it is well suited for public-sector adoption and procurement review.

Frequently Asked Questions

Considering adopting AppSuit MacroBlock?

Adopt the essential security element that controls automated attacks. It can be quickly applied with simple SDK-based integration.