Banking Trojan attacks on Android smartphones: how they operate and how to protect your money

Last update: 7 March, 2026
  • Explosive increase in banking trojans on Android, with hundreds of thousands of malicious APKs and new families active.
  • The attacks focus on stealing credentials and emptying accounts using accessibility, screen overlay, and remote control.
  • The campaigns also affect Europe and Spain, even through Google Play apps and already infected cheap mobile phones.
  • Updating the system, limiting downloads, monitoring permissions, and using specialized security significantly reduces the risk.

Banking Trojan attacks on Android

The mobile phone has become the wallet, the bank, and even the digital keychain for millions of people. This convenience comes at a price: banking trojans targeting Android smartphones are experiencing their greatest activity and sophistication, with campaigns spreading worldwide and Europe and Spain among their priority targets.

A record year for banking trojans on Android

According to Kaspersky's "Mobile Malware Evolution" report, cyberattacks against Android smartphones to steal banking data increased by 56% in 2025 compared to the previous year. The main targets are online banking applications, payment gateways, and card services , which handle a large portion of everyday transactions in Spain and the rest of Europe.

The study estimates that 255.090 unique installation packages (APKs) of banking Trojans were detected for Android, a year-over-year increase of 271%. This avalanche of new samples complicates the work of traditional defense systems, which rely heavily on recognizing known malware signatures.

In this scenario, particularly active families of malware stand out, such as Mamont, Creduz, Vultur, and Anatsa/TeaBot , designed to take control of the device and capture everything that happens on the screen. Many of these variants incorporate advanced geolocation techniques and country-specific activation , so they only turn on when the phone is in territories where the banks and services on their target list operate.

Research reports also point to specific campaigns in the European region, with Trojans like DroidBot targeting entities in the Eurozone and fraud operations taking advantage of nighttime or holiday hours to go unnoticed.

How a banking trojan works on your smartphone

Today's banking Trojans bear little resemblance to traditional viruses that deleted files or slowed down computers. Now we're talking about silent malware that leverages Android's Accessibility Services and the ability to overlay elements on the screen to gain almost complete control of the device without raising suspicion.

Variants like TeaBot or Vultur "see" everything you do by activating features originally designed for visually impaired users. The Trojan can record the screen, log keystrokes, read notifications, and, in many cases, intercept verification codes sent via SMS . When you open your bank's app, the malware can place an invisible layer that captures your username and password before they even reach the bank's server.

The power of modern hardware works against the user: high-end processors and 120Hz screens allow all this spying to run without lag or visible glitches . The phone functions normally, the battery doesn't drain excessively, and the owner doesn't notice anything unusual until they see unfamiliar transactions on their bank account.

Another worrying detail is the polymorphic nature of many of these threats: the code changes slightly with each download, making it difficult to detect using signature-based solutions. Furthermore, some samples remain inactive when they detect they are being analyzed in a laboratory environment, further delaying their identification.

From dropper to withdrawal: why some malicious apps slip through the filter

One of the most common tactics in current attacks involves using "dropper" apps uploaded cleanly to Google Play . These seemingly harmless apps (such as photo editors, casual games, or productivity tools) pass initial security checks. Once installed on the phone, they wait a few days and, when the user is off guard, download the banking Trojan module from a remote server.

Throughout 2025, various analyses documented hundreds of thousands of new mobile threats , with two-stage infection mechanisms playing a particularly prominent role. As a result, Google strengthened the controls of Google Play Protect and removed dozens of malicious apps that had accumulated millions of downloads worldwide.

The problem is that many of these tools had already infected a considerable number of users before being removed. Some campaigns also targeted Europe, taking advantage of users' trust that if an app is in the official store, it's safe by definition. Criminals exploit precisely this perception of legitimacy to spread their banking Trojans.

Meanwhile, APKs downloaded from third-party websites , alternative app stores, or social media links continue to circulate , where there is virtually no control. In these cases, users completely forgo the checks performed by the official app store and drastically increase the likelihood of ending up with a Trojan installed.

New devices that are already arriving infected

Beyond apps, some recent reports point to a particularly disturbing phenomenon: the sale of low-cost Android phones that arrive on the market with backdoors pre-installed in the firmware itself . Cases of Trojans like Triada or Keenadu integrated from the factory, without user intervention, have been documented .

In these scenarios, the buyer receives a seemingly normal mobile phone, but in reality, the device is already under the potential control of attackers from the moment it's turned on . These backdoors allow attackers to execute remote code, install additional applications, intercept passwords, read SMS messages, and redirect traffic without the user seeing any suspicious apps in the list.

Removing this type of malware is very difficult, as it 's embedded in the system . A factory reset doesn't always solve the problem, and in many cases, the only real solution is to repackage the firmware with the manufacturer's help or, even worse, replace the device with a model from a trusted supplier.

For European users, this situation poses an added risk when acquiring phones in parallel markets, uncontrolled imports or unofficial channels, where guarantees and security audits are much more lax.

Campaigns and attack techniques affecting Europe and Spain

Cybersecurity reports document several specific campaigns targeting users of European banks . In addition to classic Trojans focused on stealing credentials, threats exploiting everyday technologies, such as NFC for contactless payments , have proliferated.

Apps have been detected that ask users to hold their bank card near their phone, supposedly to "verify" it . Behind the scenes, the software copies the card data and transmits it to servers controlled by the attackers. In one country alone, tens of thousands of attempted attacks using this method were recorded in 2025, a figure that gives an idea of ​​the scale of the problem.

Meanwhile, other banking Trojans disguise themselves as fake financial apps , expense management tools, or currency converters that mimic the interfaces of legitimate banks. The goal is to trick users into entering their login credentials in an environment completely controlled by the criminal. Once the credentials are obtained, the fraud can be carried out from another device, sometimes from different countries to hinder traceability.

There has also been a rise in mobile botnets , networks of infected Android devices used for large-scale fraud. These infrastructures allow, among other things, automated access to compromised bank accounts , distribution of new malware samples, and coordinated attacks against verification systems.

Beyond banking: spy in your pocket and ongoing fraud

Although the primary target of these Trojans is money, their reach extends far beyond bank accounts. Many examples incorporate spyware functions similar to those of classic spyware : they can access the camera, microphone, call history, or real-time location of the device.

Some malicious code, such as ClayRat , has been distributed through unofficial messaging applications. These programs can read conversations, record audio, and activate the camera without the user's knowledge . With this information, attackers can supplement bank fraud with blackmail, identity theft, or the sale of data on underground forums.

Others, like Harly , hide within casual games or personalization apps and specialize in subscribing users to paid services without their consent. Even if the individual amount is small, the sum of recurring charges can become a constant drip that's difficult to detect without regularly checking statements.

The combination of direct bank theft, phantom subscriptions, and personal data collection makes the Android smartphone a central piece for organized cybercrime, which exploits every possible avenue for monetization.

Why Androids are such an attractive target

Android dominates the smartphone market in Europe and Spain, making it, statistically speaking, the prime target for those seeking to maximize the reach of their banking Trojans . This is compounded by the highly fragmented ecosystem, with manufacturers slow to release patches or even stop updating relatively recent models.

Experts point out that devices that no longer receive monthly security updates are the most vulnerable, especially in the mid-range and low-end segments. This leaves a huge pool of potentially exposed devices, many of which are used to manage bank accounts, authenticate transactions, or store cryptocurrency wallets.

Another key factor is the ability to install APKs from external sources , a widespread practice among advanced users and in markets with abundant alternative repositories. This flexibility, when managed well, can be useful; however, when misused, it becomes the main entry point for fake banking applications and malicious modules that would never pass rigorous testing.

The near-blind trust that many users place in their mobile phones doesn't help either. Banking, email, messaging, and two-factor authentication all converge on a single device , so if a Trojan manages to infiltrate it, it has everything it needs to complete the fraud without compromising other devices.

Warning signs: how to detect a potential banking Trojan

Although the goal of these attacks is to go unnoticed, there are some telltale signs that can reveal the presence of a banking Trojan on Android . Experts advise paying attention to certain details in your daily life.

A common clue is the appearance of small flickers or strange changes on the screen when opening banking or payment apps. There may also be unusual spikes in data usage when the phone is idle, or the activation of Accessibility Services in apps that, in principle, don't need those permissions.

Another worrying symptom is receiving notifications of login attempts you don't recognize, unexpected password reset emails, or SMS messages with verification codes you didn't request. In these cases, it's advisable to immediately check the devices linked to your accounts and, if possible, disconnect any active sessions.

If your mobile phone is behaving erratically, unknown applications are appearing , or strange charges are detected on your bank account, it's prudent to act as if there were a security breach: change passwords from a trusted device, consult with your financial institution, and consider a full phone analysis.

Practical steps to reduce risk on your Android

Cybersecurity experts agree that, although the risk cannot be completely eliminated, most banking trojan attacks on Android can be avoided by following basic digital hygiene guidelines.

First and foremost, it is essential to keep your operating system and applications up to date . Many Trojans exploit known vulnerabilities for which patches already exist, but which remain exploitable because users postpone updates indefinitely.

It is also recommended to restrict app installations to official stores , such as Google Play, and avoid downloading APK files from links shared via messaging apps, social media, or websites of dubious origin. While the official store is not infallible, the risk is considerably lower than with unverified channels.

Before installing any application, carefully review the permissions it requests and be wary of those that ask for access to functions they don't need to operate. Similarly, it's helpful to read recent reviews and consider whether any comments mention strange or suspicious behavior.

Finally, security firms recommend using Android-specific protection solutions capable of analyzing applications in real time and blocking typical banking trojan behaviors, such as malicious screen overlays or misuse of Accessibility Services.

What to do if you suspect your phone has been compromised

If there are reasonable grounds to suspect that an Android smartphone may be infected with a banking Trojan, experts advise acting quickly, but without rushing. The first step is to disconnect the device from Wi-Fi and mobile data networks whenever possible, to sever communication with the attackers' command and control servers.

From a trusted alternative device (another mobile phone, a computer), it's advisable to change the passwords for your banking apps, email, and other key services , as well as revoke access and active sessions. If your bank offers real-time notifications of transactions and spending limits, it's worth reviewing them and, if necessary, temporarily lowering them.

On Android itself, an additional step is to check which apps have accessibility or device administrator permissions and revoke them for those that aren't essential. Then, you can run a scan with a reliable security tool to try to identify the threat.

If suspicious behavior persists, many experts recommend performing a factory reset after backing up important photos and documents. In more extreme cases, where there is evidence of backdoors in the firmware or the phone came from a dubious source, it may be safer to stop using that device for financial transactions.

The explosive increase in banking trojan attacks on Android smartphones demonstrates the extent to which mobile phones have become central to our digital lives and a prime target for cybercrime. With a fragmented ecosystem, millions of devices without daily patches, and increasingly sophisticated techniques for infiltrating the system undetected, the best defense lies in combining security technology, prudent habits, and a healthy dose of skepticism when installing apps or granting permissions. It's not about living in fear, but about being aware that a significant portion of our money and identity travels on that small device in our pocket, and acting accordingly.

What does the RatON Trojan do?
Related articles:
RatON on Android: Full Analysis of the Banking Trojan