Isnin, 21 September 2026


Back in 2009, banking malware was already nasty.

One old TechViewz post, New Banking Trojan Nasty and Formidable, talked about malware that could manipulate online banking sessions and steal information from users.

At the time, the big fear was pretty simple.

Someone steals your banking password.

Fast forward to 2026 and the problem has changed quite a bit.

Modern banking malware does not always want just your username and password anymore.

It wants your phone.

That matters because your phone now contains almost everything needed to prove that you are you.

Your banking app.

Your SMS messages.

Your OTP or TAC codes.

Your email.

Your contacts.

Your device PIN.

Your active login sessions.

Sometimes even your e-wallet.

Recent Android banking Trojans have been designed to abuse Accessibility permissions, show fake login screens over real banking apps, intercept SMS messages, record screens and remotely control parts of the device. MyCERT warned Malaysian users this year about malicious APK campaigns targeting banking customers through fake courier, job and app-update messages.

The interesting part is what happens next.

Instead of stealing your password and logging in from another computer somewhere overseas, some newer malware is designed for on-device fraud.

Basically, the attacker can use your infected phone itself.

That means the bank may see the same device, same IP address, same app session and other familiar signals it normally uses to decide whether something looks suspicious. Malware such as ToxicPanda 2.0 has been designed specifically around this idea.

That is a very different problem from the banking Trojans people worried about fifteen years ago.

The banking app itself might be perfectly legitimate.

The phone around it might not be.

And that is what makes mobile banking malware uncomfortable.

We spent years making banking easier. No browser. No physical token. No trip to the branch. Just unlock the phone, open the app and approve the transaction.

Convenient.

But the phone also became the place where identity, authentication and transactions all meet.

That broader shift toward identity becoming the new security boundary is explored in The New Security Perimeter Is No Longer The Network. It Is Identity.

For normal users, the lesson is less complicated.

Be extremely suspicious when a parcel message, job offer, app update or random link asks you to install an APK outside the official app store. MyCERT specifically warns against sideloading apps from links received through messaging apps, SMS or social media.

In 2009, banking malware wanted your password.

In 2026, stealing the password may only be step one.

Because if attackers can control the device that receives the OTP, opens the banking app and approves the transaction, they do not just have your password.

They have the place where your digital identity lives.