Mobile banking Trojan threats surge dramatically, phones now prime cybercrime targets

Cybercriminals are ramping up efforts to target users’ finances, with new data from Kaspersky revealing an unprecedented spread of malicious mobile software. In the first quarter of 2026 alone, researchers detected 162,275 new mobile banking Trojan installation packages. This figure is more than double the total recorded throughout 2024 and equals roughly two-thirds of the entire annual count for 2025. Banking Trojans made up 52.96 percent of all malicious mobile apps found in Q1 2026, a sharp rise from the roughly 31 percent share seen in 2025.

These findings come from anonymized data collected via the Kaspersky Security Network, showing that attackers are taking advantage of people’s growing reliance on mobile devices for shopping, work, communication, and daily transactions. In the first three months of 2026, Kaspersky blocked over 2.67 million attacks involving malware, adware, and unwanted software. The total number of detected malicious installation packages reached 306,070, including 439 linked to mobile ransomware. Preinstalled backdoors like Triada and Keenadu, embedded in device firmware during manufacturing, also ranked among the most common threats encountered.

The scale of these threats confirms that smartphones are no longer secondary targets but have become a primary battleground for cyber defense. Users store everything from personal photos and messages to financial data and work files on their devices, making them highly valuable targets for criminals. This upward trend began in 2025, when Kaspersky systems blocked more than 14 million mobile attacks globally—averaging about 1.17 million attempts each month.

Choon Hong Chee, head of consumer channel for APAC at Kaspersky, explained that criminals are using increasingly advanced distribution methods. Malicious apps spread through unofficial app stores, phishing links, fake promotions, tampered legitimate apps, and malicious ads. Attackers also abuse trusted online services and use multi-stage tactics that start with seemingly safe files or links to avoid being flagged.

Separate Kaspersky research on messaging fraud, titled The Great Messaging Heist, highlights the real-world impact: a single successful scam costs victims an average of US$733. More than half of successful scams are completed in under 30 minutes from first contact to theft. Notably, 66 percent of victims believe artificial intelligence was used against them—most often to write convincing messages, followed by voice cloning and fake images or videos.

To stay safe, users are advised to install apps only from official marketplaces, avoid clicking suspicious links or offers, keep their operating systems and apps updated, double-check requests for personal information received via messaging apps, and use dedicated mobile security tools to spot threats early. As mobile devices become central to daily life across Southeast Asia and worldwide, cybersecurity experts stress that mobile protection is no longer optional—it is an essential part of digital safety.

Website |  + posts

Related Stories

spot_img

Latest Stories