🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
A banking trojan is malware that steals financial credentials and manipulates banking sessions, disguising itself as legitimate software to stay resident on the device.
The category changed platforms once before. Classic Windows trojans such as Zeus injected code into browsers to alter what a customer saw on a banking page, and once banks moved authentication into mobile apps, the malware followed.
Today's version arrives as an Android application. It abuses accessibility permissions, draws fake screens over real banking apps, intercepts one-time codes, and increasingly runs fraudulent transactions on the victim's device instead of exporting credentials.
A banking trojan runs through six stages, and the credential theft everyone associates with it happens late in the sequence.
That last step changed the economics of the whole category. On-device fraud runs the transaction from the victim's own phone, with the correct device fingerprint, IP address, and app instance, which strips away most of the signals a bank's fraud engine uses to spot an unfamiliar session.
Coverage of this malware tends toward consumer advice, which leaves out the three ways it lands on an enterprise balance sheet.
Those three effects share one root cause outside the perimeter: a device the organization does not manage, reached through infrastructure that borrows its brand.
MFA slowed credential resale, and it did not stop the trojan, because the malware runs on the device where the second factor arrives.
Only phishing-resistant authentication bound to a separate device, or transaction signing that displays the real payee, holds up against a compromised handset. Codes, prompts, and confirmations that live on the infected phone are all reachable by the malware on it.
Volume has moved decisively to Android, and it is growing rather than tapering.
Kaspersky recorded 255,000 mobile banking trojan installation packages during 2025, inside 815,000 malicious packages overall, with banker-related attacks growing 1.5 times year over year, according to its mobile threat report.
That trend carried into 2026 without pause. Kaspersky counted 162,275 banking trojan packages in the first quarter alone, with Trojan-Banker the largest single category at 52.96% of detected applications, per its Q1 2026 statistics.
Families that mass-produce variants drive those numbers, since a fresh package defeats signature detection until someone samples it.
Distribution mechanics explain part of that volume. Droppers reach official app stores disguised as PDF readers, QR scanners, and file managers, pass review with no malicious code present, then fetch the banking payload after installation.
Families differ in platform, signature technique, and current status, and several older names now survive mainly as code inherited by newer malware.
Chasing family names has limited defensive value for most teams. Overlay capture, accessibility abuse, and notification interception appear across nearly all of them, and detection built on those behaviors survives the next rebrand.
Banking trojans collect a wide range of digital and behavioral data that enables attackers to take over accounts and execute financial fraud.

Stolen data rarely stays with the original operator. Credentials surface later in combolists and dark web markets, so leaked credential monitoring catches exposure that no endpoint alert produced.
The second list matters more than the first for an institution. Customers report infections rarely and late, while fraud telemetry sees the same malware family across thousands of accounts.
Banking trojans target users and organizations that regularly access financial services online, especially where security awareness or controls are weak.

Everyday users who access online banking from personal computers or smartphones are common targets. Those who click phishing links or install unverified apps face higher risk.
Small businesses are attractive targets due to limited cybersecurity defenses. Compromised business accounts can lead to larger financial losses and data exposure.
Users who rely heavily on mobile banking apps are increasingly targeted by Android banking trojans. Malicious apps and fake overlays make mobile platforms a high-risk environment.
Remote workers often use personal devices and unsecured networks. This increases exposure to phishing-based banking trojan infections.
Banks are indirectly affected when customer accounts are compromised. Fraud losses, regulatory pressure, and reputational damage are common consequences.
Banks carry the fraud loss for malware running on devices they do not control. What they can control is the distribution layer: the fake apps, lookalike domains, and phishing pages that deliver the APK under their brand.
CloudSEK's TRIAD team documented that pattern against Indian banking customers, where fake complaint portals collected card data and then pushed an SMS-forwarding trojan onto the victim's phone to intercept the one-time codes.
CloudSEK XVigil monitors for that infrastructure, covering fake mobile applications, brand impersonation across app stores and social platforms, phishing domains, and leaked customer data, with takedown support for what it finds.
No. A virus replicates itself into other files, while a trojan relies on a person installing it, then stays put on that device.
Ransomware announces itself and demands payment. A banking trojan stays hidden for as long as possible, since its value comes from continued access.
Rarely. Most need an install and a permission grant, though preinstalled firmware trojans arrive on the handset before the first power-on.
Yes, at far lower rates. App Store review and iOS sandboxing block overlays and accessibility abuse, so iOS fraud leans on phishing pages and sideloading through enterprise profiles.
Partly. Mobile security tools catch known packages, while fresh variants and dropper-delivered payloads need behavioral detection and in-app integrity checks.
Yes, in most cases, though preinstalled firmware trojans survive it. Credentials need resetting from a separate, clean device afterward.
Yes. Wallet apps sit on the same target lists as banking apps, and seed phrases displayed on screen are captured the same way as PINs.
The mid-2000s. Zeus, identified in 2007, set the template of web injects and credential theft that later families inherited.
Malware-as-a-service crews build and rent the malware, while separate affiliates run distribution and cash-out, which explains the varied targeting between campaigns.
Yes, particularly for corporate banking in Latin America and Europe, where families such as Grandoreiro still run remote overlay fraud against treasury users.
