September 29, 2026

On-Device Fraud: How Mobile Malware Bypasses Fraud Detection

A few months ago, a friend told me about a relative who received a phone call from someone claiming to be from his bank. The “bank employee” walked him through a "security check," and installed what he thought was a banking app update. Twenty minutes later, his balance was gone. No suspicious link. No stolen card. Nothing his bank's fraud engine ever saw, because the fraud never touched the bank's systems. It happened entirely on his phone.

That story stuck with me because it captures something the industry is still catching up to. For years, fraud prevention meant watching the wire, the session, the login. Velocity checks, device fingerprinting, behavioral biometrics, all built to catch something unusual happening between a user and a server. But a growing share of banking fraud never reaches that server in a form any system can flag. The attacker is already inside the device, riding the user's own authenticated session, tapping through the same screens a legitimate customer would.

Meet a few from the family

Security researchers have been tracking this shift closely, and three malware families illustrate it well.

TsarBot, first documented by Cyble's threat intelligence team in early 2025, went after more than 750 applications spanning banking, cryptocurrency, payments, and social media across multiple regions. It builds a fake lock screen tailored to the exact PIN or pattern the device uses, then quietly harvests it. It also carries out screen recording and remote control, along with keylogging and SMS interception — a full toolkit for taking over a session without ever needing the user's password to leave the device.

CopyBara, analyzed extensively by Zscaler's ThreatLabz and Cleafy Labs, has been targeting banks and crypto exchanges in Italy and Spain since late 2023. What makes it notable isn't just the credential theft. Cleafy's researchers described how the malware performs unauthorized money transfers directly on the victim's device via instant payments, which is exactly the kind of on-device fraud that renders conventional anti-fraud countermeasures largely ineffective. The transaction looks legitimate because, technically, it is. It's coming from the real app, the real device, the real session.

Hook traces back to ThreatFabric's 2023 discovery, an evolution of the ERMAC family with remote access tooling bolted on. As ThreatFabric put it at the time, that RAT capability is what allows a full device takeover, completing the entire fraud chain from data theft to transaction without needing any additional channel. Newer variants have added ransomware-style overlays and lock screen bypasses, and researchers have observed the malware spreading through GitHub repositories alongside phishing sites.

Why the fraud stack doesn't see it

Here's the uncomfortable part: Most fraud stacks are tuned to notice anomalies in network traffic, IP reputation, or login patterns. On-device fraud doesn't produce many of those signals because the session is genuine. The IP is the customer's home network. The device is the one on file. What's compromised is the layer beneath all of that, the app itself, its accessibility permissions, its ability to trust what it's rendering to the screen.

This is why on-device protection needs to sit closer to the code. Runtime checks that catch overlay injection, accessibility service abuse, and screen recording attempts before a transaction ever gets typed in. Hardened apps that make it painful for a bot like TsarBot to identify what it's even looking at. Real-time threat visibility that tells a security team a specific malware family is active on a specific device, not just that a transaction looked odd after the fact.

Fraud didn't get smarter. It got closer. And the closer it gets to the device, the more the device itself needs to be part of the defense, not just the delivery mechanism for someone else's controls.

Not sure where your app stands against on-device fraud? Talk to us. We will help you figure out what's actually protecting your users.

Discover how Guardsquare provides industry-leading protection for mobile apps.

Request Pricing

Other posts you might be interested in