Zimperium Finds 34 Android Malware Families Targeting 1,243 Banking Apps

2 hour ago 1 sources neutral

Key takeaways:

  • EMEA's malware concentration signals urgent mobile security upgrades for European banks.
  • 67% fraud surge makes mobile security a DORA compliance prerequisite for crypto firms.
  • Third-party incident concentration demands infrastructure mapping beyond vendor diversification.

Zimperium’s zLabs researchers have identified 34 Android malware families carrying tools or targeting data for 1,243 banking and fintech applications across 90 countries in 2025. The total refers to potential targets built into malware campaigns, not confirmed breaches or compromised institutions. Europe, the Middle East and Africa were the dominant theater, accounting for more than 800 app targets and 30 of the 34 families. The United Kingdom led EMEA with 72 targeted apps, followed by Spain with 65, Italy with 57, Turkey with 56 and Germany with 55.

Zimperium said the region’s target lists overlap across campaigns. TsarBot targeted 450 banking apps in EMEA, CopyBara targeted 446 and Hook targeted 385, but adding those figures would double-count apps. The report described TsarBot using screen recording, attack-generated overlays and abuse of Android Accessibility Services; CopyBara adding phone-based social engineering; and Hook offering remote access through virtual network computing and live screen sharing.

The common attack path begins before a user opens a banking app. Victims install malicious Android packages through fake downloads, phishing links, messaging lures or compromised distribution routes. The malware then seeks permissions to read notifications, text messages, screen content or accessibility functions. Overlays can place counterfeit login screens over legitimate apps to steal credentials. Notification or SMS access can expose one-time authentication codes. Accessibility privileges can let malware read screen elements, press buttons or approve prompts, while remote-control functions let operators act through the victim’s device. A comparable Belgian network allegedly used phone calls and remote-access software in a phishing operation worth more than €500,000.

The report also highlighted regional specialization. Nexus combines overlay technology with two-factor authentication interception and has 90% of its global targets in EMEA. FluBot and Cabassous use European delivery and logistics lures, while EventBot and MaliBot target EMEA financial institutions with keylogging, SMS interception and unauthorized-transfer capabilities. The United States moved in the opposite direction: 162 US banking applications were under active targeting in Zimperium’s broader 2026 Banking Heist release, up from 109 in 2023. The company said Android malware-driven fraudulent financial transactions rose 67% year over year, though it did not disclose the underlying transaction count or country-level loss total.

Zimperium argued that AI speeds up attacks by translating and localizing lures, writing exploit scripts and making phishing pages resemble real financial apps, but the core techniques predate generative AI. The 2026 Verizon Data Breach Investigations Report said vulnerability exploitation became the entry point in 31% of breaches and that mobile social-engineering attacks through text messages and calls achieved a 40% higher success rate than traditional email phishing. The same industrialization is visible outside mobile malware: ASIC removed more than 19,400 online scams in its latest financial year as deepfakes and fabricated sites created connected verification trails around fraudulent investments.

Zimperium also addressed European rules, arguing that DORA mandates runtime application checks, device-integrity controls and changing fraud detection. That claim needs qualification. The European Banking Authority has said DORA harmonizes ICT risk management, incident reporting, testing and third-party risk management, but it does not prescribe a single mobile-security product. DORA has applied since January 2025 and covers banks, payment firms, investment companies, insurers, trading venues and crypto-asset service providers. The same caution applies to PSD3: although the European Parliament and Council reached a political agreement on the PSD2 review in November 2025, presenting PSD3 as a settled universal in-app malware mandate would be premature without identifying the final legal provision and implementation timetable.

Zimperium’s broader conclusion is that financial institutions should combine device, session and transaction evidence. App hardening can raise the cost of reverse engineering. Runtime controls can look for rooting, debugging, hooking frameworks, screen sharing and accessibility abuse. Backend systems can compare those signals with transaction size, recipient history, login behavior and account risk. No single layer is sufficient: signature detection may miss new variants, while behavior-based systems can produce false positives that block legitimate customers using accessibility tools or unusual devices.

The cybersecurity analysis extends beyond mobile malware into dependency-risk accounting. Financial firms have traditionally measured cyber risk through assets, vulnerabilities, incidents and controls, but that model becomes incomplete when payment flows cross cloud services, market-data providers, identity systems, outsourced operations, APIs and telecommunications links. The more useful question is shifting from “What systems do we protect?” to “Which dependencies must remain trustworthy for a financial service to complete correctly?”

The European Supervisory Authorities’ first DORA incident report, published in June 2026, recorded 3,383 major ICT-related incidents across the EU financial sector for 2025, with roughly one third having cross-border impact. System failures and external events were the largest drivers, and almost 29% of major incidents originated with third-party providers. Those numbers show why cyber resilience cannot be reduced to malware prevention. The important object to protect is the financial service and the chain of dependencies that makes it possible.

The analysis also stressed that third-party risk is really dependency concentration. Two vendors can appear independent while relying on the same cloud region, DNS provider, identity service or telecommunications path. A bank can diversify contracts without diversifying the underlying failure domain. Security architecture should therefore map dependencies beneath the contractual layer, including shared control planes, authentication paths, external APIs, data feeds, privileged administration channels and recovery dependencies. Strong controls should help answer whether the right identity initiated an action, whether the instruction changed, whether the destination was expected, and whether the transaction followed an approved path. This creates a distinction between system compromise and business compromise: attackers do not always need to take a platform offline; the more valuable outcome may be to remain inside normal workflows while altering who gets paid, what data is trusted, or which action appears legitimate.

Sources
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.