AppSuit MacroBlockProtecting your service from automated attacks,
blocked at the source with AppSuit MacroBlock
A security solution that detects·blocks macros and automated input during mobile app execution in real time Fundamentally defends against automation-based service abuse such as ticket scalping, fraudulent reservations, and repeated transaction manipulation
Fake hands, a million macros
Data is deceived, and your business is eroded
Automated macros behave like real users and distort your data. With repeated input and virtual touches they seize reservations, payments, and transactions ahead of legitimate customers, which destabilizes the revenue structure and erodes customer trust
STAGE 01 · Introduction
Rise of automated macro attacks
Legitimate macro apps distributed on official app stores are abused to automatically manipulate the service repeatedly.
STAGE 02 · Repetition
Service abuse based on repetitive input
Second-by-second repetitive input monopolizes ticketing·reservations·purchases, blocking legitimate users' opportunity to use the service.
STAGE 03 · Concealment
Hard to distinguish from legitimate users
Because macro apps are legitimate apps rather than malicious code, detection itself is impossible with conventional AV (antivirus).
STAGE 04 · Damage
Compromised service integrity
When automated fraud is repeated, service fairness is compromised and legitimate users' trust collapses.
* Because macros leverage legitimate apps rather than malicious code, they cannot even be detected without a dedicated behavior detection solution.
Three-stage defense that blocks automated attacks
Rather than merely detecting macro threats, it immediately blocks them per policy and analyzes abnormal patterns.
DETECT
Macro behavior detection
- Macro app signature detection
- Touch-pattern-based detection
- Virtual input detection
- ADB connection detection
CONTROL
Automated input blocking
- Instant blocking
- Notification response
- Policy customization
ANALYZE
Abnormal pattern analysis
- Repetitive input pattern analysis
- Device integrity checks
- Rooting & emulator detection
Protection areas
Blocks macro behavior in the four areas most vulnerable to automated attacks.
Service protection
- Reservation systems
- Ticketing services
- Checkout screens
Financial protection
- Repeated transaction blocking
- Fraudulent transfer prevention
- Authentication flow protection
Games & points
- Auto-play blocking
- Reward monopoly prevention
- Fairness protection
Platform protection
- Abuse prevention
- Service integrity
- Legitimate user protection
Behavior-based precision detection + policy-based instant response
It detects automated behavior and responds flexibly even to modified attacks. Blocking·notification·threshold methods can be freely customized per the client's policy.
Behavior-based precision detection
Signature + pattern-based detection
Detects in real time whether major macro app signatures such as FRep, FRep2, and Touch Macro are present and whether specific touch patterns are being repeated.
Virtual input + ADB detection
Detects virtual touch events that are not real user touches, along with automated behavior via ADB·remote programs.
Detects automated behavior rather than the app itself to respond to modified attacks
Policy-based instant response
Instant blocking method
Blocks app usage or restricts service access immediately upon detection, fundamentally preventing damage from automated attacks.
Threshold-based blocking method
Minimizes false positives with a threshold setting that blocks only when automated behavior persists beyond a certain duration.
Blocking·notification·threshold methods can be customized per the client's policy
Three simple steps, protection starts right after installation
Easily added to your existing development environment via an SDK · library approach.
Works instantly as an in-app library with no separate server
Embedded in the client's app via an SDK · library approach. It operates as an in-app (library) form with no separate server integration.
Add the SDK · library
Easily applied to your existing development environment via an SDK · library approach
Add the MacroBlock library file to your Android app development environment
Configure policy
Customizable to fit the client's security policy
Set the detection scope and response method (blocking·notification·threshold) according to the guide.
Application complete
Works instantly in an in-app form with no separate server integration
Complete the embedding of security features through the app build
Proven technology, certified trust
The core differentiators of AppSuit MacroBlock that keep automated attacks under control.
User-behavior-based detection
Analyzes actual input patterns rather than a simple app list to precisely judge whether activity is automated.
Normal vs. abnormal input
Distinguishes real touches from virtual input to block only macros, without false positives.
Minimal impact on service UX
Responds selectively to automated behavior only, without affecting legitimate users.
Multi-angle composite detection
Combines varied signals — touch patterns, virtual input, ADB, rooting — to detect automation.
Flexible policy customization
Blocking, thresholds, and notification methods can be configured to fit your policy.
Continuous update response
Responds to new macros and OS changes to defend against the latest automated attacks.
Positioning within the AppSuit product suite
MacroBlock focuses on blocking automated behavior at the 'Process' stage — between user input and output.
Positioning within the AppSuit product suite
Areas covered by MacroBlock
- Macro app detection
- Automated input blocking
- Abnormal pattern analysis
Handled by other modules
- Keypad — Data encryption·input protection
- AV — Malware detection·analysis
- Anti-Capture — Screen capture blocking
Optional service
Integrate with AppSuit Radar for real-time monitoring
MacroBlock customers can additionally integrate Radar to centrally monitor detection data.
AppSuit Radar
Unified monitoring
AppSuit
Premium
AppSuit
Air
AppSuit
AV
AppSuit
RemoteBlock
AppSuit
MacroBlock
AppSuit
VPNBlock
Features available when AppSuit MacroBlock is integrated with AppSuit Radar
- Real-time threat monitoring
- Unified dashboard
- Policy-based response
- Monthly reports
Quality certifications and intellectual property
MacroBlock's security reliability has been verified based on official certifications.
GS (Good Software) Certification Grade 1
A product awarded the highest grade of the software quality certification granted by the Telecommunications Technology Association (TTA). With verified functionality·reliability·security, it is well suited for public-sector adoption and procurement review.
Frequently Asked Questions
Considering adopting AppSuit MacroBlock?
Adopt the essential security element that controls automated attacks. It can be quickly applied with simple SDK-based integration.