Introduction
The finance sector continues to face sustained and evolving cyber threats driven by the high value of financial data, credentials, and transactional access. Malware remains one of the most common and effective mechanisms used to compromise financial institutions, payment platforms, and end users, enabling fraud, data theft, and operational disruption.
According to Bitsight Threat Intelligence, malware activity impacted approximately 34 percent of organizations observed, accounting for 36 percent of total attacks over the past year. Financial services organizations remain particularly exposed due to the direct monetization potential of stolen credentials, sensitive customer data, and authenticated system access.
Financially motivated malware campaigns increasingly rely on scalable delivery methods, credential theft, and exploitation of trusted technologies rather than novel techniques. As a result, many intrusions generate their most significant impact after initial compromise, when stolen data or access is reused, resold, or leveraged for fraud.
This blog highlights the top malware categories currently targeting the finance sector, examining how these threats are delivered, how they operate, and the risks they pose to organizations and customers.
Methodology and scope
This assessment is based on analysis conducted by Bitsight Threat Intelligence, incorporating telemetry, malware analysis, incident reporting, and observed attack patterns affecting financial organizations and their customers.
The scope of this report focuses on malware categories most commonly associated with financial impact, including credential theft, fraud, data exposure, and unauthorized system access. Coverage includes both enterprise-targeted malware and consumer-focused threats that generate downstream risk for financial institutions.
To maintain relevance and accuracy, this report emphasizes observed techniques, delivery methods, and operational behaviors rather than attribution to specific threat actors or ransomware groups. Malware-as-a-service ecosystems are discussed as enabling models where applicable, reflecting their role in scaling financially motivated activity.
Metrics referenced reflect aggregated observations over the past year and are intended to illustrate relative prevalence and impact rather than exact incident counts. Findings are presented to support risk prioritization, detection strategy development, and incident response planning within the finance sector.
1. Banking trojans
Banking trojans have remained a consistent threat to the finance sector as the adoption of online banking and digital payments increases. These malware families are specifically designed to steal credentials related to banking platforms, financial services, and cryptocurrency exchanges.
According to Bitsight Threat Intelligence, banking trojans continue to serve as key initial access vectors in financially motivated attacks, likely due to their ability to remain undetected, propagate widely, and target high-value environments. This conclusion is drawn from:
- Detection of known banking trojan indicators (file hashes, command-and-control infrastructure, and payload behaviors) across financial organizations and their supply chains.
- Correlation of credential theft activity with malware exposure.
- Trend data showing ongoing use and re-use of families such as Anubis, Hydra, and Cerberus.
- Deep and dark web monitoring showing advertisement, evolution, and sale of banking trojans by criminal actors.
An example detection included a financial platform in Southeast Asia with observed command-and-control communication linked to infrastructure previously associated with the Anubis banking trojan (IP: 185.141.62.123).
Most banking trojans are modular in design. After initial infection, they can download additional functionality tailored to the victim, enabling credential theft, session hijacking, or remote access.
Email attachments continue to be the most common delivery mechanism. These typically contain macros or embedded scripts that execute malware under the guise of legitimate business communication. Once active, infections may support credential theft, fraud, or resale of access on underground forums.
Modern banking trojans are increasingly sophisticated. Capabilities may include overlay attacks on banking apps, interception of SMS-based authentication, abuse of accessibility services, keylogging, screen recording, and remote control. These features allow attackers to conduct unauthorized transactions with minimal user awareness.
Geographically, banking trojan activity has been especially prevalent in Brazil, Turkey, and Southeast Asia, where malware campaigns are often customized for local financial institutions and payment platforms.
Recent examples:
- DoubleTrouble Android Banking trojan spread through Discord. Initially, DoubleTrouble was spread through phishing sites. In July 2025, security researchers observed DoubleTrouble distributing malicious Android Package Kits (APKs) hosted through Discord channels which allowed them to evade detection.
- Klopatra Android Banking Trojan, infected thousands of devices. Klopatra functions both as a Remote Access Trojan (RAT) and an Android Banking Trojan. In August 2025, security researchers discovered that the banking trojan had infected an estimated 3,000 devices in Spain and Italy. According to Bitsight Threat Intelligence, Klopatra Banking Trojan appeared in March of 2025 and has 40 distinct builds.
2. Android banking malware
Android banking malware continues to evolve alongside the growth of mobile banking, posing a persistent threat to end users. These threats typically aim to steal credentials, intercept one-time passwords (OTPs), and gain unauthorized access to financial applications, often resulting in account takeovers, fraudulent transactions, and long-term erosion of customer trust.
In 2025, Bitsight observed elevated levels of Android banking malware activity with a significant spike in detections during August and September. Campaigns observed across Turkey, Spain, Italy, and Southeast Asia illustrate how regional mobile threats are tailored to local languages, payment platforms, and mobile banking habits.
These campaigns frequently involve malicious Android applications distributed through unofficial sources or disguised as legitimate tools like PDF readers, streaming services, or phone optimizers. Once installed, the malware leverages advanced techniques such as overlay attacks, SMS interceptions, keylogging, and abuse of Android Accessibility Services to harvest credentials in real time.