Summary is AI-generated, newsdesk-reviewed
  • Banking malware targets 1,243 financial apps across 90 countries, says Zimperium report.
  • Malware adapts to bypass security, affecting Android transactions increasing 67% yearly.
  • U.S. leads in attacked apps; TsarBot, CopyBara, Hook hit 60% of banking apps.

Zimperium has published the 2026 Banking Heist Report, revealing an escalating trend in mobile banking threats worldwide.

Targeting over 1,200 financial applications, this surge in banking malware has turned mobile banking apps into a primary avenue for financial fraud.

Rising Threats from Banking Malware

In 2025, Zimperium's zLabs tracked 34 active malware families targeting financial institutions across 90 countries, causing a 67% increase in malware-driven transactions on Android devices year-over-year.

This research highlights sophisticated campaigns specifically designed to evade app security measures, putting both institutions and their customers at risk.

Mobile Banking Malware's Growing Sophistication

The report emphasizes the need to build strong security measures directly into mobile apps"Mobile banking malware has come a long way from simply stealing passwords. Today it can take full control of a customer's device. What used to take highly skilled attackers weeks to build can now be put together and launched in days, and AI is making that even faster. The gap between what attackers can do and what defenders can keep up with has never been this wide. Mobile app security has to be where fraud prevention starts," said Krishna Vishnubhotla, Vice President of Product Strategy, Zimperium.

The report outlines malware's capacity to intercept authentication codes and phone calls, maintaining a low profile to bypass traditional security tools, which results in fraud often going undetected until it is too late.

Global and Regional Impacts

The United States continues to be heavily targeted, with 162 apps currently under threat—up from 109 in 2023. Dominant malware families like TsarBot, CopyBara, and Hook are influencing over 60% of banking and fintech apps globally.

Additionally, nearly half of the examined malware families have evolved to include financial extortion capabilities, including ransomware.

Mobile Security as a Critical Defense

The report underscores the necessity of incorporating stringent security measures directly into mobile applications. By enhancing runtime integrity, hardening applications against reverse engineering, and gaining proactive visibility into device risks, financial institutions can better protect against widespread fraud and meet increasing regulatory requirements.

Zimperium is slated to present its findings at the RSA Conference from March 23 to March 26, at booth #S-1543.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...