Inspiration
Banking fraud happens in two acts — the moment a customer is deceived by a phishing link, and the moment the stolen money disappears through layers of mule accounts. Existing tools only ever address one half of that lifecycle, and even then, they're manual. Tools like VirusTotal require a person to notice a suspicious link, copy it, and paste it into a checker — and humans are lazy by default. Nobody stops mid-panic, which is exactly the emotional state scammers engineer, to go do that extra step. We wanted to build something that works with human behavior instead of against it, and that treats fraud as one continuous lifecycle instead of two disconnected problems.
What it does
CyberNetX is a single platform with two engines. ShieldNetX is a browser extension + Android app that protects any person — not just bank customers — from phishing and smishing links in real time, with zero manual effort. It scores every link automatically across six behavioral signals (click velocity, dwell time, geo velocity, HTML/JS analysis via a Ghost Sandbox, sender trust) instead of relying on a reported-scam blocklist, so it catches zero-day phishing pages on their very first appearance.
TraceNetX picks up if a scam does succeed. Instead of working forward from one flagged account like existing AML tools — which stop at the first suspicious hop and leave an analyst to manually trace the rest — TraceNetX works backward. It follows every hop through the mule-account layers to the convergence point where the money actually ends up, because mule accounts are disposable but the dealer can't hide. It runs on graph intelligence (Neo4j) and an ML ensemble (XGBoost, LightGBM, Random Forest, Isolation Forest) with SHAP explainability, and generates a one-click, court-ready evidence package (STR flag, I4C cross-reference, FIR summary).
How we built it
- Frontend: React dashboard, Chrome Extension (MV3), Flutter + native Java for Android
- Backend: FastAPI (Python) with Uvicorn, REST APIs
- Detection: A Ghost Sandbox that renders and inspects suspicious pages in isolation, analyzing HTML structure and JavaScript for cookie stealers, obfuscated code, and fingerprinting attempts — without ever loading the page in a real browser
- ML/Intelligence layer: An ensemble of XGBoost, LightGBM, Random Forest, and Isolation Forest for anomaly detection, with SHAP for explainable risk scoring
- Data layer: Neo4j graph database to model the mule-account network with force-directed visualization (Spider Map)
- Dev environment: Kali Linux, Playwright for automated page analysis, Git/GitHub
Challenges we ran into
Building real-time behavioral detection that doesn't rely on a static blocklist meant designing signals (click velocity, geo velocity, dwell time) that could catch zero-day phishing pages with no prior reputation data — a much harder problem than blocklist matching. On the TraceNetX side, modeling mule-account networks as a graph and tracing backward to a convergence point (rather than just flagging individual accounts) required getting the graph traversal and anomaly scoring right so that it surfaces the actual dealer instead of noise.
Log in or sign up for Devpost to join the conversation.