Invest1 distinct publisher2 min readPublished
The Georgia Tech corpus says the handset belongs to the attacker while Regulation E says the loss belongs to the bank, which makes every extra authentication factor pushed to that same phone a purchase with no yield.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The split inside that 159 is where the underwriting sits. The samples were built to harvest credentials from 147 of the apps [5], and stolen credentials still have to be spent somewhere, which leaves the bank's server-side scoring one more look at the transaction; for 112 apps that second look is the entire defense [2]. In the other 35 the transfer starts on the customer's own handset inside the customer's own session, 22% of the tested set [1], and there is no login anomaly to catch because nothing anomalous happened at login.
Android's accessibility service, built so software can read the screen and tap on a user's behalf for people with disabilities, is what makes most of this work [7], and the same access covers the channels banks use to check their work: SMS passcodes, email, push notifications and in-app approvals are all readable and editable once the device is taken over [15]. Eward Driehuis of ThreatFabric puts it as an engineering constraint rather than a warning, saying multifactor authentication becomes "less efficient or even fully compromised if additional factors are available from the same device" [14]. Read that as a budget line. A dollar spent adding a fourth on-device factor is a dollar not spent on an off-device factor or on server-side behavioural scoring, and on this evidence only the second pair is still standing.
The most useful number here is one nobody has. Singapore, Malaysia, India and Hong Kong already require protections inside the banking app [16], and Driehuis says ThreatFabric's intelligence "does not show a significant decrease in mobile malware activity" in those regions [17]. This is probably too harsh a reading of one vendor's telemetry, and ThreatFabric sells fraud-detection software [19], so its account of its own data is not disinterested. But four mandates with no measurable decline is the nearest thing to a controlled test anyone has run on app hardening, and it suggests hardening is a compliance cost that does not price as a control.
The evidence has dated edges. The sample window closed in December 2022 [1], so anything Android has tightened since is invisible in these percentages. Zimperium's count of the U.S. leading the world in banking apps under active targeting arrives without an absolute number attached [11]. And the 54% of customers who now bank primarily by app, per Morning Consult [12], is a mobile-first population that includes iPhones, while the corpus is Android.
Which leaves 35 of 159. Nothing in the source material argues with it.
Ranked by verification strength, evidence, and original report placement.
Research released this week by mobile security vendor Zimperium counts more banking apps under active targeting in the U.S. than in any other country.
Eward Driehuis, vice president of fraud engineering at ThreatFabric, said most such malware is "actually taking over the device" and that malware makes multifactor authentication "less efficient or even fully compromised if additional factors are available from the same device."
Malware on a compromised phone can see and manipulate text messages carrying one-time passcodes, emails, push notifications and in-app transaction approvals.
Driehuis said ThreatFabric's intelligence "does not show a significant decrease in mobile malware activity" in those regions.
A group led by Brendan Saltaformaggio, an associate professor at Georgia Tech, collected malware samples from VirusTotal between August and December 2022 and ran them on Android phones.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quantified academic corpus, reported at one remove
The core findings are unusually specific and internally consistent: a named researcher, a defined collection window, 9,850 executed samples, and per-app counts (159 targeted, 147 credential-harvesting, 35 unassisted transfer, 98 alert-suppressing, 9,102/9,024 persistence). Liability claims are grounded in cited CFPB Regulation E FAQ material. Deductions: the cluster contains only one publication, the underlying paper is not quoted or linked in the supplied text, the corpus dates from 2022 while the targeting counts are 2026, and the trend assertions rest on two commercial vendors' private telemetry rather than reproducible data.
Widely deployed attack surface, real channel scale
Adoption here is the real-world footprint of the phenomenon rather than of a product, and it is measured on both sides: thousands of live samples targeting 159 genuine bank apps in the corpus, 162 U.S. apps under active targeting per Zimperium versus 69 in the UK, and 54% of bank customers primarily using mobile apps. The expansion into small and midsize U.S. institutions is asserted directionally without absolute counts, and no data quantifies how many customers or transfers are actually affected, so this is short of fully measured deployment.
Slightly overstated by headline generalization
Findings and framing are mostly proportionate - the article discloses that Zimperium's U.S. lead partly reflects the sheer number of U.S. institutions and states outright that no public dataset separates malware-driven transfers, leaving total exposure unmeasured. The mild overstatement is temporal and rhetorical: a 2022 sample corpus is presented as the current state of 'U.S. bank apps are now top target', the 35-of-159 capability is a laboratory capability rather than an observed loss volume, and the two corroborating trend sources both sell fraud-detection products. No claim in the cluster is contradicted by another supplied source.
Vendor-supplied trend data, disclosed
The two sources carrying the forward-looking claims are commercially interested: ThreatFabric sells fraud-detection software and supplies the MFA-compromise, hardening-ineffectiveness and target-expansion assertions, while Zimperium is a mobile security vendor whose report supplies the U.S.-is-top-target count. Both have a direct interest in banks perceiving device-side controls as insufficient. Mitigating factors: the article discloses ThreatFabric's business model, the quantitative core comes from an academic team with different incentives, and the liability analysis rests on regulator documents.
Specific but single-publisher
Confidence is limited chiefly by cluster structure: one publisher, one source item, no independent reporting to cross-check the corpus counts, the vendor telemetry or the Regulation E reading. Within that constraint the material is highly specific, attributed to named individuals and documents, and the article flags its own measurement gap, which supports moderate rather than low confidence.
security
66% of mobile banking trojans now take the whole device, and 45% ask for a ransom1 distinct publisher
security
Manic's mesh relay moves stolen data phone to phone, no internet path required1 distinct publisher
build
Manic hands stolen PINs to the phone next to it, up to four hops from any egress point1 distinct publisher
build
ToxicPanda 2.0 talks its way to an ADB shell, so wireless debugging belongs in the baseline1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026