Report by Zimperium
2026 Mobile Banking Heist Report
Key Findings
TsarBot targeted 450 banking apps and accounted for 58% of its global activity.
CopyBara targeted 446 banking apps.
Hook targeted 385 banking apps.
Nexus concentrated 90% of its global targets in EMEA.
34 malware families targeted 1,243 mobile banking and fintech apps across 90 countries globally.
In EMEA, 30 mobile malware families targeted over 800 banking and fintech applications across 44 countries.
TsarBot, CopyBara, and Hook collectively targeted more than 60% banking and fintech apps.
The United States had 162 banking apps under active targeting, the highest concentration of any single country globally.
Ukraine, Russia, and the United States are the top three countries hosting command-and-control infrastructure across the malware families analyzed.
Android malware transactions increased by 67% year-over-year.
More than 60% of mobile banking apps lack basic code protection.
Nearly half of the active malware families have financial extortion capabilities, including ransomware that can encrypt files on the device.
Android malware-driven financial transactions increase 67% year-over-year.
Thirty-four active malware families targeted 1,243 financial apps across 90 countries.
The United States had the highest concentration of targeted apps globally, with 162 banking applications under active targeting, up from 109 in 2023.
TsarBot, CopyBara, and Hook collectively targeted more than 60% of global banking and fintech apps.