This blog post was co-authored by Pratik Shah, Product Management Director.

Last year we introduced App Protection to protect our on-premises Citrix Virtual Apps and Desktops customers. We’re excited to announce that App Protection is now generally available to our Citrix Virtual Apps and Desktops service customers, adding a critical layer of defense against social engineering, phishing events, key logging, and screenshot malware for end users accessing corporate resources through any Windows or Mac devices, whether personal, unmanaged, or managed.

IT and end users alike have seen the benefits of BYOD programs, which have led to an increase of personal devices in the workplace. Additionally, many companies need gig workers and contractors to use their personal devices to get work done. While IT takes measures to ensure that corporate-owned and managed devices are secure through policy administration, regular health checks, and web filtering, gig workers and contractors might not take the same measures on their personal devices. It’s unlikely that they are monitoring the health of their devices at all, despite the fact that they likely visit social media and other popular sites that are havens for malware. So, while IT invests in security solutions at double-digit growth rates, the risk of a data breach is still high because personal devices infected with malware can enter any corporate network.

Synopsys, a Citrix Virtual Apps and Desktops customer, used App Protection to support remote workers who had types of users that had to be managed differently. These end users were using various types of devices such as BYO or unmanaged devices and were easily able to bridge security gaps to mitigate risk. Learn more in our Synopsys customer story.

According to PCI Security Standards Council (PCI SSC), ATM cash-out attacks are on the rise and can be caused on silent keyloggers sitting on the computer. These attacks are carried out by inserting malware via phishing or social engineering methods into a financial institution or payment processor’s systems. Once infected, the system can transmit users’ personal data back to a third-party attacking system, causing huge financial liability.

Key logging and screen capture malware commonly affect unmanaged endpoints. When present on a device, key logging malware captures each key stroke entered by a user, creating a significant risk for an organization. The malware captures all the information end users type into a device, including user names and passwords. Screen-capture malware periodically takes a snapshot of the user’s screen, saving it to a hidden folder on the device or directly uploading it to the attacker’s server. This also creates significant risk because the attacker can exfiltrate all the information on the user’s screen.

Even with managed devices, there is still the threat of social engineering. A common attack through social engineering is using screen sharing to steal data, money, and more. In a screen share attack, the attacker will call and pretend they are tech support or IT and convince an unsuspecting target to screen share their device. At this point, the attacker can infiltrate the device and take financial information, sensitive data, and more. This is even riskier in businesses such as call centers, financial institutions, healthcare, and any business handling sensitive customer and patient data. App Protection defends against accidental screen sharing by turning apps delivered through Citrix Virtual Apps and Desktops into black screens.

App Protection can complement your IT security strategy with a zero trust security approach, assuming all Windows or Mac devices whether they are personal, unmanaged, or managed are compromised and protecting from data exfiltration. To defend against key loggers, App Protection scrambles keystrokes entered in the device, sending the attacker undecipherable text. It also prevents screen shot malware by turning all screen shots into a blank picture. Check out the video below to see App Protection in action.

Get Started Today

App Protection is generally available today for Citrix Virtual Apps and Desktops service and for on-premises deployment of Citrix Virtual Apps and Desktops. If users are accessing Citrix Virtual Apps and Desktops through a Mac, they must be using Citrix Workspace app version 2001 or later, while Windows users must access their Virtual Apps and Desktops through Citrix Workspace app 1912 or later. App Protection currently only protects sessions initiated through StoreFront. For additional technical requirements, check out the Citrix Docs App Protection page.

Contact your Citrix sales rep or partner to learn more about App Protection and purchasing options. App Protection policies for SaaS and web apps is currently in public tech preview.