Aug 27, 2026

Mobile Fraud in 2026: Malware is Actively Targeting Mobile Banking Apps in LATAM

Banking fraud now starts on the mobile device.

Our most recent malware threat research from Zimperium’s zLabs research team revealed 34 malware families targeting 1,243 mobile banking and fintech apps across 90 countries globally.

The threat is not evenly spread. In Latin America (LATAM), 21 malware families are actively targeting 68 core banking and fintech apps across 12 countries.

Threat actors are using AI at every stage of malware development, from localizing lures to scripting exploits to making phishing pages and overlays harder to tell from the real thing. Verizon's 2026 DBIR reports the same shift industry-wide, malware built with AI-assisted code is growing, and threat actors are using AI across the full attack chain rather than for a single task.

The following section details the malware families and capabilities driving fraud in LATAM, along with tactical measures mobile app security teams can adopt to defend their applications and preserve consumer trust.

Most Targeted LATAM Countries by Banking Malware

The concentration of targeted applications across LATAM reflects where threat actors anticipate the highest return on investment, focusing heavily on the region’s major financial centers. Here is the breakdown of mobile banking apps under active attack by country.

1LATAM

Most Active Banking Malware Operating in LATAM

Mobile banking malware strains operating in LATAM fall into two main categories. Some are global families that have expanded into the region. Others have been built specifically to target banks in the region, adapted with local language, banking habits, and payment rails like PIX specific to each country.

Global Malware Active in LATAM:

    • TsarBot: Targets 49 banking apps, using Accessibility Services abuse, dynamic overlays, and screen recording / lock-screen manipulation.
    • CopyBara: Targets 48 banking apps, using Telephone-Oriented Attack Delivery (TOAD/vishing), dynamic form building, and Accessibility Services abuse.
    • Hook: Targets 34 banking apps, using Remote Access & Device Takeover (DTO via VNC), Accessibility Services abuse, and real-time screen sharing.
    • zAnubis: Targets 23 banking apps, using Accessibility Services abuse, keylogging, and phishing overlays.
    • Hydra: Targets 14 banking apps, using Remote Access & Device Takeover (via TeamViewer), SMS exfiltration, and anti-uninstall protection.

Regionally Active Malware in LATAM

    • PixPirate: Targets 12 banking apps, using Accessibility Services abuse to manipulate and intercept local Pix instant payment transfers.
    • BrasDex: Targets 8 banking apps, using automated credential theft and ATS (Automatic Transfer System) engines to silently execute unauthorized bank transfers.
    • GoatRat: Targets 7 banking apps, focusing on Automated Transfer System (ATS) fraud and overlay attacks.
    • PixBankBot: Targets 6 banking apps, using dynamic overlays designed to capture session credentials and transfer funds via local payment rails.

Key Malware Capabilities Enabling Fraud in LATAM

Modern mobile banking trojans in LATAM rely on several capabilities to exploit victim devices and capture sensitive data. Below are some key capabilities.

    • Abuse of Accessibility Services. Malware misuses Android's built-in accessibility features to read screen content, log keystrokes, and control the device without the user's knowledge.
    • Screen Overlay Attacks. A fake screen is placed over the real banking app to capture login credentials and card details as the victim types them.
    • Initiate and Complete Unauthorized Wire Transfers (ATS). Automatic Transfer System capabilities let malware initiate and approve fraudulent transactions directly from the device without alerting the victim.
    • Remote Monitoring and Access of the Device. Attackers view the device screen in real time, letting them watch the victim's activity and time their attack.
    • Device Takeover (DTO). Full remote control of the device lets attackers act as the victim, bypassing behavioral and biometric checks that assume the real user is in control.
    • One Time Passcode (OTP) Interception and Manipulation. Malware reads or redirects SMS and push notification messages to capture one-time passcodes and bypass two-factor authentication.
    • Evasion and Anti-Analysis. Malware hides from security tools and resists reverse engineering, letting it stay active on a device undetected for longer

Best Practices to Secure Your Mobile Banking App

To protect mobile banking apps against targeted trojan campaigns, security leaders should align their defenses directly with modern attack techniques:

Harden the application

Make the app resistant to reverse engineering and tampering, from both human attackers and AI-assisted analysis. This stops attackers from inspecting the app to build targeted malware and exploits, whether they're doing it manually or using AI to speed up the process.

Runtime Protection

Enable the app during runtime to detect and protect itself from root, jailbreak, debuggers, accessibility, hooking frameworks like Frida, and emulators in real time. These signals show the device itself cannot be trusted, regardless of what's running on it.

AI-powered Malware Protection

Signatures only catch malware they've already seen. Attackers are leveraging AI to ship new advanced variants faster than signatures get written. Apps need AI-powered protection that recognizes malicious behavior, not just known threats. That's the shift from reactive detection to predictive defense

Is Your Bank Being Targeted?

If you want to verify whether your financial organization's mobile application is actively targeted in LATAM by any of these malware families, contact our team today for a confidential assessment and brand exposure review.