Zimperium

Mobile Banking Fraud 2026: Malware Is Actively Targeting Mobile Banking Apps in the US and Canada

Written by Krishna Vishnubhotla | Sep 02, 2026

Banking fraud now starts on the mobile device.

Our most recent malware threat research from Zimperium’s zLabs research team revealed 34 malware families targeting 1,243 mobile banking and fintech apps across 90 countries globally.

When we look at the data in the US and Canada, it showed that 26 mobile malware families are actively targeting over 189 banking and fintech applications.

Threat actors are using AI at every stage of malware development, from localizing lures to scripting exploits to making phishing pages and overlays harder to tell from the real thing. Verizon's 2026 DBIR reports the same shift industry-wide, malware built with AI-assisted code is growing, and threat actors are using AI across the full attack chain rather than for a single task.

The following section details the malware families and capabilities driving fraud in North America and Canada, along with tactical measures mobile app security teams can adopt to defend their applications and preserve consumer trust.

Malware Impact in the Region

Banking Malware Impact in the United States

162 banking and fintech apps are being targeted by 26 active malware families in the United States. The targeted financial brands are headquartered across 22 states. Below are the top 10:

    • California (CA)
    • New York (NY)
    • North Carolina (NC)
    • Texas (TX)
    • Washington (WA)
    • Arizona (AZ)
    • Pennsylvania (PA)
    • Ohio (OH)
    • Florida (FL)
    • Tennessee (TN)

Banking Malware Impact in Canada

27 banking and fintech apps are being targeted by 20 active malware families in Canada. The targeted financial brands are headquartered across 5 provinces. They are shown below:

    • Ontario (ON)
    • British Columbia (BC)
    • Alberta (AB)
    • Quebec (QC)
    • Saskatchewan (SK)

Most Active Banking Malware in North America and Canada

Based on the report 26 distinct malware strains are actively targeting banking apps in the United States. 20 of these also operate in Canada. Six, however, are US-only: Medusa, Nexus, Android/Bianlian Botnet, Roamer, Godfather, and Ermac.

Below are the top 7 most active malware families operating in North America and Canada:

    • TsarBot: Uses multi-port WebSockets to record screens, manipulate lock-screen credentials, and execute automated overlay phishing.
    • CopyBara: Operates via Telephone-Oriented Attack Delivery (TOAD/vishing), generating dynamic, customized fake forms on the fly based on instructions from live operators.
    • Teabot (Anatsa): Uses keylogging, GitHub-hosted payloads, real-time screen sharing, and overlay phishing pages.
    • Hook: Built on Ermac code, utilizing bi-directional Socket.IO WebSockets to provide full Virtual Network Computing (VNC) and Device Takeover (DTO) capabilities.
    • GodFather: Modernized from Anubis code, using automated background tasks every few seconds to exfiltrate Google Authenticator 2FA codes and record screens.
    • ExobotCompact.D / Octo: Operates using compact bytecode payloads, detecting active foreground banking apps to trigger targeted overlay login pages.
    • Hydra: Leverages Remote Access & Device Takeover (via TeamViewer), SMS exfiltration, anti-uninstall protections, and bulk SMS spamming.

Best Practices to Secure Your Mobile Banking App

To protect mobile banking apps against targeted trojan campaigns, security leaders should align their defenses directly with modern attack techniques:

    • Harden the application: Make the app resistant to reverse engineering and tampering, from both human attackers and AI-assisted analysis. This stops attackers from inspecting the app to build targeted malware and exploits, whether they're doing it manually or using AI to speed up the process.
    • Runtime Protection - Enable the app during runtime to detect and protect itself from root, jailbreak, debuggers, accessibility, hooking frameworks like Frida, and emulators in real time. These signals help the app ensure the device is safe and not vulnerable to fraud before allowing high-risk transactions.
    • AI-powered Malware Protection - Signatures only catch malware they've already seen. Attackers are leveraging AI to ship new advanced variants faster than signatures get written. Apps need AI-powered protection that recognizes malicious behavior, not just known threats. That's the shift from reactive detection to predictive defense

Is Your Bank Being Targeted?

If you want to verify whether your financial organization's mobile application is actively targeted by any of these malware families, contact our research team today for a confidential assessment and brand exposure review.