Banking fraud now starts on the mobile device.
Our most recent malware threat research from Zimperium’s zLabs research team revealed 34 malware families targeting 1,243 mobile banking and fintech apps across 90 countries globally.
The threat is not evenly spread. In Asia Pacific & Japan (APJ), 24 malware families are actively targeting 214 core banking and fintech apps across 19 countries.
Threat actors are using AI at every stage of malware development, from localizing lures to scripting exploits to making phishing pages and overlays harder to tell from the real thing. Verizon's 2026 DBIR reports the same shift industry-wide, malware built with AI-assisted code is growing, and threat actors are using AI across the full attack chain rather than for a single task.
The following section details the malware families and capabilities driving fraud in APJ, along with tactical measures mobile app security teams can adopt to defend their applications and preserve consumer trust.
Most Targeted APJ Countries for Banking Malware
The concentration of targeted applications across APJ reflects where threat actors anticipate the highest return on investment, focusing heavily on the region’s major financial centers. Here is the breakdown of mobile banking apps under active attack by country.
- Australia: 50 banking apps targeted
- India: 42 banking apps targeted
- Vietnam: 23 banking apps targeted
- Malaysia: 17 banking apps targeted
- Japan: 15 banking apps targeted
- China: 14 banking apps targeted
- Indonesia: 12 banking apps targeted
- Singapore: 10 banking apps targeted
- New Zealand: 8 banking apps targeted
- Thailand: 5 banking apps targeted
Most Active Banking Malware Operating in APJ
Mobile banking malware strains operating in APJ fall into two main categories. Some are global families that have expanded into the region. Others have been built specifically to target banks in the region, adapted with local language, banking habits, and payment rails like PIX specific to each country.
Global Malware Active in APJ
- TsarBot: Targets 146 banking apps, using Accessibility Services abuse, dynamic overlays, and screen recording / lock-screen manipulation.
- CopyBara: Targets 143 banking apps, using Telephone-Oriented Attack Delivery (TOAD/vishing), dynamic form building, and Accessibility Services abuse.
- Hook: Targets 127 banking apps, using Remote Access & Device Takeover (DTO via VNC), Accessibility Services abuse, and real-time screen sharing.
- Anubis II: Targets 35 banking apps, using Accessibility Services abuse, overlay attacks, keylogging, and SMS interception.
- Hydra: Targets 29 banking apps, using Remote Access & Device Takeover (via TeamViewer), SMS exfiltration, and anti-uninstall protection.
Regionally Active Malware in APJ
- GoldDigger: Targets 51 banking apps, using Virbox Protector anti-analysis packing, Accessibility Services abuse, and fake government portal lures.
- Roamer: Targets 7 banking apps, focusing on Accessibility Services abuse, credential theft, and targeted regional bank monitoring.
- SMSSpy_Malaysia: Targets 7 banking apps, using fake e-commerce checkout portals, phishing overlays, and SMS/OTP interception.
- GigabudRAT: Targets 5 banking apps, using WebSocket-based real-time screen recording via MediaProjection and server-side mobile verification.
- HelloTeacher: Targets 3 banking apps, disguising itself as messaging apps (Viber, Kik) to capture UI component IDs and record screens.
Key Malware Capabilities Enabling Fraud in APJ
Modern mobile banking trojans in APJ rely on several capabilities to exploit victim devices and capture sensitive data. Below are some key capabilities.
- Abuse of Accessibility Services: Exploit Accessibility permissions to read on-screen UI components, capture lock patterns/passwords, and auto-grant malicious runtime permissions.
- Screen Overlay Attacks: Display phishing login screens when a victim opens targeted regional banking apps.
- Initiate and Complete Unauthorized Wire Transfers (ATS): Initiate and automate fraudulent transfers directly from the infected device.
- Remote Monitoring and Access: Record or stream the device screen in real time every second to the C2 server.
- Device Takeover (DTO): Allow attackers to remotely control gestures, swipes, and clicks to act as the victim on the device.
- OTP Interception and Manipulation: Target SMS read permissions and notifications to harvest OTPs and bypass 2FA during fake checkout or banking sessions.
- Evasion - Uses enterprise-grade commercial software protection tool, to pack and encrypt its Dalvik bytecode and native binaries.
- Anti-Analysis - Only reveals its malicious payload to visitors who enter a valid phone number, so automated scanners get skipped entirely.
Best Practices to Secure Your Mobile Banking App
To protect mobile banking apps against targeted trojan campaigns, security leaders should align their defenses directly with modern attack techniques:
- Harden the application: Make the app resistant to reverse engineering and tampering, from both human attackers and AI-assisted analysis. This stops attackers from inspecting the app to build targeted malware and exploits, whether they're doing it manually or using AI to speed up the process.
- Runtime Protection - Enable the app during runtime to detect and protect itself from root, jailbreak, debuggers, accessibility, hooking frameworks like Frida, and emulators in real time. These signals show the device itself cannot be trusted, regardless of what's running on it.
- AI-powered Malware Protection - Signatures only catch malware they've already seen. Attackers are leveraging AI to ship new advanced variants faster than signatures get written. Apps need AI-powered protection that recognizes malicious behavior, not just known threats. That's the shift from reactive detection to predictive defense
Is Your Bank Being Targeted?
If you want to verify whether your financial organization's mobile application is actively targeted in APJ by any of these malware families, contact our team today for a confidential assessment and brand exposure review.