Zimperium has published its 2026 Banking Heist Report, indicating a significant rise in mobile banking malware, which now poses a substantial global threat to financial apps.
The study highlights the financial sector's vulnerability as attackers increasingly exploit mobile banking applications, marking them as a critical point for potential fraud.
Malware bypassing security measures
Throughout 2025, Zimperium’s zLabs team monitored 34 active malware families, which targeted 1,243 financial institutions in 90 countries. This led to a 67% increase in Android malware-driven financial transactions compared to the previous year.
The reported incidents were part of larger, sophisticated campaigns that continuously adapt to bypass existing app security measures, threatening both financial institutions and their clients.
Challenges in mobile app security
Krishna Vishnubhotla, Vice President of Product Strategy at Zimperium, commented on the evolution of mobile banking malware: "Mobile banking malware has come a long way from simply stealing passwords. Today it can take full control of a customer's device. What used to take highly skilled attackers weeks to build can now be put together and launched in days, and AI is making that even faster. The gap between what attackers can do and what defenders can keep up with has never been this wide. Mobile app security has to be where fraud prevention starts."The report highlights a fast-changing threat landscape where traditional defenses are falling behind
The advanced nature of today's malware allows it to intercept authentication codes, persist invisibly on devices, and mimic legitimate banking sessions, often eluding traditional security measures. These developments pose significant challenges to traditional fraud detection systems, making it increasingly difficult for institutions to react before fraud occurs.
Key findings and threat analysis
The report details a rapidly evolving threat landscape, where traditional defenses are struggling to keep pace. The United States emerges as a significant target, with 162 banking apps currently under attack, increasing from 109 in 2023. Malware families such as TsarBot, CopyBara, and Hook are particularly prevalent, collectively affecting over 60% of analysed global banking and fintech applications.
Additionally, nearly half of the identified malware families possess financial extortion capabilities, such as ransomware, which enable attackers to encrypt device files and demand payment.
Enhancing mobile app security
To counter these threats, it is essential for financial institutions to strengthen their mobile app security. This includes measures to protect against reverse engineering, maintaining runtime integrity, and assessing device risk before fraud impacts their systems. These strategies are crucial for combatting scalable fraud and meeting increasing regulatory demands.
Zimperium plans to present these findings at the upcoming RSA Conference, taking place from March 23 to March 26 at booth #S-1543.
