Trending Topics

The great mobile banking heist starts on your smartphone
Look, nobody is saying that you don’t need to continue protecting your networks from fraud, but you can’t afford to ignore your users’ smartphones. That’s the takeaway from newly published research by Zimperium that has uncovered 34 active malware families targeting, are you sitting down, 1,243 financial apps across 90 countries.
Hardly surprising, then, that the report also found that Android malware-driven financial fraud has increased by 67% year on year. The question is, as the fraud battlefield becomes the customer’s smartphone, have your defensive strategies kept up to protect against attackers who, Zimperium warned, “can manipulate legitimate banking sessions before traditional fraud controls ever detect suspicious activity?”
Of the 34 malware families analysed by the researchers, three appear to dominate the mobile fraud threats cape: TsarBot, CopyBara and Hook.
Between them, this malware trio accounted for at least 60% of all analysed banking and fintech app attacks. Interestingly, or should that be really bloody scarily, nearly half of the malware families included some form of ransomware or extortion capability.
“What used to take highly skilled attackers weeks to build can now be put together and launched in days,” warned Krishna Vishnubhotla, Zimperium’s Vice President of Product Strategy, “and AI is making that even faster.”
Indeed, Vishnubhotla told me that the threat gap, they distance between attack and defence capabilities, “has never been this wide”.
“The frontline of financial fraud has migrated from backend infrastructure to the customer’s mobile device,” said Jason Soroko, Senior Fellow at Sectigo. “With threat actors deploying automated trojans to hijack legitimate banking sessions, traditional server-side fraud controls are rendered blind.”
Key takes from 2026 Banking Heist Report
The 2026 Banking Heist Report is pretty unambiguous in stating that mobile banking apps have “become the primary battleground for financial fraud,” and the research suggests that the “attackers are winning.”
With threat actors now deploying sophisticated and highly scalable attack campaigns, ones that are capable of continuous evolvement where it comes to the ability to bypass app security controls, it’s hardly surprising that both organisations and their customers are finding themselves in trouble.
And it’s not just Zimperium saying this.
“Today’s malware families don’t just steal credentials,” said Boris Cipot, Senior Security Engineer at Black Duck, “they intercept authentication codes, monitor live sessions, and convincingly mimic legitimate app behaviour.”
Which is why simply checking logins is no longer sufficient as an anti-fraud measure, considering that the device itself might already be comprised and hostile. “Detecting compromised phones, blocking malware abuse of accessibility features, and monitoring for suspicious behaviour during an active session are all critical,” Cipot concluded.
The takeaway from Zimperium is clear: “financial institutions that extend security to the mobile app itself, hardening it against reverse engineering, protecting its runtime integrity, and gaining visibility into device risk before fraud reaches their systems will be better positioned to protect against scalable fraud and satisfy increasing regulatory scrutiny.”
