Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Hackers Exploit Critical Langflow Bug in Just 20 Hours

March 20, 2026

http://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html

March 20, 2026

http://thehackernews.com/2026/03/meta-disables-150k-accounts-linked-to.html

March 20, 2026
Facebook X (Twitter) Instagram
Friday, March 20
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Financial Brands Targeted in Global Mobile Banking Malware Surge
News

Financial Brands Targeted in Global Mobile Banking Malware Surge

Team-CWDBy Team-CWDMarch 19, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A global surge in mobile banking malware targeting 1243 financial brands across 90 countries is reshaping the fraud landscape, with attacks now originating primarily on user devices, according to Zimperium zLabs. 

Zimperium’s latest report examined 34 active malware families affecting apps with more than three billion downloads, revealing what analysts describe as industrialised, large-scale campaigns.

These operations are reportedly evolving faster than traditional banking defences, driven by widespread code sharing and low barriers to entry for attackers.

Devices as Primary Battleground

Mobile banking is now the dominant channel for consumers, Zimperium said, with 54% relying on apps to manage accounts. As usage has increased, so has exposure to risk.

The report highlights a sharp rise in malicious activity, including a 56% increase in Android banking trojan attacks in 2025 and a 271% jump in unique malware packages to 255,090. Online fraud rose 21% between 2024 and 2025, while one in 20 verification attempts is now considered fraudulent. Overall, 80% of fraud occurs through online or mobile platforms.

“Mobile banking applications are absolutely a prime target,” Boris Cipot, senior security engineer at Black Duck, commented. “As the research shows, more than 1200 financial apps are currently under active attack, and malware-driven fraud has increased 67% year over year.”

Attackers are exploiting weak points in mobile applications. More than 60% of banking apps lack basic code protection, allowing criminals to reverse engineer systems and tailor attacks before targeting users.

Malware Capabilities Outpace Traditional Defences

Modern malware has progressed beyond credential theft, Zimperium warned, enabling attackers to control devices and operate within legitimate banking sessions. As a result, fraudulent activity often appears indistinguishable from normal user behaviour.

Read more on mobile banking fraud: GodFather Malware Upgraded to Hijack Legitimate Mobile Apps

“Today’s malware families don’t just steal credentials, they intercept authentication codes, monitor live sessions, and convincingly mimic legitimate app behavior,” Cipot said. “In many cases, attackers are effectively taking control of the device itself.”

Three malware families, TsarBot, CopyBara and Hook, accounted for more than 60% of banking and fintech app targeting. New variants such as Sturnus and Crocodilus introduce advanced techniques, such as “blackout” modes, that allow transactions to occur while a device appears inactive.

“The frontline of financial fraud has migrated from backend infrastructure to the customer’s mobile device,” Jason Soroko, senior fellow at Sectigo, said. “With threat actors deploying automated trojans to hijack legitimate banking sessions, traditional server-side fraud controls are rendered blind.”

The threat is global but unevenly distributed, Zimperium warned. The US has 162 targeted banking apps, the highest concentration worldwide, followed by the UK with 69, Spain with 65 and Italy with 52. Rapidly digitizing markets, including India (42), Vietnam (23) and Malaysia (17) are also heavily targeted.

Artificial intelligence is accelerating attacks, enabling faster reverse engineering and the use of deepfakes to bypass identity checks.

The researchers concluded that financial institutions must prioritise mobile app security to defend against such threats, as backend-focused defences alone are no longer sufficient.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWhat Boards Must Demand in the Age of AI-Automated Exploitation
Next Article Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
Team-CWD
  • Website

Related Posts

News

Hackers Exploit Critical Langflow Bug in Just 20 Hours

March 20, 2026
News

http://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html

March 20, 2026
News

http://thehackernews.com/2026/03/meta-disables-150k-accounts-linked-to.html

March 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views

Near-ultrasonic attacks on voice assistants

September 11, 20256 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Our Picks

How to help older family members avoid scams

October 31, 2025

Is it OK to let your children post selfies online?

February 17, 2026

Can password managers get hacked? Here’s what to know

November 14, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.