Jaroslav Novotný, Tomáš Soukal
April 4, 2023

Protecting Your API from App Impersonation: Token Hijacking Guide and Mitigation of JWT Theft

Gone are the days of locally-held data and standalone applications. With the rise of smartphones and portable devices, we are constantly on the go and reliant on network calls for everything from social communication to live updates. As a result, protecting backend servers and API calls has become more crucial than ever.
Gone are the days of locally-held data and standalone applications. With the rise of smartphones and portable devices, we are constantly on the go and reliant on network calls for everything from social communication to live updates. As a result, protecting backend servers and API calls has become more crucial than ever.
You can read more about the concept of RASP (Runtime application self-protection)
here.

You may also like

Breaking the Android Sandbox and How to Defend Against It
Breaking the Android Sandbox and How to Defend Against It
A deep-dive into CVE-2024-0044 and how Runtime Application Self-Protection can stop it
Defending Mobile Banking Apps Against the Rokarolla Trojan
Defending Mobile Banking Apps Against the Rokarolla Trojan
Read the full article on our blog.
Case Study: How Rogue Malware Apps Attack Your Users (and What Our Data Shows)
Case Study: How Rogue Malware Apps Attack Your Users (and What Our Data Shows)
This case study, courtesy of Talsec Labs, delves into Android malware campaigns and samples. The culmination of this research materializes in the state-of-the-art Malware Detection SDK.
Read More