The great mobile banking heist starts on your smartphone

Look, nobody is saying that you donโ€™t need to continue protecting your networks from fraud, but you canโ€™t afford to ignore your usersโ€™ smartphones. Thatโ€™s the takeaway from newly published research by Zimperium that has uncovered 34 active malware families targeting, are you sitting down, 1,243 financial apps across 90 countries.

Hardly surprising, then, that the report also found that Android malware-driven financial fraud has increased by 67% year on year. The question is, as the fraud battlefield becomes the customerโ€™s smartphone, have your defensive strategies kept up to protect against attackers who, Zimperium warned, โ€œcan manipulate legitimate banking sessions before traditional fraud controls ever detect suspicious activity?โ€

Of the 34 malware families analysed by the researchers, three appear to dominate the mobile fraud threats cape: TsarBot, CopyBara and Hook.

Between them, this malware trio accounted for at least 60% of all analysed banking and fintech app attacks. Interestingly, or should that be really bloody scarily, nearly half of the malware families included some form of ransomware or extortion capability.

โ€œWhat used to take highly skilled attackers weeks to build can now be put together and launched in days,โ€ warned Krishna Vishnubhotla, Zimperium’s Vice President of Product Strategy, โ€œand AI is making that even faster.โ€

Indeed, Vishnubhotla told me that the threat gap, they distance between attack and defence capabilities, โ€œhas never been this wide”.

โ€œThe frontline of financial fraud has migrated from backend infrastructure to the customer’s mobile device,โ€ said Jason Soroko, Senior Fellow at Sectigo. โ€œWith threat actors deploying automated trojans to hijack legitimate banking sessions, traditional server-side fraud controls are rendered blind.โ€

Key takes from 2026 Banking Heist Report

The 2026 Banking Heist Report is pretty unambiguous in stating that mobile banking apps have โ€œbecome the primary battleground for financial fraud,โ€ and the research suggests that the โ€œattackers are winning.โ€

With threat actors now deploying sophisticated and highly scalable attack campaigns, ones that are capable of continuous evolvement where it comes to the ability to bypass app security controls, itโ€™s hardly surprising that both organisations and their customers are finding themselves in trouble.

And it’s not just Zimperium saying this.

โ€œTodayโ€™s malware families donโ€™t just steal credentials,โ€ said Boris Cipot, Senior Security Engineer at Black Duck, โ€œthey intercept authentication codes, monitor live sessions, and convincingly mimic legitimate app behaviour.โ€

Which is why simply checking logins is no longer sufficient as an anti-fraud measure, considering that the device itself might already be comprised and hostile. โ€œDetecting compromised phones, blocking malware abuse of accessibility features, and monitoring for suspicious behaviour during an active session are all critical,โ€ Cipot concluded.

The takeaway from Zimperium is clear: โ€œfinancial institutions that extend security to the mobile app itself, hardening it against reverse engineering, protecting its runtime integrity, and gaining visibility into device risk before fraud reaches their systems will be better positioned to protect against scalable fraud and satisfy increasing regulatory scrutiny.โ€

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.