Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

66% of mobile banking trojans now take the whole device, and 45% ask for a ransom

Zimperium's 2026 heist report tracks 34 malware families against 1,243 financial brands. The capability mix has moved from stealing credentials to owning the handset and encrypting it.

The Watch · Security desk

How we use AISend a correction

What happened

  • Zimperium's zLabs team published its 2026 Mobile Banking Heist Report on Tuesday, covering 34 active malware families against 1,243 financial brands in 90 countries.
  • It counts 25 families, described as 66% of those studied, as enabling full device control, with 76% offering transaction takeover.
  • 45% of the families support financial extortion, including modules that encrypt files on the phone and demand cryptocurrency to unlock them.

Why it matters

  • decision A ransomed customer handset forces banks to decide whether they own recovery for hardware they never issued, or tell the customer it is their problem. Neither answer is currently written down.
  • constraint When the payment is initiated on the real device inside the real session, the device-trust signals fraud engines lean on stop separating good from bad, and detection has to move to how the screen...
  • exposure Banks shipping apps without code protection are supplying the specification attackers build against, and cheap LLM-assisted reverse engineering shortens the gap between release and tailored malware.
  • precedent Once device control and NFC relay are rented rather than written, they become the floor for unskilled operators rather than the ceiling for capable ones.

Encrypted files on a customer's handset do not fit anywhere in a bank's existing response process. Zimperium puts extortion capability in 45% of the families it tracks, which on a 34-family base is roughly 15 codebases carrying a module that encrypts local files and demands cryptocurrency [10][21]. A fraud team can reverse a payment. It cannot decrypt a phone, and it has no standing to send anyone to collect the device.

The report's own counting deserves a look before anyone quotes it in a board pack. Zimperium says 25 families enable full device control and calls that 66% of the families studied [3]. Twenty-five out of 34 is 73.5%, and 66% of 34 works out at 22.4 families [22]. One of those two figures is scoped to something other than the 34 active families in the headline count, and the summarised report does not say which.

The more useful pair is growth. Attacks on Android rose 56% while unique installation packages rose 271% to 255,090, which implies a prior-year base near 68,800 [5][6][18]. Package count grew roughly five times faster than attack volume [19]. That gap reads as repackaging rather than appetite: the same capability rebuilt over and over to stay ahead of signature matching, which is what happens once malware-as-a-service hands these builds to operators who did not write them [11]. Zimperium also estimates about one verification attempt in 20 at online financial services is fraudulent, or 5% [8][20], with 80% of financial fraud events now occurring on online or mobile platforms [c7b].

Concentration cuts the defender's way. TsarBot, CopyBara and Hook between them cover 60% of financial apps worldwide, with TsarBot alone aimed at 711 banking apps and 90 fintech apps such as crypto wallets [13][14]. In North America, Godfather and Teabot dominate, both built around device takeover and session manipulation to get past strong authentication [17]. The United States leads on exposure with 162 targeted banking apps [2]. Instrumenting for the techniques a handful of families use covers most of the addressable surface, even against 255,090 distinct installers.

Part of the supply side is the banks' own doing. Zimperium reports that more than 60% of mobile banking apps ship without basic code protection, handing attackers the API structure, authentication logic and transaction workflow [15], and large language models have made that reverse engineering cheaper [23]. The same tooling produces deepfakes aimed at biometric and eKYC enrolment checks, and better branded overlays [24]. Boris Cipot of Black Duck, quoted by SC Media, describes the outcome as banking trojans turning into surveillance platforms that blur the line with spyware [12].

Zimperium's recommendation is to treat handsets as full-fledged, high-risk endpoints [16]. Taken seriously, that means acquiring runtime telemetry from hardware the bank neither owns nor can image, and then acting on what it says. That is an incident-response mandate funded out of a fraud budget.

What to watch

  • Whether Zimperium publishes a family-by-family breakdown that reconciles the 25-family count with the 66% share and the 34-family scope.
  • Whether any bank or regulator discloses a customer-handset ransomware case, and who is recorded as owning the recovery.
  • Whether NFC relay transaction hijacking starts appearing as a separate line in card network fraud reporting.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence38
Adoption54
Hype gap+32
Incentives82
Confidence44
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Zimperium's zLabs research team released the 2026 Mobile Banking Heist Report on Tuesday, based on analysis of 34 active mobile malware families targeting 1,243 financial brands across 90 countries.

    ReportedSupportedView cited source
  2. [2]

    The United States had the greatest number of affected brands, with 162 U.S. banking apps targeted by mobile malware.

    ReportedSupportedView cited source
  3. [3]

    Zimperium says 25 malware families, which it describes as 66% of all families studied, now enable full device control.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. scworld.com

    1 article · August 26, 2026

    Mobile banking trojans expand capabilites; 66% now allow full device takeover

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories