The malware threat: Now closer to home than ever

Concept of cybercriminal taking control of mobile phone

For years, community banks could reasonably assume that the biggest financial institutions presented the most attractive targets for sophisticated cybercriminals. Bigger banks meant more customers, more accounts, and potentially bigger paydays. That simply isn’t the case.

New research highlighted by American Banker in their August 27 article, U.S. bank apps are now top target for malware: Study, suggests that attackers are setting their sights beyond the largest financial institutions. Small and midsize U.S. banks and credit unions are increasingly being added to malware target lists. And according to ThreatFabric, a provider of research and fraud solutions, the number is rising. For community banks and their customers, this should be a wake-up call.

Banking apps are target number one

Mobile banking has become the primary way millions of Americans interact with their financial institutions. According to an American Bankers Association survey cited by American Banker, 54% of bank customers have shifted to managing their accounts primarily through mobile apps.

Unfortunately, criminals have noticed the shift as well. Research by Georgia Tech examined 9,850 Android malware samples and divided the applications they targeted into seven categories. Banking was the most-targeted category, with 159 legitimate banking apps targeted by 3,579 malware samples.

The findings get considerably more disturbing

Malware targeting 147 of those 159 apps was designed to steal credentials such as usernames and passwords. But in 35 of the 159 banking apps, the malware could actually initiate a money transfer without the customer’s knowledge. The danger may begin with an app that appears completely unrelated to banking. Malware is being distributed through Android apps masquerading as PDF readers, file managers, device cleaners, and other everyday utilities. Once installed, the malware can identify whether the customer uses one of the banking apps on its target list and attempt to steal credentials or, in some cases, take control of the device to facilitate fraudulent transactions.

Think about that for a moment. Not only can a customer be fooled into approving a fraudulent transaction. Now, the malware on their phone can make that transaction entirely on its own. According to the Georgia Tech research, “a valid login is not proof that the customer authorized the transfer.”

When your phone becomes the criminal's phone

Part of what makes this threat so difficult is the level of control sophisticated malware can gain over a mobile device. Eward Driehuis, vice president of fraud engineering at ThreatFabric, told American Banker that much of today's malware is “actually taking over the device.” Once that happens, many of the security measures banks and their customers rely on become vulnerable. One-time passcodes sent by text? Malware may see them. Push notifications? Potentially compromised. In-app transaction approvals? Those, too.

Driehuis warns that multifactor authentication can become “less efficient or even fully compromised.” Even warning the customer after something suspicious occurs may not work. Of the malware samples researchers examined, more than 90% could not be removed through normal means. And for 98 of the 159 targeted banking apps, malware could hide or delete notifications sent by the bank about suspicious activity. The security problem is therefore no longer confined to protecting the banking app itself. Once the device has been compromised, the criminal may effectively be acting as the bank’s customer.

Community banks are now in the crosshairs

Perhaps the most important finding for community bankers is how the target is changing. A 2026 Zimperium report cited by American Banker identified 162 U.S. banking apps under active targeting; more than twice the 69 identified in the United Kingdom. Some of that difference reflects the sheer number of financial institutions in the United States. 

But that doesn't tell the whole story. Attackers, Driehuis says, have recently “started to pay attention to multiple small-to-medium sized banks and credit unions in the U.S. next to the big players.” So much for the belief that a community bank is simply too small to earn the interest of bad actors.

There's another reason why banks need to take the threat seriously: the financial consequences may not end with the customer. As American Banker explains, malware-driven transfers can qualify as unauthorized electronic fund transfers under Regulation E. Consumer negligence cannot simply be used to shift liability back to the customer. In other words, educating customers about mobile malware isn't simply good customer service. It's part of protecting the bank.

Fighting malware with messaging

Community banks can't control every app their customers download or every link they click. But they can help customers recognize threats before those threats gain control of their devices. This is where messaging becomes an important layer of defense. 

Banks must regularly remind customers to download apps only from trusted sources, avoid suspicious links and attachments, keep devices and apps updated, protect account credentials, and contact the bank immediately when something doesn't look right. Just as importantly, cybersecurity education shouldn't be a once-a-year message. The threat changes too quickly. 

Bank Marketing Center can help community banks keep those customer conversations going. The company's web-based portal offers bank marketers access to thousands of professionally designed, bank marketing templates that can be customized quickly with the institution's branding and messaging. Content can be delivered through social media, digital signage, direct mail, statement stuffers, and other channels, quickly and easily, providing banks with multiple ways to keep their customers informed and protected.  And at a time when cybercrimes are increasingly sophisticated, educational messaging can go a long way… in both protecting customers and building trust in their community bank.

Bank Marketing Center

We’re Bank Marketing Center, the leading subscription-based, automated marketing platform created specifically for community banks. Today, we help marketing professionals at more than 300 financial institutions develop and distribute timely, engaging communications that strengthen brand trust, deepen customer relationships, and drive revenue growth. 

We make that possible by automating many of the essential marketing functions banks depend on; from content creation using professionally designed bank marketing templates to social media scheduling and monitoring, digital asset management, compliance routing, and more.

We also believe strongly in sharing the knowledge and insights we gain along the way. Whether we’re exploring the latest AI tools, offering strategies for attracting and retaining top talent, hosting a webinar on operational efficiency, or sharing expert perspectives on where the banking industry is headed, our goal is the same: helping community banks succeed.

Want to learn more about how we can support your community bank and its marketing efforts? A good place to start is bankmarketingcenter.com. You’re also welcome to contact me directly at 678-528-6688 or by email at nreynolds@bankmarketingcenter.com. As always, I look forward to hearing your thoughts.

Comments are closed