Kaspersky detects more new banking Trojan packages in one quarter of 2026 than in the whole of 2024, signalling a sharp escalation in mobile financial threats.
Cybercriminals are increasingly following the money—and that money is now sitting inside smartphones. New research from Kaspersky reveals a dramatic escalation in mobile banking threats, with the company detecting 162,275 new mobile banking Trojan installation packages in the first quarter of 2026 alone.
The figure is more than twice the number detected throughout all of 2024 and represents roughly two-thirds of the total recorded during 2025. Banking Trojans accounted for 52.96% of all malicious mobile applications detected during the quarter, rising sharply from around 31% across 2025.
The numbers highlight a fundamental shift in the cyber threat landscape. Smartphones are no longer secondary targets. As consumers increasingly use mobile devices for banking, shopping, work and communication, they have become repositories of financial credentials, personal information and sensitive business data.
“Cybercriminals are increasingly leveraging sophisticated techniques to distribute malicious mobile applications through unofficial app stores, phishing links, fake giveaways and modified legitimate applications,” said Choon Hong Chee, Head of Consumer Channel for APAC at Kaspersky.
Kaspersky also blocked more than 2.67 million mobile attacks involving malware, adware and unwanted software during the quarter, while detecting over 306,000 malicious installation packages.
Attackers are exploiting unofficial app stores, phishing links, fake giveaways, malicious advertising and modified legitimate applications to reach victims. Increasingly sophisticated, multi-stage attacks are also abusing trusted online services and legitimate tools to evade detection.
The rapid growth of AI-powered scams adds another layer of concern. With fraud becoming faster and more convincing, mobile security can no longer be treated as an optional consumer add-on.
For users and organisations alike, the message is increasingly clear: the smartphone has become a primary gateway to digital life—and protecting it must now be a cybersecurity priority.
