Android banking malware has evolved into two dominant forms: sophisticated banking Trojans and fake banking apps built to steal banking credentials, payment card data, and SMS one-time passwords. ESET reported that Trojans including BankBot, Anubis, Exobot, and MazarBot use overlay attacks, intrusive permissions, persistence techniques, and in some cases abuse of Android Accessibility features to impersonate legitimate apps and facilitate account takeover and fraud. Fake banking apps use a simpler approach, posing directly as a bank or financial service and presenting fraudulent login screens immediately after installation to harvest credentials.
The report said the leak of BankBot source code helped drive a surge in Android banking Trojan variants, while fake banking apps became increasingly prevalent as a lower-complexity but still effective theft method. It also highlighted a Trojanized QRecorder app distributed through Google Play that targeted banks in Germany, Poland, and the Czech Republic and was installed more than 10,000 times before removal. ESET concluded that although advanced Trojans are more invasive and technically capable, fake banking apps can be equally effective because victims who install them are highly likely to enter sensitive information.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In November 2018, ESET discovered an Android banking Trojan technique that abused Accessibility services to navigate targeted financial apps and transfer funds directly. The paper highlights this as an evolution beyond credential theft toward direct fraudulent transactions.
The report says fake banking apps were reported as increasing in prevalence throughout 2018. It identifies them as a growing category of Android banking malware alongside more sophisticated banking Trojans.
According to the white paper, the BankBot source code leak likely helped drive a surge of Android banking Trojan variants during 2017. This marked a broader escalation in Android banking malware activity.
The white paper states that BankBot source code was published on an underground forum in December 2016. It says this leak contributed to numerous hybrid variants of Android banking malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.