Wednesday , June 25 2025
Malware

Across 61 countries
29 malware families target 1,800 banking apps worldwide

The research uncovered that 29 malware families targeted 1,800 banking applications across 61 countries last year. In comparison, the 2022 report uncovered 10 prolific malware families targeting 600 banking apps.

Traditional banking apps are the main target, with 1,103 compromised apps, accounting for 61% of the total. FinTech and Trading apps make up the remaining 39%.

WhatsApp banned on all US House of Representatives devices

The U.S. House of Representatives has banned congressional staff from using WhatsApp on government devices due to security concerns, as...
Read More
WhatsApp banned on all US House of Representatives devices

Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

Kaspersky found a new mobile malware dubbed SparkKitty in Google Play and Apple App Store apps, targeting Android and iOS....
Read More
Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

OWASP has released its AI Testing Guide, a framework to help organizations find and fix vulnerabilities specific to AI systems....
Read More
OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

In a major milestone for the country’s digital infrastructure, Axentec PLC has officially launched Axentec Cloud, Bangladesh’s first Tier-4 cloud...
Read More
Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

Hackers Bypass Gmail MFA With App-Specific Password Reuse

A hacking group reportedly linked to Russian government has been discovered using a new phishing method that bypasses two-factor authentication...
Read More
Hackers Bypass Gmail MFA With App-Specific Password Reuse

Russia detects first SuperCard malware attacks via NFC

Russian cybersecurity experts discovered the first local data theft attacks using a modified version of legitimate near field communication (NFC)...
Read More
Russia detects first SuperCard malware attacks via NFC

Income Property Investments exposes 170,000+ Individuals record

Cybersecurity researcher Jeremiah Fowler discovered an unsecured database with 170,360 records belonging to a real estate company. It contained personal...
Read More
Income Property Investments exposes 170,000+ Individuals record

ALERT (CVE: 2023-28771)
Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

GreyNoise found attempts to exploit CVE-2023-28771, a vulnerability in Zyxel's IKE affecting UDP port 500. The attack centers around CVE-2023-28771,...
Read More
ALERT (CVE: 2023-28771)  Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

CISA Flags Active Exploits in Apple iOS and TP-Link Routers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included two high-risk vulnerabilities in its Known Exploited Vulnerabilities (KEV)...
Read More
CISA Flags Active Exploits in Apple iOS and TP-Link Routers

10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

SafetyDetectives’ Cybersecurity Team discovered a public post on a clear web forum in which a threat actor claimed to have...
Read More
10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

The top banking malware families are Hook, Godfather, and Teabot. These families have targeted the most banks. In the 2022 report, 19 malware families were mentioned, and they have developed new capabilities. Additionally, ten new families have been recognized as a threat in 2023.

Banking trojans are getting smarter and more successful at tricking mobile devices. They can avoid security measures and go undetected. Traditional security methods are struggling to keep up with the growing threat.

US banks are the most targeted by financially motivated cyber threats. 109 banks in the US were targeted by banking malware in 2023. In comparison, the UK and Italy had 48 and 44 targeted banks, respectively. Additionally, trojans are now targeting more than just banking apps. They are also targeting cryptocurrency, social media, and messaging apps.

“Mobile banking security is currently in a high-stakes scenario, with numerous threat actors posing substantial risks. This report shows the sophistication, adaptability, and scalability of banking trojans and their widespread impact on mobile applications across the globe,” said Nico Chiaraviglio, Chief Scientist of Zimperium. “We are seeing that they are finding ways to bypass traditional defenses, which is why it is critical that banking and financial organizations employ comprehensive, real-time, on-device mobile security to combat these intelligent adversaries.

New capabilities in emerging banking malware families:

Automated Transfer System (ATS):  A technique that facilitates unauthorized transfers of money.
Telephone-based Attack Delivery (TOAD): Involves a follow-up call to gain trust and download more malware.
Screen Sharing: Being able to remotely control a victim’s device without having physical access to it.
Malware-as-a-Service (MaaS): An online business model offering malware creation tools for rent or sale, facilitating easy execution of cyberattacks.

These findings show that the mobile threat landscape is growing and changing. We need to prioritize mobile security and have a comprehensive strategy that focuses on fighting mobile banking trojans. Instead of just reacting to threats, organizations should be proactive and have real-time visibility and protection against threats. This means moving away from a standard-based approach and considering real-world threats.

“By monitoring millions of devices, Zimperium has identified alarming figures highlighting how widespread, global, and successful mobile banking malware can be,” said Jon Paterson, CTO at Zimperium. “Cybercriminals continue to target traditional banking apps and FinTech & Trading apps because of the widespread use of dated app security techniques that are falling short.”

Check Also

170000

Income Property Investments exposes 170,000+ Individuals record

Cybersecurity researcher Jeremiah Fowler discovered an unsecured database with 170,360 records belonging to a real …

Leave a Reply

Your email address will not be published. Required fields are marked *