- Key insight: Every authentication factor a bank delivers to a customer's phone, including SMS codes, push approvals and in-app confirmations, is compromised once malware takes over the device.
- Supporting data: Across 9,850 malware samples, Georgia Tech researchers found banking apps to be the most-targeted category, and in 35 of the 159 banking apps the malware could move money without the customer acting.
- Forward look: ThreatFabric reports that attackers are adding small and midsize U.S. banks and credit unions to their target lists, and that the count is rising.
Overview bullets generated by AI with editorial review.
Research out of Georgia Tech has found that banking apps are the most heavily targeted category of software on Android phones. Research released this week by mobile security vendor Zimperium counts more banking apps under active targeting in the U.S. than in any other country.
In addition, more than half of bank customers (54%) now manage their accounts primarily through a mobile app, according to a Morning Consult
These trends have dire consequences for banks that serve Android users.
When banking malware takes over a customer's phone, every authentication control the bank sent to that phone stops working.
The one-time passcode, the push notification, the in-app approval — malware reads all of it. In some cases, the malware controls the app and phone directly.
Little of a bank's fraud defense survives once a customer's device gets compromised, and Regulation E turns most of the malware's gains into banks' losses.
Malware that attacks phones threatens any company with an app, but U.S. banks are unusually exposed.
What the malware defeats
Any data or resource reachable from an infected phone should be treated as compromised.
Most such malware is "actually taking over the device," according to Eward Driehuis, vice president of fraud engineering at ThreatFabric, an Amsterdam mobile threat intelligence firm that sells fraud-detection software.
This full-device compromise affects multifactor authentication, or MFA. Malware makes MFA "less efficient or even fully compromised if additional factors are available from the same device," Driehuis told American Banker.
Malware on a compromised phone can see and manipulate text messages carrying one-time passcodes, emails, push notifications and in-app transaction approvals.
A group led by Brendan Saltaformaggio, an associate professor at Georgia Tech, collected malware samples from VirusTotal (which aggregates such samples for security research) between August and December 2022 and ran them on Android phones, according to
The group categorized the targeted apps into seven categories; banking was the largest, with 159 apps targeted by 3,579 malware samples.
Those 159 were banks' own apps, not counterfeits. The five countries where they were most widely used were Russia, Brazil, the United Kingdom, the United States and Mexico.
The studied malware was designed to collect credentials (such as usernames and passwords) from 147 of those 159 apps. For 35 of them, the malware could initiate a money transfer without the customer doing anything.
Android's accessibility service makes much of this possible. These settings let software read the screen and tap on a user's behalf so that people with disabilities can operate a phone. American Banker has
The customer can't get rid of it
Telling customers to delete the app does not work. Of the 9,850 samples Saltaformaggio's team studied, 9,102 blocked the user from revoking the malware's permissions, and 9,024 blocked the user from uninstalling it.
In other words, a vast majority (more than 90%) of malware that the group studied is unremovable by normal means.
A bank's warning about such malware does not reach the customer either. In 98 of the 159 banking apps, the malware either hid or deleted notifications a bank sends when it sees something wrong on the customer's phone or in their banking activity.
Because malware can dismiss fraud alerts, "banks must not assume that an ignored warning implies the customer was okay with a transaction," Saltaformaggio told American Banker.
Hardening the app doesn't close it
Regulators in Singapore, Malaysia, India and Hong Kong require protections inside the banking app itself, according to the
The requirements have not made a dent. ThreatFabric's intelligence "does not show a significant decrease in mobile malware activity" in these regions, Driehuis said.
Attackers get around these rules by moving to techniques the rules do not reach, such as malware that relays a phone's contactless payment signal. Such malware "does not even touch the mobile application of the targeted bank," Driehuis said.
U.S. regulators ask for less. The Federal Financial Institutions Examination Council's 2021
Nothing in the guidance addresses malware on the phone. In fact, on the same page the guidance mentions malware, it tells banks to explain to customers their rights "in the event of unauthorized access to an account, including protections under Regulation E."
Who pays
Regulation E, which governs consumer accounts, defines a transfer initiated by someone who obtained account access through fraud as an unauthorized electronic fund transfer, according to the Consumer Financial Protection Bureau's
A bank may not weigh the consumer's negligence when setting liability, the FAQs say on page 13.
In other words: If the customer unknowingly installs a banking trojan on their phone, and the trojan initiates a transfer, the bank covers much of the loss. This liability rests on one fact: Malware-driven transfers are unauthorized.
No public dataset separates malware-driven transfers from other unauthorized ones, so the industry's total exposure is unmeasured. However, what can be counted is growing.
Zimperium's Tuesday report counts 162 U.S. banking apps under active targeting, more than double the United Kingdom's 69.
The U.S. figure partly reflects how many financial institutions the country has, according to Driehuis. But attackers recently "started to pay attention to multiple small-to-medium sized banks and credit unions in the U.S. next to the big players," he said.
That leaves banks of all sizes merely inferring what is really happening on a user's Android phone — whether a transfer was authorized or malware-initiated.
"A valid login is not proof that the customer authorized the transfer," Saltaformaggio said.












