SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
66% of mobile banking trojans now take the whole device, and 45% ask for a ransom
Zimperium's 2026 heist report tracks 34 malware families against 1,243 financial brands. The capability mix has moved from stealing credentials to owning the handset and encrypting it.
The Watch · Security desk
What happened
- Zimperium's zLabs team published its 2026 Mobile Banking Heist Report on Tuesday, covering 34 active malware families against 1,243 financial brands in 90 countries.
- It counts 25 families, described as 66% of those studied, as enabling full device control, with 76% offering transaction takeover.
- 45% of the families support financial extortion, including modules that encrypt files on the phone and demand cryptocurrency to unlock them.
Why it matters
- decision A ransomed customer handset forces banks to decide whether they own recovery for hardware they never issued, or tell the customer it is their problem. Neither answer is currently written down.
- constraint When the payment is initiated on the real device inside the real session, the device-trust signals fraud engines lean on stop separating good from bad, and detection has to move to how the screen...
- exposure Banks shipping apps without code protection are supplying the specification attackers build against, and cheap LLM-assisted reverse engineering shortens the gap between release and tailored malware.
- precedent Once device control and NFC relay are rented rather than written, they become the floor for unskilled operators rather than the ceiling for capable ones.
Encrypted files on a customer's handset do not fit anywhere in a bank's existing response process. Zimperium puts extortion capability in 45% of the families it tracks, which on a 34-family base is roughly 15 codebases carrying a module that encrypts local files and demands cryptocurrency [10][21]. A fraud team can reverse a payment. It cannot decrypt a phone, and it has no standing to send anyone to collect the device.
The report's own counting deserves a look before anyone quotes it in a board pack. Zimperium says 25 families enable full device control and calls that 66% of the families studied [3]. Twenty-five out of 34 is 73.5%, and 66% of 34 works out at 22.4 families [22]. One of those two figures is scoped to something other than the 34 active families in the headline count, and the summarised report does not say which.
The more useful pair is growth. Attacks on Android rose 56% while unique installation packages rose 271% to 255,090, which implies a prior-year base near 68,800 [5][6][18]. Package count grew roughly five times faster than attack volume [19]. That gap reads as repackaging rather than appetite: the same capability rebuilt over and over to stay ahead of signature matching, which is what happens once malware-as-a-service hands these builds to operators who did not write them [11]. Zimperium also estimates about one verification attempt in 20 at online financial services is fraudulent, or 5% [8][20], with 80% of financial fraud events now occurring on online or mobile platforms [c7b].
Concentration cuts the defender's way. TsarBot, CopyBara and Hook between them cover 60% of financial apps worldwide, with TsarBot alone aimed at 711 banking apps and 90 fintech apps such as crypto wallets [13][14]. In North America, Godfather and Teabot dominate, both built around device takeover and session manipulation to get past strong authentication [17]. The United States leads on exposure with 162 targeted banking apps [2]. Instrumenting for the techniques a handful of families use covers most of the addressable surface, even against 255,090 distinct installers.
Part of the supply side is the banks' own doing. Zimperium reports that more than 60% of mobile banking apps ship without basic code protection, handing attackers the API structure, authentication logic and transaction workflow [15], and large language models have made that reverse engineering cheaper [23]. The same tooling produces deepfakes aimed at biometric and eKYC enrolment checks, and better branded overlays [24]. Boris Cipot of Black Duck, quoted by SC Media, describes the outcome as banking trojans turning into surveillance platforms that blur the line with spyware [12].
Zimperium's recommendation is to treat handsets as full-fledged, high-risk endpoints [16]. Taken seriously, that means acquiring runtime telemetry from hardware the bank neither owns nor can image, and then acting on what it says. That is an incident-response mandate funded out of a fraud budget.
What to watch
- Whether Zimperium publishes a family-by-family breakdown that reconciles the 25-family count with the 66% share and the 34-family scope.
- Whether any bank or regulator discloses a customer-handset ransomware case, and who is recorded as owning the recovery.
- Whether NFC relay transaction hijacking starts appearing as a separate line in card network fraud reporting.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence38
- Adoption54
- Hype gap+32
- Incentives82
- Confidence44
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Zimperium's zLabs research team released the 2026 Mobile Banking Heist Report on Tuesday, based on analysis of 34 active mobile malware families targeting 1,243 financial brands across 90 countries.
- [2]
The United States had the greatest number of affected brands, with 162 U.S. banking apps targeted by mobile malware.
- [3]
Zimperium says 25 malware families, which it describes as 66% of all families studied, now enable full device control.
- [4]
Zimperium says 76% of the families studied provide transaction takeover capabilities.
- [5]
Banking trojan attacks on Android smartphones increased by 56% last year, according to Zimperium.
- [6]
The total number of unique banking trojan installation packages rose to 255,090, a 271% year-over-year increase.
- [7]
Modern banking malware focuses on initiating fraudulent transactions directly from the user's device to make them appear more legitimate, using remote control that abuses accessibility features for remote tap, swipe and keyboard input, paired with overlays or black screens to hide the activity.
- [8]
About one in every 20 verification attempts to online financial services is estimated to be fraudulent as of 2025.
- [9]
80% of financial fraud events now occur on online or mobile platforms, according to the report.
- [10]
45% of the families studied enable financial extortion, including ransomware modules that encrypt files stored on mobile devices and typically demand cryptocurrency payments to regain access.
- [11]
Session cookie theft, brand-impersonating overlays for credential theft, and transaction hijacking through NFC relay all increased in 2025, with such capabilities made easily accessible to less-skilled threat actors through malware-as-a-service offerings.
- [12]
Boris Cipot, principal security engineer at Black Duck, told SC Media there has been an evolution of banking trojans into broader account takeover and surveillance platforms, blurring the line between financial malware and spyware.
- [13]
The top three malware families by number of financial apps targeted, TsarBot, CopyBara and Hook, collectively cover 60% of all global financial apps.
- [14]
TsarBot alone targets 711 banking apps and 90 fintech apps such as cryptocurrency wallets.
- [15]
Zimperium's report states that more than 60% of mobile banking apps lack basic code protection, letting attackers understand their API structure, authentication logic and transaction workflows and tailor malware to that architecture.
- [16]
Zimperium recommends financial institutions harden code against reverse engineering, use runtime protections to detect code injection, overlay injection, keylogging, session manipulation and NFC relay attempts, recognise signs of device-level compromise, and treat mobile devices as full-fledged, high-risk endpoints rather than secondary access points.
- [17]
North America is heavily targeted by the Godfather and Teabot families, which focus on device takeover and session manipulation to bypass strong authentication controls, Zimperium said.
- [18]
A 271% year-over-year increase to 255,090 packages implies a prior-year base of about 68,800 unique installation packages.
- [19]
Installation package count grew about 4.8 times faster than attack volume last year.
- [20]
One fraudulent attempt in every 20 verification attempts is 5%.
- [21]
45% of 34 tracked families is about 15 families carrying extortion capability.
- [22]
25 of 34 families is 73.5%, about 7.5 points above the 66% share Zimperium cites, and 66% of 34 would be 22.4 families, so the two figures cannot both use the same denominator.
- [23]
Large language models make it easier for malware developers to reverse engineer targeted apps, according to Zimperium.
- [24]
Attackers use AI to create deepfakes that can bypass biometric and electronic Know Your Customer protections, and to craft more convincing branded overlays for credential theft, Zimperium said.
Sources
1 independent publisher whose own reporting we read for this story.
- scworld.comMobile banking trojans expand capabilites; 66% now allow full device takeover
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.