Mobile Banking Malware Surges 3.6 Times, Crypto Phishing Up 83%

Cybercriminals are increasingly targeting mobile banking and cryptocurrency users, with mobile banking malware incidents rising 3.6 times and crypto-related phishing detections surging by 83.4% in 2024, according to Kaspersky’s latest Financial Cyberthreats report.

Banks remained the primary target for financial phishing, accounting for 42.6% of attacks, up from 38.5% in 2023. Payment systems were mimicked in 19.3% of financial phishing attempts, with PayPal being the most targeted brand, despite its attack share dropping from 54.7% to 37.5%. Meanwhile, attacks on Mastercard nearly doubled to 30.5%.

The number of cryptocurrency-related phishing attempts spiked significantly, with Kaspersky blocking 10.7 million attempts in 2024, compared to 5.8 million in 2023.

On the malware front, PC-focused banking malware detections declined from 312,453 in 2023 to 199,204 in 2024. However, most PC malware shifted focus to crypto-asset theft, with Grandoreiro targeting 1,700 banks and 276 crypto wallets in 45 countries.

Mobile banking malware incidents, on the other hand, surged from 69,200 to 247,949 cases, particularly in the second half of 2024. The Mamont Trojan accounted for 36.7% of mobile banking malware activity, often spread through fake stores and delivery tracking apps. Türkiye remained the most affected country, with an increase to 5.7% of users encountering financial threats, followed by Indonesia (2.7%) and India (2.4%). Malaysia was also affected, with 0.3% of users encountering mobile banking malware.

“In 2024, financial phishing and scams increased in numbers and reached a new level of sophistication, unleashing waves of attacks on users. Fraudsters are increasingly leveraging fake brands and services to get user data, and the popularity of smartphones for financial transactions only fuels their appetite,” said Olga Svistunova, senior web content analyst at Kaspersky.

Kaspersky advises users to enable multifactor authentication, avoid suspicious links, and use reliable security solutions. Businesses are encouraged to implement strict security policies and stay updated with the latest cyberthreats.

Latest News

Must read