Threat Intelligence

What active or emerging threats are targeting European banking in January 2026

TLT
Threat Landscape Team
2026-01-208 min read

Current threat intelligence points to a surge in operator-driven mobile banking trojans and industrialized phishing ecosystems aimed squarely at European financial institutions. The Klopatra Android RAT is an emerging threat that has evolved quickly and keeps its targeting focused within Europe.

Primary Active Threats

The following table summarizes the most prominent malware families and services currently targeting European banking organizations:

Malware/Threat NameThreat Actor / OriginPrimary TargetsKey Characteristics
KlopatraTurkish-speaking GroupEuropean Banking AccountsUses Hidden VNC (HVNC), Accessibility abuse, and commercial-grade obfuscation (Virbox) to perform real-time, silent fraud.
Katz StealerUnknownItaly, Finland, ManufacturingInformation stealer often bundled with or related to PureLog Stealer; targets financial and administrative data.
EvilProxyPhaaS ProviderGlobal Banking / CryptoAdvanced phishing-as-a-service (PhaaS) that automates AJAX-looping to bypass MFA tokens in real time.
Cuckoo StealerUnknownBanking InstitutionsEmerging info-stealer targeting retail and financial credentials.
VMDetectLoaderUnknownBanking InstitutionsSpecialized loader designed to detect virtualized environments before delivering banking payloads.

Technical Analysis: Klopatra & Operator-Driven Fraud

Klopatra marks a shift toward "hands-on" fraud. Operators often control the trojan directly, and that lets them mimic legitimate user behavior and bypass advanced fraud detection systems.

MITRE ATT&CK Mapping for Klopatra:

TacticTechnique IDDescription
Initial AccessT1444Sideloading: Delivered via pirated IPTV droppers (e.g., Mobdro Pro IP TV + VPN) requesting REQUEST_INSTALL_PACKAGES.
PersistenceT1624Accessibility Service Abuse: Abuses Android Accessibility APIs to capture screens, inject gestures, and prevent app termination.
Defense EvasionT1406Obfuscation: Employs commercial-grade Virbox packing and native C/C++ libraries to hide core logic from Java-based analysis.
Credential AccessT1411Adversary-in-the-Middle (Overlays): Uses dynamic HTML overlays to harvest banking credentials and PINs.
Command & ControlT1219Remote Access Software (Hidden VNC): Enables a "black screen" mode while the device is charging at night to perform silent transactions via HVNC.

Vulnerability Landscape (CVEs)

Most banking fraud still relies on social engineering and credential theft. Recent bulletins have also flagged the following CVEs as relevant to the wider financial sector:

CVE-2025-23280, CVE-2025-23330, CVE-2025-54252: All three were identified recently and are often weaponized in delivery chains or infrastructure abuse to help financial malware persist.

Infrastructure Abuse: Threat actors increasingly use legitimate services such as AWS X-Ray for covert C2, and signed UEFI shells help them survive as bootkits, preserving long-term access to compromised financial workstations.

Affected European Jurisdictions

Intelligence reports explicitly mention targeted activity in the following European countries:

  • Italy: Target of Katz Stealer and PureLog Stealer campaigns.
  • Finland: Target of Katz Stealer and automated financial fraud campaigns.
  • Turkey: Identified as a primary hub for the development and operation of the Klopatra botnets, with artifacts indicating vertically integrated operations.

Gain continuous, structured threat intelligence with the Threat Landscape Platform. Start free — no credit card required — or upgrade to Professional for just $49/month.

Ready to Transform Your Threat Intelligence?

See how Threat Landscape can reduce alert fatigue and improve your security operations