Summary is AI-generated, newsdesk-reviewed
  • Zimperium report: Banking malware targets 1,243 financial apps, increasing mobile fraud risks.
  • Mobile malware outpaces defences, controls devices, intercepts codes and impersonates banking sessions.
  • USA targeted heavily; TsarBot, CopyBara, Hook malware dominate global banking app attacks.

Zimperium has published its 2026 Banking Heist Report, indicating a significant rise in mobile banking malware, which now poses a substantial global threat to financial apps.

The study highlights the financial sector's vulnerability as attackers increasingly exploit mobile banking applications, marking them as a critical point for potential fraud.

Malware bypassing security measures

Throughout 2025, Zimperium’s zLabs team monitored 34 active malware families, which targeted 1,243 financial institutions in 90 countries. This led to a 67% increase in Android malware-driven financial transactions compared to the previous year.

The reported incidents were part of larger, sophisticated campaigns that continuously adapt to bypass existing app security measures, threatening both financial institutions and their clients.

Challenges in mobile app security

Krishna Vishnubhotla, Vice President of Product Strategy at Zimperium, commented on the evolution of mobile banking malware: "Mobile banking malware has come a long way from simply stealing passwords. Today it can take full control of a customer's device. What used to take highly skilled attackers weeks to build can now be put together and launched in days, and AI is making that even faster. The gap between what attackers can do and what defenders can keep up with has never been this wide. Mobile app security has to be where fraud prevention starts."The report highlights a fast-changing threat landscape where traditional defenses are falling behind

The advanced nature of today's malware allows it to intercept authentication codes, persist invisibly on devices, and mimic legitimate banking sessions, often eluding traditional security measures. These developments pose significant challenges to traditional fraud detection systems, making it increasingly difficult for institutions to react before fraud occurs.

Key findings and threat analysis

The report details a rapidly evolving threat landscape, where traditional defenses are struggling to keep pace. The United States emerges as a significant target, with 162 banking apps currently under attack, increasing from 109 in 2023. Malware families such as TsarBot, CopyBara, and Hook are particularly prevalent, collectively affecting over 60% of analysed global banking and fintech applications.

Additionally, nearly half of the identified malware families possess financial extortion capabilities, such as ransomware, which enable attackers to encrypt device files and demand payment.

Enhancing mobile app security

To counter these threats, it is essential for financial institutions to strengthen their mobile app security. This includes measures to protect against reverse engineering, maintaining runtime integrity, and assessing device risk before fraud impacts their systems. These strategies are crucial for combatting scalable fraud and meeting increasing regulatory demands.

Zimperium plans to present these findings at the upcoming RSA Conference, taking place from March 23 to March 26 at booth #S-1543.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...