Blog / Threats
Threats
Mobile Banking Malware: The Phone That Approves Your Payments Now Works for Someone Else
Mobile banking malware on one phone can overlay the bank app and forward one-time codes. How it gets in and how to keep it off the phones that approve payments.
The delivery app that delivered the bank
The accountant at a Sharjah trading company is expecting a shipment of samples from a supplier in Guangzhou. A text arrives on her Android phone: the parcel is held, and there is a link to track and release it. The link opens a page that looks like a courier's, which explains that the tracking app is not on the app store "for regional reasons" and walks her through installing it directly. She has done this before for a payment app. She taps allow, allow, allow.
The tracking app shows a parcel on a map. It never moves, but she is busy.
Two days later she opens the company's banking app to approve a supplier payment, and the login screen looks a shade different. Same logo, same colors, a fraction slower. She signs in. A one-time code arrives by text. She enters it. The app says the session timed out and asks her to try again, which works the second time.
What she has done, without seeing it, is type her banking credentials into a fake screen the "tracking app" drew on top of the real one, and hand over the code the bank sent to prove it was her. The app has also been quietly reading every text message since Tuesday. By Thursday afternoon there are three new payees on the account and two transfers pending approval from a phone that is, as far as the bank can tell, hers.
What the heck does this mean
Mobile banking malware is malicious software on a phone whose purpose is to take over the owner's bank account. The phone is the target because the phone is where the money now gets approved.
A banking trojan is that malware in its most common form: an app that pretends to be something harmless, a courier tracker, a PDF reader, a "system update," and waits for you to open your bank.
An overlay attack is the fake screen. The trojan detects when the real banking app opens and draws its own login page on top, pixel for pixel, so what you type goes to the attacker first.
SMS OTP interception is reading the one-time code your bank sends by text. If the malware can read your messages, the code protecting your account is the same code the attacker is holding.
Sideloading is installing an app from outside the official store. It is how most banking trojans arrive, because the store's checks are the thing they cannot pass.
The owner's version: the phone your accountant approves payments on is now a device on your network, and probably the least protected one you have.
The numbers that matter
Banking trojans made up 52.96% of detected mobile malware in the first quarter of 2026, with 162,275 banking-trojan installation packages found, according to Kaspersky Securelist's Q1 2026 mobile statistics. More than half of everything caught on phones that quarter was after a bank account.
New Android banking-trojan installers reached 255,090 in 2025, up 271% on the year before, per Kaspersky's 2025 annual mobile report. This is not a niche. It is an industry with a product roadmap.
The UAE Cyber Security Council reported in 2025 that the country had recorded more than 12,000 Wi-Fi breaches since the start of that year, 35% of all incidents in the period. The public network at the cafe where your accountant checks the bank is part of the attack surface too.
What to do this week
- Buy a dedicated phone for payment approvals. No email, no messaging apps, no browsing, nothing sideloaded. It lives with the person who approves transfers and nowhere else. A basic Android or iPhone costs less than a single fraudulent payee. (CIS 1 Inventory and Control of Enterprise Assets)
- List every phone that has a company banking app, a payment approval role, or company email on it, and who owns each one. If you cannot list them, you cannot protect them. (CIS 1 Inventory and Control of Enterprise Assets)
- Put mobile security software on every company-managed phone and block installation from unknown sources on Android. The "regional reasons" app should have been impossible to install. (CIS 10 Malware Defenses)
- Ask the bank to move approvals off SMS codes to app-based approval with device binding or a physical token, and to require two separate people for any new payee. (CIS 6 Access Control Management)
- Set transfer limits and new-payee delays in the banking platform, so a third payee added on a Thursday afternoon waits until Monday and a phone call. (CIS 6 Access Control Management)
- Tell staff, in one short message, the two things never to do on a phone that touches company money: install an app from a link, and grant accessibility or draw-over permissions to anything that is not a known accessibility tool. (CIS 14 Security Awareness and Skills Training)
Where AccuSights fits
Our assessment includes the devices most audits ignore: the phones that approve payments, the personal handsets with company email, and the permissions granted to apps nobody remembers installing. The Cyber Hygiene Test takes three minutes and asks in plain language. For a second opinion on your payment approvals, book 15 minutes with an engineer and bring the accountant.
Questions people ask
Is SMS one-time code safe for business banking? It is better than a password alone and worse than every other option. A text message can be read by malware on the phone, redirected by a SIM swap, or typed by your own accountant into a fake page. Ask your bank for app-based approval, a hardware token, or a physical security key for the accounts that move money. Keep SMS as the fallback, not the standard.
Should staff use personal phones for company banking apps? Only if the company can see and manage that phone, and for a small business that usually means no. A personal phone has whatever apps the family installed, sideloaded or otherwise, and you cannot check it without the owner's cooperation. Buy a dedicated phone for payment approvals. It costs less than one fraudulent transfer, and it can live in a drawer when it is not needed.
How do I tell if a phone has a banking trojan? Look for an app you do not remember installing that asked for accessibility permissions or the right to draw over other apps, a bank app that suddenly asks you to sign in again with a slightly different screen, text messages arriving and disappearing, or a battery that drains faster than it used to. If you see any of these, stop using the phone for banking, call the bank from another device, and have the phone wiped.
The parcel never arrived. The attacker did. Give the phone that moves your money the same respect you give the safe it replaced.
Questions people ask
Is SMS one-time code safe for business banking?
It is better than a password alone and worse than every other option. A text message can be read by malware on the phone, redirected by a SIM swap, or typed by your own accountant into a fake page. Ask your bank for app-based approval, a hardware token, or a physical security key for the accounts that move money. Keep SMS as the fallback, not the standard.
Should staff use personal phones for company banking apps?
Only if the company can see and manage that phone, and for a small business that usually means no. A personal phone has whatever apps the family installed, sideloaded or otherwise, and you cannot check it without the owner's cooperation. Buy a dedicated phone for payment approvals. It costs less than one fraudulent transfer, and it can live in a drawer when it is not needed.
How do I tell if a phone has a banking trojan?
Look for an app you do not remember installing that asked for accessibility permissions or the right to draw over other apps, a bank app that suddenly asks you to sign in again with a slightly different screen, text messages arriving and disappearing, or a battery that drains faster than it used to. If you see any of these, stop using the phone for banking, call the bank from another device, and have the phone wiped.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Deepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director
Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.
ThreatsBusiness Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank
Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.
Reputation and business riskCyber Insurance in 2026: The Renewal Form, the Premium and the Claim That Gets Denied
Cyber insurance requirements in 2026: what the renewal form asks, why premiums moved, and how a ticked box about MFA on a shared mailbox gets a claim denied.
