Mobile stealers and banking trojans are a different category of infostealer. They target the device people use for banking, payments, identity verification, messaging, email, crypto wallets, two-factor authentication, and daily communication. A compromised mobile phone can expose much more than saved credentials. It can expose the live user session, authentication codes, push notifications, banking app activity, device screen content, and the victim’s ability to approve or reject financial transactions.
Android is the main battlefield for mobile banking malware. The platform gives users more flexibility to install apps, and attackers exploit that flexibility through fake applications, malicious websites, social engineering, third-party stores, and occasionally apps that reach official marketplaces before removal. Kaspersky reported that Android Trojan banker attacks increased by 56% in 2025 compared with the previous year, and described these trojans as malware designed to steal credentials for online banking, e-payment services, and credit card systems.
Mobile banking trojans are often grouped with infostealers because they steal credentials, personal data, financial data, SMS messages, one-time passwords, device information, and authentication material. At the same time, they go beyond classic desktop infostealers. A Windows stealer usually collects data from files, browsers, wallets, and applications. A mobile banking trojan can watch the victim interact with an app, place fake screens over legitimate banking apps, intercept messages, read notifications, capture the screen, abuse Accessibility Services, and help the attacker perform fraud in real time.
ESET describes Android infostealers as threats that often target banking information and can lead to identity theft, financial loss, and other severe consequences. This framing is important. Mobile stealers sit between malware, fraud, and identity crime. Their goal is not only to collect passwords. Their goal is to take over the victim’s relationship with financial services, payment apps, crypto apps, email, social accounts, and sometimes corporate resources.
What makes mobile stealers different
The most important difference between mobile stealers and desktop stealers is proximity to authentication. A mobile phone is often the device that receives SMS codes, push notifications, banking alerts, email recovery links, authenticator prompts, and app-based approvals. This makes mobile malware extremely valuable to criminals. A stolen password from a desktop may still require a second factor. A compromised phone may give the attacker access to that second factor.
Mobile banking trojans are also interactive. Many families use overlays, which are fake login screens displayed on top of legitimate apps. When the victim opens a banking app, the malware detects the target and places a convincing fake screen over it. The victim enters credentials, payment details, or verification codes into the attacker’s form. The attacker receives the information while the victim believes they are interacting with the real app.
Accessibility Services abuse is another defining feature. Android Accessibility Services were created to help users interact with devices, but malware can abuse these permissions to observe screens, click buttons, grant permissions, read text, prevent removal, and automate fraud. Zimperium’s research into mobile infostealers describes threats such as TrickMo and AppLite that use mobile capabilities to compromise banking information and sensitive credentials for corporate resources such as VPNs and cloud services.
SMS and notification interception also set mobile stealers apart. Banking trojans can read incoming SMS messages, capture one-time passwords, intercept push notifications, and hide alerts from the victim. Some families use remote-control features that let the attacker operate the device while the victim sees a fake maintenance screen, lock screen, or progress message. This creates a direct path from credential theft to financial fraud.
The main Android and mobile stealer families
The mobile stealer ecosystem includes several overlapping categories: banking trojans, remote-access trojans, SMS stealers, overlay malware, crypto-wallet stealers, and hybrid spyware-bankers. Important families include Anatsa, also known as TeaBot in some reporting, Cerberus, Alien, ERMAC, Octo, Exobot, Xenomorph, SOVA, SharkBot, Hydra, Godfather, Medusa, Vultur, SpyNote, BRATA, FluBot, Hook, TrickMo, AppLite, Mamont, BankBot, Marcher, Ginp, EventBot, Gustuff, Chameleon, GoldPickaxe, and Copybara.
Anatsa is one of the most important modern Android banking trojans. It first emerged around 2020 and has repeatedly targeted banking users in Europe and North America. Zscaler reported that Anatsa is capable of credential theft, keylogging, and fraudulent transaction enablement, and that a recent variant targeted more than 831 financial institutions worldwide, including banks and cryptocurrency platforms. ThreatFabric reported that Anatsa again targeted North America through Google Play in a campaign focused on mobile banking apps.
Cerberus is one of the most influential Android banking trojans because of its role in the evolution of later families. Its source-code history and underground circulation helped shape families such as Alien, ERMAC, and other related Android bankers. Cerberus-style malware commonly uses overlays, SMS theft, contact theft, device information collection, and Accessibility Services abuse. Its importance is historical and practical because many later Android banking families reused concepts that Cerberus helped popularize.
Alien is commonly discussed as a successor or derivative family connected to the Cerberus ecosystem. It targets banking applications, steals credentials, intercepts SMS messages, and can support overlay-based fraud. Alien represents the way Android banker codebases evolve after leaks, sales, arrests, and market shifts. One criminal product disappears or loses momentum, and another family absorbs its techniques.
ERMAC is another family associated with the post-Cerberus Android banking ecosystem. It is known for targeting a wide range of banking, wallet, and financial applications with overlays and credential theft. ERMAC also illustrates how Android banking malware is sold as a criminal service, with operators using target lists and configuration updates to expand coverage across regions and financial institutions.
Octo, associated with the ExobotCompact lineage, is a high-impact Android banking trojan because of its remote-control capabilities. Families in this category can support on-device fraud, where the attacker uses the victim’s own phone to perform actions. This technique can help fraud appear more legitimate because it originates from the real device, real app environment, and familiar user context.
Xenomorph is another prominent Android banking trojan. It targets financial applications, steals credentials, and has been associated with overlay attacks and automation features. Xenomorph is important because it reflects the professionalization of mobile malware: modular architecture, expanding target lists, and a focus on fraud execution rather than simple data theft.
SOVA, SharkBot, Hydra, Godfather, Medusa, Vultur, BRATA, and SpyNote each represent different points on the spectrum between banker, RAT, spyware, and infostealer. Some focus heavily on overlays and financial credentials. Others add screen streaming, remote control, file access, SMS interception, or device manipulation. This overlap makes the mobile category harder to classify than Windows stealers. A mobile family may be a banker in one campaign, a RAT in another, and an infostealer across all campaigns.
FluBot became widely known as an SMS-driven mobile threat that spread through messages and stole banking and device data. Its importance comes from scale and distribution style. It showed how mobile malware can spread through the same messaging channels people trust for delivery notifications, package updates, and service alerts.
Hook is important because it shows how mobile banking trojans continue to expand capability. Public reporting in 2025 described Hook Version 3 as adding advanced overlay, NFC deception, lockscreen spoofing, transparent gesture capture, and live screen-streaming capabilities. These features show the direction of the market: mobile malware is moving from credential collection toward real-time fraud assistance.
Mamont became one of the notable families in Kaspersky’s 2025 mobile malware reporting. Kaspersky described mobile malware growth in 2025 and highlighted banking trojans such as Mamont among the threats used to steal banking and personal data.
Comparison table: major Android and mobile stealers
| Family | Main role | Primary targets | Common techniques | Typical delivery | Current risk |
|---|---|---|---|---|---|
| Anatsa / TeaBot | Banking trojan | Banking apps, crypto platforms, credentials | Overlays, keylogging, fraudulent transaction support | Google Play abuse, fake document apps, droppers | Critical |
| Cerberus | Banking trojan | Banking apps, SMS, credentials | Overlays, SMS theft, Accessibility abuse | Malicious apps, third-party stores, phishing | High historical and lineage risk |
| Alien | Banking trojan | Banking apps, credentials, SMS | Overlays, SMS interception, device data theft | Malicious apps, droppers | High |
| ERMAC | Banking trojan | Banking apps, wallets, financial apps | Overlays, credential theft, target-list updates | Malicious apps, criminal distribution | High |
| Octo | Banking trojan / remote fraud tool | Banking apps and financial accounts | Remote control, overlays, on-device fraud | Droppers, malicious apps | Critical |
| Exobot / ExobotCompact | Banking trojan lineage | Banking apps and credentials | Overlays, SMS theft, remote commands | Malicious apps and loaders | High historical and lineage risk |
| Xenomorph | Banking trojan | Financial apps, credentials, crypto apps | Overlays, automation, credential theft | Droppers, fake apps | High |
| SOVA | Banking trojan | Banking apps, wallets, credentials | Overlays, session and credential theft | Fake apps, phishing | High |
| SharkBot | Banking trojan | Banking apps and payment apps | Overlays, SMS theft, unauthorized transfers | Droppers and fake apps | High |
| Hydra | Banking trojan | Banking apps and financial services | Overlays, SMS theft, remote control | Third-party stores and fake apps | High |
| Godfather | Banking trojan | Banking and crypto apps | Overlays, credential theft, SMS interception | Fake apps and droppers | High |
| Medusa | Banking trojan | Banking apps and device data | Overlays, remote control, keylogging | Malicious apps and phishing | High |
| Vultur | Banking RAT / trojan | Banking apps, screen content, credentials | Screen recording, remote access, overlays | Droppers and fake apps | High |
| SpyNote | Android RAT | Messages, files, credentials, device control | Remote access, SMS theft, surveillance | Fake apps and phishing | High |
| BRATA | Banking RAT / trojan | Banking apps and device data | Remote control, credential theft, device manipulation | Fake apps and phishing | High |
| FluBot | SMS and banking malware | SMS, banking credentials, contacts | SMS spreading, credential theft | Smishing and delivery-message lures | High historical risk |
| Hook | Banking trojan | Banking apps, NFC flows, screen content | Overlays, screen streaming, remote control | Criminal distribution and fake apps | High |
| TrickMo | Banking trojan / infostealer | Banking apps, OTPs, enterprise credentials | Accessibility abuse, screen capture, OTP theft | Fake apps and social engineering | High |
| AppLite | Banking trojan variant | Banking apps and employee device credentials | Credential theft, mobile infostealing | Fake apps and social engineering | Medium to high |
| Mamont | Banking trojan | Banking and personal data | Credential theft, social engineering | Fake apps and malicious webpages | Medium to high |
| BankBot | Banking trojan | Banking apps and credentials | Overlays, SMS theft | Fake apps and droppers | Historical risk |
| Marcher | Banking trojan | Banking and payment apps | Overlays and credential theft | Fake apps and phishing | Historical risk |
| Ginp | Banking trojan | Banking apps and payment data | Overlays and credential theft | Fake apps and malicious sites | Historical risk |
| EventBot | Mobile credential stealer | Banking, crypto, financial apps | SMS theft, credential theft | Fake apps | Historical and medium risk |
| Gustuff | Banking trojan | Banking apps and crypto apps | Overlays, Accessibility abuse, automation | Fake apps and criminal distribution | High historical risk |
| Chameleon | Banking trojan | Banking apps and credentials | Accessibility abuse, overlays, device manipulation | Fake apps and phishing | High |
| GoldPickaxe | Mobile stealer / fraud malware | Financial identity data and banking users | Social engineering, identity theft flows | Localized malicious apps | Medium to high |
| Copybara | Banking trojan | Banking apps and financial accounts | Remote control, overlays, fraud support | Fake apps and social engineering | High |
This table focuses on operational risk rather than strict code lineage. Mobile malware families often share infrastructure, code, techniques, target lists, and operators. A family name can also represent a product, a fork, a campaign cluster, or a malware lineage. For defenders and business readers, the most useful comparison is what the malware can steal, how it gains permissions, and how it helps attackers commit fraud.
How mobile banking trojans infect users
Mobile banking trojans usually begin with social engineering. The victim is convinced to install an app that appears useful, urgent, or legitimate. The lure may be a PDF reader, package tracking app, security update, cleaner, browser update, loan app, government service, news app, crypto tool, banking utility, job application app, or streaming app. Once installed, the app asks for permissions that appear connected to its purpose but give the malware access to sensitive device functions.
Google Play abuse is a recurring challenge. Attackers submit apps that appear benign during review and later activate malicious behavior through updates, remote configuration, or downloaded payloads. Anatsa campaigns have repeatedly used document-reader or PDF-themed apps to reach banking users. In 2025, reporting on an Anatsa campaign described a malicious app disguised as a “PDF Update” to a document viewer and served through Google Play, with targeting against users in the United States and Canada.
Third-party stores and direct APK downloads remain important distribution channels. Attackers host apps on fake websites, send links through SMS or messaging apps, or place malicious apps in unofficial stores. These campaigns often rely on urgency. The victim may believe they need to install an app to receive a package, verify a bank account, complete a job application, update security settings, or access a financial service.
Smishing is especially effective on mobile devices. A message that appears to come from a delivery company, bank, tax authority, employer, or marketplace can push the victim toward a malicious app installation. The same device that receives the lure also installs the malware and receives authentication codes, which creates a complete fraud environment for the attacker.
The role of overlays
Overlay attacks are one of the core techniques in Android banking malware. The malware waits for the victim to open a targeted app. When the real app launches, the malware displays a fake screen on top of it. The fake screen may ask for login credentials, card details, identity information, one-time codes, or recovery information. To the victim, the fake screen appears to be part of the banking app.
Overlays work because mobile banking interactions are repetitive and trusted. Users expect to see login prompts, security checks, maintenance messages, verification steps, and update screens. Attackers copy these patterns. Anatsa has used deceptive overlays and maintenance-style screens to hide malicious activity and collect banking credentials during real banking app use.
The overlay model also allows precise targeting. A banking trojan can include a list of hundreds of financial apps and display a different fake screen for each one. Zscaler reported that a recent Anatsa variant targeted more than 831 financial institutions worldwide, including cryptocurrency platforms. This scale turns the malware into a configurable fraud platform rather than a single-purpose fake banking app.
Accessibility Services abuse
Accessibility Services abuse is one of the most powerful tools available to Android malware. Once the victim grants Accessibility permission, the malware may be able to observe screen content, interact with apps, click buttons, approve permissions, read text, prevent uninstallation, and automate actions. This can support credential theft, fraud execution, permission escalation, and defense evasion.
The social engineering around Accessibility permission is usually simple. The app claims it needs accessibility access to scan documents, improve battery usage, enable a security feature, update the device, automate a task, or provide customer support. Once granted, the permission gives the malware a powerful position on the device.
This technique is central to many Android banking trojans because it bridges the gap between passive theft and active fraud. A stealer that only reads files has limited access on mobile. A trojan with Accessibility permission can interact with the phone while the user is logged in, making it much more useful to attackers.
SMS, OTP, and notification theft
Mobile banking malware often targets SMS messages because many banks and services still use SMS for one-time passwords, login verification, transaction approval, and account recovery. Even when SMS is one layer of a larger authentication process, access to messages can help attackers complete fraud.
Notification access expands this capability. Banking alerts, push approvals, email previews, chat messages, and authentication prompts can appear in notifications. A trojan that reads or hides notifications can collect sensitive information and reduce the chance that the victim sees suspicious activity.
Some families also manipulate the user experience during fraud. The malware may show a full-screen overlay, fake update page, maintenance message, or lock screen while the attacker performs actions in the background. This reduces user awareness and buys time for unauthorized transfers, credential collection, or account changes.
Remote control and on-device fraud
The most advanced mobile banking trojans support remote control. This allows attackers to operate the victim’s device directly or through automation. On-device fraud is powerful because transactions can appear to originate from the trusted device, trusted app, familiar IP range, and normal mobile environment.
Remote-control features may include screen streaming, gesture capture, click automation, text input, app launching, locking the device, hiding the screen, and interacting with banking apps. Public reporting on Hook Version 3 described capabilities such as live screen streaming, lockscreen spoofing, transparent gesture capture, and deceptive NFC prompts. These capabilities show how Android banking trojans are becoming fraud workstations that run inside the victim’s phone.
On-device fraud creates a serious challenge for banks and fintech companies. Traditional fraud controls often look for unfamiliar devices, new browsers, unusual login locations, or suspicious sessions. Mobile banking trojans can operate from the victim’s real device, which makes behavioral analytics, transaction monitoring, device integrity checks, and runtime app protection more important.
Enterprise impact
Mobile stealers are often viewed as consumer banking threats, but their enterprise impact is growing. Employees use phones for work email, messaging, password recovery, authenticator apps, VPN approvals, cloud dashboards, CRM access, finance tools, HR systems, and collaboration platforms. A compromised phone can expose corporate credentials, business communication, customer data, and approval flows.
Zimperium specifically warns that mobile infostealers can compromise sensitive credentials for corporate resources such as VPNs and cloud services, making families such as TrickMo relevant to enterprise security. This is the key shift for business readers. Mobile malware is not only a bank-fraud problem. It can become an identity, SaaS, and cloud-access problem.
The risk is especially high for executives, finance teams, sales teams, support teams, and administrators. These users may receive approval prompts, handle sensitive email, access financial systems, manage ad accounts, or approve payments. A mobile stealer can help attackers move from personal device compromise to business email compromise, invoice fraud, account takeover, and unauthorized access to company platforms.
How mobile stealer logs are monetized
Mobile stealer data can be monetized in several ways. Banking credentials and one-time codes can be used for unauthorized transfers. Card details can be used for payment fraud. Crypto wallet data can lead to direct asset theft. Email and messaging access can support phishing, impersonation, and business email compromise. Device data can support identity theft and account recovery abuse.
Mobile malware also creates value through real-time fraud support. Some attackers do not only sell logs. They operate panels that show infected devices, targeted apps, available permissions, screen content, and commands. The attacker can wait until the victim opens a banking app, trigger an overlay, capture credentials, intercept the OTP, and complete a transaction.
The underground economy rewards families that offer reliable targeting, updated overlays, remote control, and broad financial-app coverage. This is why mobile banking trojans often maintain large target lists by country, bank, fintech app, crypto exchange, and payment service.
Detection opportunities
Mobile stealer detection should focus on permissions, behavior, installation source, network activity, and signs of overlay or remote-control abuse. Suspicious use of Accessibility Services is one of the strongest signals. A PDF reader, flashlight app, cleaner, news app, or package tracker that asks for Accessibility permission deserves immediate scrutiny.
Other important signals include notification access requests, SMS permissions, screen-capture behavior, device admin privileges, apps hiding their icon, apps preventing uninstallation, unusual battery usage, unexpected background activity, and connections to suspicious command-and-control infrastructure. Some trojans remove or hide their launcher icon after installation, making them harder for users to find. Recent reporting on Android banking trojan campaigns described hidden apps that target hundreds of banking, crypto, and social media apps, with some variants removing their icon or blocking attempts to reach system settings.
Financial institutions should monitor for signs of mobile malware-driven fraud. These include unusual navigation patterns, rapid transaction setup after login, overlay-related user behavior, accessibility-enabled devices, risky device integrity signals, new payees, abnormal transfer timing, high-risk device fingerprints, and sessions that combine legitimate device identity with suspicious user actions.
Enterprise teams should monitor mobile access to email, VPN, SaaS, and cloud tools. A compromised phone can be part of an identity attack even when the original target was a consumer banking app.
Prevention priorities
The strongest prevention starts with controlled app installation. Users should install apps from trusted sources, verify developers, avoid direct APK links, review permissions, and treat unexpected Accessibility permission requests as high risk. Official app stores reduce some risk, but they do not remove the threat. Anatsa campaigns have repeatedly shown that malicious apps can reach Google Play before removal.
Mobile device management can reduce enterprise exposure. Companies should enforce device compliance, block risky sideloading, monitor dangerous permissions, require OS updates, separate work and personal profiles, and apply conditional access for mobile devices. High-risk roles should use stronger mobile security controls because their phones are tied to sensitive business workflows.
Banks and fintech companies should strengthen transaction security beyond passwords and SMS codes. Device binding, behavioral analytics, runtime application protection, transaction signing, phishing-resistant authentication, and fraud monitoring can reduce the value of stolen credentials. SMS-based one-time passwords should be treated as a weaker control because mobile malware is designed to intercept them.
User education should use concrete mobile examples. People should recognize fake PDF readers, fake package trackers, fake government apps, fake bank support apps, fake device updates, malicious APK links, and apps asking for Accessibility permission without a clear reason. The most effective education shows users the exact screens and permission prompts attackers abuse.
Comparison framework for mobile stealers and banking trojans
The best way to compare mobile stealer families is to evaluate them by fraud capability rather than only by stolen data. A desktop stealer comparison often focuses on browsers, wallets, files, and exfiltration. A mobile comparison should focus on overlays, Accessibility abuse, SMS and notification theft, remote control, target-app coverage, and on-device fraud.
| Dimension | Low | Medium | High |
|---|---|---|---|
| Target scope | One app or narrow region | Several banks or apps | Hundreds of banks, fintech apps, crypto apps, and regions |
| Credential theft | Basic phishing screen | App-specific overlays | Dynamic overlays with keylogging and session support |
| OTP access | Basic SMS reading | SMS and notification theft | SMS, notification, authenticator, and real-time capture support |
| Accessibility abuse | Limited permission use | Screen reading or click support | Full automation, permission escalation, anti-removal behavior |
| Remote control | No remote control | Basic commands | Screen streaming, gesture capture, on-device fraud |
| Persistence | Simple app install | Hidden icon or background service | Anti-removal, device admin abuse, repeated permission recovery |
| Enterprise impact | Consumer banking only | Email or messaging exposure | VPN, cloud, SaaS, authenticator, and business app exposure |
| Remediation complexity | Remove app and reset password | Remove app, reset credentials, review accounts | Full device cleanup, session revocation, account review, financial investigation |
This framework helps explain why two mobile threats can have very different risk levels. A fake banking app that captures a password is dangerous. A full banking trojan with Accessibility abuse, overlays, notification theft, and remote control can support live fraud from the victim’s own device.
How mobile stealers fit into the broader infostealer economy
Mobile stealers are becoming more important because criminals follow authentication. As banks, fintechs, SaaS platforms, and cloud providers strengthen desktop security, attackers look for the device that receives approvals, messages, and recovery codes. The phone is now an identity hub, and mobile malware is designed to exploit that role.
The market also rewards specialization. Windows stealers dominate credential-log volume, while mobile banking trojans dominate fraud enablement. A Windows stealer may give an attacker stored credentials and browser sessions. A mobile trojan may give an attacker the ability to watch, click, approve, intercept, and transact. These are different forms of value in the same cybercrime economy.
The mobile ecosystem also has a regional dimension. Many banking trojans focus on specific countries, banks, languages, and payment systems. A family may be highly active in Europe, North America, Latin America, Southeast Asia, or specific local banking markets. Target lists can change quickly through configuration updates, which makes continuous monitoring important.
Conclusion
Android and mobile stealers are among the most dangerous forms of infostealer malware because they target the device closest to authentication and financial activity. They steal credentials, intercept SMS messages, read notifications, abuse Accessibility Services, display banking overlays, capture screens, and in advanced cases allow attackers to perform fraud directly from the victim’s phone.
Families such as Anatsa, Cerberus, Alien, ERMAC, Octo, Xenomorph, SOVA, SharkBot, Godfather, Medusa, Vultur, SpyNote, BRATA, Hook, TrickMo, and Mamont show how broad the mobile threat landscape has become. Some are classic banking trojans. Some are remote-access tools. Some are hybrid infostealers. The common thread is access to identity, money, and authentication.
For defenders, the main lesson is that a mobile stealer infection should be treated as both a malware incident and an identity-fraud incident. Removing the app is only one part of the response. Users and organizations should reset credentials, revoke sessions, review banking and payment activity, check email and SaaS accounts, remove risky permissions, inspect device integrity, and consider a full device reset when high-risk malware is confirmed.
For businesses, mobile security now belongs in the same conversation as endpoint security, identity security, cloud security, and fraud prevention. The phone is no longer only a personal device. It is a business access point, an authentication device, and a financial control surface. Attackers understand that clearly, and mobile banking trojans are built to take advantage of it.