Loading...
Loading...
How RedGobble designed and shipped MalwareX — a real-time AI malware detection platform that catches phishing, cloned apps and unknown threats that signature-based antivirus misses.
Client
RedGobble Product
Industry
Cybersecurity
Timeline
6 months
Our Role
End-to-end product build — research, architecture, AI, app, launch

Traditional antivirus tools rely on signature databases: they can only detect threats that have already been catalogued. Zero-day malware, repackaged apps and phishing sites slip through until a signature is published. RedGobble set out to build protection that could reason about behaviour — flagging suspicious activity the moment it appears, without waiting for a known signature.
How we validated the problem and shaped the approach before building.
Studied the Android threat landscape — repackaged apps, overlay phishing, accessibility-abuse malware — and how they evade signature scanners.
Evaluated on-device vs cloud detection trade-offs: on-device privacy and offline coverage versus cloud model size and update velocity.
Benchmarked open-source malware datasets and explored behaviour-based feature extraction for lightweight on-device inference.
Interviewed Android users about trust: what makes a security app credible, transparent and non-disruptive to daily use.
MalwareX uses a hybrid architecture: a lightweight on-device behaviour monitor continuously profiles apps, network activity and permission usage, while threat intel and phishing checks run against a cloud service. The on-device model scores behaviour in real time; anything above the alert threshold triggers an immediate report with a clear, actionable explanation. Cloud-side analytics enrich detection as new patterns are learned, without slowing the device.
Two-week discovery sprint: threat research, detection strategy and UX for security messaging.
Model development in parallel with app build — behaviour features engineered and iterated against labelled threat data.
Agile sprints with weekly product demos; detection accuracy tracked as the core success metric.
Beta programme on Google Play for real-device validation before public release.
Play Store compliance review, security-labelling and release management for launch.
Kept the on-device model deliberately small and event-driven, reserving heavy analysis for the cloud; behaviour scoring runs only on app installs, updates and network events.
Every alert ships with a plain-language explanation and recommended action, and the scoring threshold is calibrated conservatively to protect credibility.
Behavioural profiling observes actions rather than signatures, so stealthy patterns still surface — the core architectural bet of the product.
Shipped and published on Google Play as a live product
Real-time detection of malware, phishing and cloned apps with plain-language alerts
Enterprise deployment path with centralized dashboards and policy controls
Demonstrated RedGobble's full-cycle capability: AI research, mobile build and launch
Detection model
Behaviour-based, not signature-based
Detection coverage
Real-time on-device + cloud
Platform
Android (Google Play), iOS-ready
Deployment
Consumer app + enterprise dashboard
3 weeks
Threat landscape, detection strategy and product definition.
12 weeks
Behaviour model training in parallel with Flutter app development.
6 weeks
Real-device beta, false-positive calibration, UX hardening.
Ongoing
Google Play release, enterprise dashboards, continuous detection tuning.
What we would carry into the next project — and what we apply to yours.
Security products live or die on user trust — transparency beats cleverness.
On-device AI is a real constraint problem: the smallest model that works is the best model.
A hybrid on-device/cloud split gives you coverage and velocity without sacrificing performance.
Beta testing on real devices surfaces battery and false-positive issues that no lab can.
MalwareX validates RedGobble's ability to ship a defensible AI product end-to-end — from model research to a live store listing — and gives enterprises a real, deployable security tool with an on-premise-friendly roadmap.
RedGobble designed and built the full product — threat research, the behaviour-based detection model, the Flutter app, cloud APIs and enterprise dashboards.
Regular antivirus matches known signatures. MalwareX profiles behaviour with on-device AI, so it can flag unknown and zero-day threats the moment suspicious activity appears.
Yes. Enterprise deployments add centralized dashboards, policy controls and reporting for security teams.
It is live on Android via Google Play, with an iOS-ready Flutter codebase and web-based enterprise dashboards.
Yes. MalwareX is one example; we build custom threat detection and AI security tools. See the AI Development service.
How RedGobble built VisiLearn — a visual-first platform that turns tokenizers, embeddings and attention into interactive diagrams so students and developers actually understand NLP.
How RedGobble built Wordique — a language-learning app that uses spaced repetition and AI-personalised lessons to make vocabulary growth daily, measurable and genuinely engaging.
Tell us what you are building and get a tailored plan from the same engineering team.