Banking fraud now starts on the mobile device.
Our most recent malware threat research from Zimperium’s zLabs research team revealed 34 malware families targeting 1,243 mobile banking and fintech apps across 90 countries globally.
When we look at the data in Europe, the Middle East, and Africa (EMEA), it showed that 30 mobile malware families are actively targeting over 800 banking and fintech applications across 44 countries.
Threat actors are using AI at every stage of malware development, from localizing lures to scripting exploits to making phishing pages and overlays harder to tell from the real thing. Verizon's 2026 DBIR reports the same shift industry-wide, malware built with AI-assisted code is growing, and threat actors are using AI across the full attack chain rather than for a single task.
The following section details the malware families and capabilities driving fraud in EMEA, along with tactical measures mobile app security teams can adopt to defend their applications and preserve consumer trust.
Most Targeted Countries in the Region
The concentration of targeted applications across EMEA reflects where threat actors anticipate the highest return on investment, focusing heavily on the region’s major financial centers. Here is the breakdown of mobile banking apps under active attack by country.
Europe:
- United Kingdom: 72 targeted apps
- Spain: 65 targeted apps
- Italy: 57 targeted apps
- Turkey: 56 targeted apps
- Germany: 55 targeted apps
- Poland: 39 targeted apps
- France: 39 targeted apps
- Austria: 28 targeted apps
- Netherlands: 27 targeted apps
Middle East & Africa:
- United Arab Emirates: 38 targeted apps
- Kuwait: 15 targeted apps
- Qatar: 11 targeted apps
- Nigeria: 8 targeted apps
Most Active Banking Malware Operating in EMEA
Mobile banking malware strains operating in EMEA fall into two main categories. Some are global families that have expanded into the region. Others have been built specifically to target banks in the region, adapted with local language, banking habits, and payment rails specific to each country.
Global Malware Active in EMEA:
- TsarBot: Targets 450 banking apps (58% of its global activity), using Accessibility Services abuse, dynamic overlays, and screen recording.
- CopyBara: Targets 446 banking apps, leveraging vishing (TOAD), dynamic form building, and Accessibility Services abuse.
- Hook: Targets 385 banking apps, utilizing Remote Access & Device Takeover (DTO via VNC), Accessibility Services abuse, and real-time screen sharing.
Regionally Active Malware in EMEA:
- Nexus: 90% of its global targets are concentrated in EMEA, equipping attackers with SOVA-based overlay frameworks and 2FA interceptors.
- Flubot / Cabassous: Highly prevalent across European logistics lures, using SMS contact spamming, Accessibility abuse, and Play Protect disabling.
- Eventbot & MaliBot: Strains active exclusively across EMEA financial institutions, designed for keylogging, SMS interception, and unauthorized financial transfers.
Regulations in EMEA Mandating Malware Protection
Regulatory authorities across EMEA are increasingly mandating client-side or in-app protections, recognizing that traditional server-side controls, such as WAFs, MFA, and basic server detection, are no longer sufficient and are being bypassed. The three examples show where this is heading across the region.
- Europe (PSD3,DORA): Mandates strict runtime application and device integrity checks, dynamic fraud detection, and operational resilience against device-level risks.
- Middle East ( CBUAE UAE): Requires financial applications to detect malware, screen sharing, and unauthorized remote access during active banking sessions. (CBUAE: Notice No. CBUAE/FCMCP/2025/3057)
- Global Alignment (RBI India, RMiT Malaysia): Establishes explicit requirements for mobile app obfuscation, anti-tampering, and proactive risk detection.
Best Practices to Secure Your Mobile Banking App
To protect mobile banking apps against targeted trojan campaigns, security leaders should align their defenses directly with modern attack techniques:
- Harden the application: Make the app resistant to reverse engineering and tampering, including AI-assisted and agentic AI attacks. This stops attackers from inspecting the app to build targeted malware and exploits, even when they're using AI to speed up the process.
- Runtime Protection - Let the app detect and protect itself in real time from root, jailbreak, debuggers, accessibility abuse, hooking frameworks like Frida, and emulators. These signals show the device itself can't be trusted, regardless of what's running on it.
- AI-powered Malware Protection - Signatures only catch malware they've already seen. Attackers are leveraging AI to ship new, advanced variants faster than signatures get written. Apps need a combination of behavioral and AI-powered malware protection that detects and stops sophisticated malware techniques.
Click here to download the Mobile Banking Heist Report
Is Your Bank Being Targeted?
If you want to verify whether your financial organization's mobile application is actively targeted by any of these malware families, contact our research team today for a confidential assessment and brand exposure review.