Mobile Banking Malware Evolution: A Threat Landscape Report
In 2025, the landscape of mobile banking malware has undergone a profound transformation, driven by increasingly sophisticated techniques that extend far beyond traditional methods of credential theft. According to research by Zimperium’s zLabs, the prevalence of mobile malware has surged, fundamentally altering the tactics employed by cybercriminals. This report highlights the findings of their extensive analysis, which explored threats targeting over 1,243 financial institutions across 90 nations, revealing alarming trends in the frequency and complexity of attacks.
The research indicates that a staggering 66% of the 34 active mobile malware families analyzed are now capable of delivering complete control over the device. Additionally, 76% of these malware types facilitate transaction takeover, while 45% incorporate financial extortion capabilities, such as ransomware modules. This evolution in malware functionality underscores a shift in the focus of attackers, who are now able to initiate fraudulent actions directly from compromised devices.
The magnitude of the threat has escalated dramatically, with unique banking trojan installation packages skyrocketing to an unprecedented 255,090 in 2025. This figure represents a staggering 271% increase compared to the previous year. Alarmingly, it has been estimated that roughly one in every 20 verification attempts to online financial services is fraudulent. Perhaps most concerning is that 80% of all financial fraud events now occur through online or mobile platforms. Among the most notorious malware families currently in circulation—TsarBot, CopyBara, and Hook—these three collectively target a remarkable 60% of all global financial applications. TsarBot alone has been identified as affecting 711 banking apps as well as 90 fintech applications, including various cryptocurrency wallets.
Whereas earlier iterations of mobile banking malware primarily functioned by intercepting notifications or utilizing remote screensharing to gather user credentials, the modern threats are far more intricate. Today’s malware is focused on executing fraudulent transactions straight from the compromised devices, making these actions appear legitimate enough to evade fraud detection systems. Attackers exploit accessibility features to perform remote taps, swipes, and keyboard inputs while often employing overlays or black screens to obscure malicious activities from the user’s view. These evolved techniques include theft of session cookies, creation of brand-impersonating overlays intended for credential harvesting, and transaction hijacking through NFC relay attacks. Such capabilities are increasingly available through malware-as-a-service offerings, significantly lowering the barrier for entry for less skilled cybercriminals.
The role of artificial intelligence in the evolution of mobile banking malware is becoming increasingly pronounced. Attackers now use large language models to reverse engineer targeted applications, finding vulnerabilities in the systems that could be exploited. Alarmingly, over 60% of mobile banking applications lack basic code protection, which would normally restrict the analysis of their API structures, authentication protocols, and transaction workflows. AI technologies also facilitate the creation of sophisticated deepfakes that can bypass biometric verification, as well as assist in crafting more convincing branded overlays aimed at credential theft. Particularly in North America, the Godfather and Teabot malware families pose significant risks by focusing on device takeover and session manipulation to circumvent robust authentication controls.
In light of these extraordinary developments, Zimperium has issued recommendations for financial institutions to fortify their defenses against such emerging threats. Experts suggest that organizations must implement enhanced coding practices to prevent reverse engineering and establish runtime protections capable of identifying malicious activities such as code injection, overlay injection, keylogging, session manipulation, and NFC relay attempts. Mobile devices must be treated as high-risk endpoints, necessitating mobile threat defense solutions designed to detect and respond to behavioral anomalies, rather than relying solely on traditional signature-based detection methods.
Moreover, financial organizations must enforce stringent policies that prohibit sideloading and installations from untrusted sources, as this remains a primary infection vector for mobile banking malware. By adopting a proactive and layered security approach, institutions can better safeguard themselves against the rapidly evolving landscape of mobile banking threats.
In summary, the report sheds light on the innovative techniques employed by cybercriminals in the mobile banking arena, emphasizing the urgent need for strengthened defenses to protect consumers and financial institutions alike from the ever-growing tide of cyber threats.
Source: Zimperium’s Research

