Smartphones now hold vast amounts of sensitive personal and financial data, including passwords private communications, and work-related data, making them prime targets for cybercriminals. This has led mobile banking Trojans and other malicious mobile software to proliferate and spread rapidly over the past years, as attackers shift their focus to mobile devices for greater profits.
In Q1 2026, global cybersecurity and anti-virus company Kaspersky said it detected an alarming 162,275 new mobile banking Trojan installation packages. The figure is more than twice the number recorded across the whole of 2024, and roughly two-thirds of the 2025 annual total in a single quarter.
Mobile banking Trojans are malicious software packages often disguised as legitimate apps or hidden inside seemingly harmless downloads. These software are designed to steal credentials from banking and finance apps, typically through overlay attacks that place fake login screens over real ones, read screen content, and intercept SMS one-time codes to steal money directly from victims’ financial accounts.
Mobile banking Trojans are now the most prevalent type malicious mobile applications. In Q1 2026, they accounted for a staggering 52.96% of all malicious mobile applications detected by Kaspersky, up from roughly 31% across 2025 as a whole.
These findings build on a surge of mobile banking Trojan attacks in 2025. Last year, the number of new Trojan banker installation packages for Android increased by 271% year-over-year (YoY), reaching 255,090.

The evolution of mobile banking malware
These findings align with those of other research. In August 2026, American mobile security company Zimperium released the 2026 Mobile Banking Heist Report, which analyzed 34 active mobile malware families targeting 1,243 financial brands across 90 countries.

The research highlights that while earlier generations of banking Trojans focused on credential theft, account takeover and evading detection, newer Trojans are more sophisticated and are now able to control both the victim’s account and their device. In particular, screen overlays have become a persistent tactic of new and modified malware families. In this tactic, attackers are able to invisibly capture all data entered into the device.
In 2026, banking malware has escalated to deploy ransomware, encrypting device files and demanding Bitcoin, evolving from fraud into extortion.

The report highlights three malware families, namely TsarBot, CopyBara, Hydra and Hook, that dominate the global volume of attacks across all regions. These families use overlay attacks, accessibility abuse, and command-and-control infrastructure to steal financial credentials and enable account takeover on infected devices.
Accessibility abuse takes place when a harmful app tricks a user into giving it accessibility permissions, turning assistive features into a tool for data theft and fraud. Command-and-control infrastructure, meanwhile, is a set of tools and techniques used by attackers to communicate with and direct malware on compromised devices after an initial breach.
A look at the geographical distribution of targeted banking apps reveals that malware operators follow digital maturity. In particular, the highest concentrations are in markets with strong mobile banking adoption, high transaction volume, and Android dominated device ecosystems, including the US, which had 162 banking apps under active targeting at the time of the study, the highest concentration of any single country globally. The UK follows with 69.
Fast-digitizing markets such as Vietnam, Peru, Malaysia, and the United Arab Emirates (UAE) are also notable targets, with 23, 16, 17, and 35 targeted banking applications, respectively.

Evolving tactics
Over the past years, smartphone attacks have surged, emerging as one of the primary targets for cybercriminals. This shift has been driven by the rise of infrastructure-as-a-service and code sharing, which have significantly reduced the cost of entry to cyberattacks, industrializing attacks at a scale no single institution can effectively counter alone.
Last year alone, Kaspersky solutions successfully blocked over 14 million mobile attacks globally, averaging approximately 1.17 million attacks every month and underscoring the sheer scale of mobile-targeted cybercrime.
In addition to cyberattacks, scams are another concerning threat, especially in Southeast Asia. The GSMA ASEAN Consumer Scam Report 2026, covering Indonesia, Malaysia, the Philippines, Singapore, Thailand and Vietnam and released earlier this week, found that 8% of surveyed consumers had been scammed in the previous 12 months. 96% of respondents expressed concerns about being scammed or hacked.
Among those who said they had been scammed, 68% lost money. Of that group, 82% were unable to recover any of their losses, while only 10% recovered all their losses.
The report also highlights the increasing sophistication of AI in cyberattacks. It found that 89% of respondents said that they had seen AI used in scams, while the remaining 11% could not tell whether AI was involved in the scams they met, underscoring the advanced capabilities of these technologies to deceive victims.
Fake AI-generated images were recognized by 52% of respondents, deepfake video by 48%, fake AI profiles and adverts by 46%, AI-written messaging by 43%, cloned voices of celebrities or officials by 42%, and AI chatbots holding a realistic conversation by 37%.

Featured image: Edited by Fintech News Singapore, based on image by thanyakij-12 via Magnific


