Politics

34 Android Malware Families Now Target 1,243 Banking and…

Thirty-four mobile malware families contained the tools or targeting data needed to attack 1,243 banking and fintech apps across 90 countries during 2025, according to new regional findings from Zimperium’s zLabs team. Europe, the Middle East and Africa accounted for more than 800 of the identified app targets and 30 of the 34 malware families, putting most of the observed threat catalogue inside one region.The numbers describe potential targets built into malware campaigns, not 1,243 confirmed breaches, compromised institutions or infected apps. That distinction is essential. A banking trojan can carry package names, login overlays or automated routines for hundreds of legitimate apps without successfully stealing from every institution or user on its list.

EMEA Accounts for More Than 800 App Targets

Zimperium counted more than 800 targeted banking and fintech applications across 44 EMEA countries. The United Kingdom led the regional table with 72 apps, followed by Spain with 65, Italy with 57, Turkey with 56 and Germany with 55. Poland and France each had 39, while the United Arab Emirates led the Middle East group with 38.

Those country figures measure applications associated with each market rather than infections or customer losses. They should not be used as a ranking of which population suffered the most fraud. Markets with more banks, payment companies and local app variants can produce a larger target list even if the malware’s installation rate is lower.

The EMEA result also cannot be combined family by family. TsarBot targeted 450 banking apps in the region, CopyBara targeted 446 and Hook targeted 385, but the lists overlap. Adding them would count the same app more than once. Zimperium said TsarBot uses screen recording, overlays created during an attack and abuse of Android Accessibility Services, while CopyBara adds phone-based social engineering and forms assembled as needed. Hook includes remote access through virtual network computing and live screen sharing.

The Malware Attacks the Session, Not the Bank’s Server

The common attack path begins before the user opens a banking app. A victim installs a malicious Android package through a fake download, phishing link, messaging lure or compromised distribution route. The malware then seeks permissions that can expose notifications, text messages, screen content or accessibility functions.

Once active, an overlay can place a counterfeit login screen over the genuine app and collect credentials. Notification or SMS access can expose one-time authentication codes. Accessibility privileges can allow the malware to read screen elements, press buttons or approve prompts, while remote-control functions let an operator act through the victim’s device. A comparable real-world case involved a Belgian network that allegedly used phone calls and remote-access software in a phishing operation worth more than €500,000.

This model creates a problem for server-side fraud controls. A bank may see a login from the customer’s usual handset, followed by actions performed inside a legitimate session. Multifactor authentication still matters, but it can be weakened when the same compromised device receives the code, displays the approval request and executes the transaction.

Nexus shows the regional specialization of that model. Zimperium said 90% of its global targets are in EMEA and that it combines overlay technology with two-factor authentication interception. FluBot and Cabassous use European delivery and logistics lures, while EventBot and MaliBot target EMEA financial institutions with keylogging, SMS interception and unauthorized-transfer capabilities.

The 1,243 Figure Is Smaller Than Zimperium’s 2023 App Count

Zimperium’s current headline is about geographic reach and capability growth, not a record number of targeted apps. Its 2023 Mobile Banking Heists research identified 29 malware families targeting 1,800 apps across 61 countries. The latest study lists 34 families and 90 countries but 1,243 apps.

On the face of the two releases, the app count is about 31% lower, while the number of malware families is about 17% higher and country coverage is about 48% wider. The reports do not provide enough consistent methodology to treat those changes as a clean time series. App definitions, sample collection and active-family criteria may have changed. The defensible conclusion is narrower: the observed malware is distributed across more countries and more families than in the 2023 release, even though the published app total is lower.

The United States moved in the opposite direction. Zimperium’s broader 2026 Banking Heist release counted 162 US banking applications under active targeting, up from 109 in 2023. The company also said Android malware-driven fraudulent financial transactions rose 67% year over year, though the public release does not disclose the underlying transaction count or a country-level loss total.

AI Speeds Up Attacks but Does Not Replace the Old Methods

Zimperium says attackers use AI to translate and localize lures, write exploit scripts and make phishing pages or overlays resemble real financial apps. The evidence supports a speed-and-scale argument more readily than a claim that AI created a new type of banking fraud. Credential theft, remote access, overlay attacks and abuse of user permissions all predate generative AI.

The 2026 Verizon Data Breach Investigations Report provides broader support for faster attacks. Verizon found that vulnerability exploitation became the entry point in 31% of breaches and said AI was shortening the time needed to weaponize known flaws. It also reported that mobile social-engineering attacks through text messages and calls achieved a 40% higher success rate than traditional email phishing.

AI can therefore compress several parts of the operation at once: adapting a message to local language, cloning a bank’s page, modifying code and producing new domains or advertisements after earlier versions are blocked. The same industrialization is visible outside mobile malware. ASIC removed more than 19,400 online scams in its latest financial year as deepfakes and fabricated sites created connected verification trails around fraudulent investments.

DORA Does Not Prescribe One Mobile Security Product

Zimperium argues that European rules mandate runtime application checks, device-integrity controls and changing fraud detection. That statement needs qualification. The European Banking Authority’s account of DORA says the law harmonizes ICT risk management, incident reporting, testing and third-party risk management. It does not prescribe a single mobile-security product or expressly require every institution to embed Zimperium-style protection inside an app.

DORA has applied since January 2025 and covers banks, payment firms, investment companies, insurers, trading venues and crypto-asset service providers. Its arrival has already created direct compliance costs, including CySEC supervision and penetration-testing fees for regulated firms. Mobile malware can fall within the ICT risks institutions must assess, but the precise control set depends on the entity, its systems, risk assessment and applicable technical standards.

The same caution applies to PSD3. The European Parliament and Council reached a political agreement on the PSD2 review in November 2025, according to the European Commission’s payment-services timeline. It is therefore unsafe to present “PSD3” as a settled shorthand for one universal in-app malware mandate without identifying the final legal provision, implementation timetable and the institution to which it applies.

Banks Need Device Signals and Transaction Signals Together

The security value behind Zimperium’s findings is the case for joining device, session and transaction evidence. App hardening can raise the cost of reverse engineering. Runtime controls can look for rooting, debugging, hooking frameworks, screen sharing and accessibility abuse. Backend systems can then compare those signals with transaction size, recipient history, login behavior and account risk.

No single layer is sufficient. Signature detection may miss a new malware variant, while behavior-based systems can produce false positives that block legitimate customers using accessibility tools or unusual devices. Server-side monitoring can identify an abnormal payment even when the app misses the malware. Financial institutions are increasingly consolidating those signals, as seen when Novobanco combined fraud and anti-money-laundering monitoring through Feedzai.

Operational resilience remains relevant because a response has to work after detection. Firms need a way to step up authentication, delay a transfer, contact the customer through an independent channel and investigate without turning every unusual device into an account lockout. The broader preparation burden was already visible when DORA began applying across EU financial services in January 2025.

Zimperium’s 34-family total shows how many toolsets are prepared to interact with legitimate financial apps. It does not show that every listed app failed or that every targeted user lost money. The risk lies in malware turning a trusted handset into the attack surface, then making fraudulent actions resemble the customer’s own. For banks and fintech firms, the useful measure is not how many names appear in a threat catalogue, but how quickly device compromise can be detected and converted into a safe decision before funds move.