Banking fraud now starts on the mobile device.
Our most recent malware threat research from Zimperium’s zLabs research team revealed 34 malware families targeting 1,243 mobile banking and fintech apps across 90 countries globally.
The threat is not evenly spread. In Latin America (LATAM), 21 malware families are actively targeting 68 core banking and fintech apps across 12 countries.
Threat actors are using AI at every stage of malware development, from localizing lures to scripting exploits to making phishing pages and overlays harder to tell from the real thing. Verizon's 2026 DBIR reports the same shift industry-wide, malware built with AI-assisted code is growing, and threat actors are using AI across the full attack chain rather than for a single task.
The following section details the malware families and capabilities driving fraud in LATAM, along with tactical measures mobile app security teams can adopt to defend their applications and preserve consumer trust.
The concentration of targeted applications across LATAM reflects where threat actors anticipate the highest return on investment, focusing heavily on the region’s major financial centers. Here is the breakdown of mobile banking apps under active attack by country.
Mobile banking malware strains operating in LATAM fall into two main categories. Some are global families that have expanded into the region. Others have been built specifically to target banks in the region, adapted with local language, banking habits, and payment rails like PIX specific to each country.
Modern mobile banking trojans in LATAM rely on several capabilities to exploit victim devices and capture sensitive data. Below are some key capabilities.
To protect mobile banking apps against targeted trojan campaigns, security leaders should align their defenses directly with modern attack techniques:
Make the app resistant to reverse engineering and tampering, from both human attackers and AI-assisted analysis. This stops attackers from inspecting the app to build targeted malware and exploits, whether they're doing it manually or using AI to speed up the process.
Enable the app during runtime to detect and protect itself from root, jailbreak, debuggers, accessibility, hooking frameworks like Frida, and emulators in real time. These signals show the device itself cannot be trusted, regardless of what's running on it.
Signatures only catch malware they've already seen. Attackers are leveraging AI to ship new advanced variants faster than signatures get written. Apps need AI-powered protection that recognizes malicious behavior, not just known threats. That's the shift from reactive detection to predictive defense
If you want to verify whether your financial organization's mobile application is actively targeted in LATAM by any of these malware families, contact our team today for a confidential assessment and brand exposure review.