Trojan
Malware that disguises itself as a useful application while running malicious functions in the background.
A trojan (after the Trojan horse) disguises itself as a useful program – e.g. a PDF reader or a game – while running malicious functions in the background: stealing passwords, opening backdoors, downloading further malware.
Android banking trojans like Anatsa and SharkBot remain active in 2026 and usually reach devices through tampered third-party apps.
Why this matters in 2026
Android banking trojans are the most active trojan segment in Switzerland in 2026. Anatsa, SharkBot and Brokewell target apps from PostFinance, UBS, ZKB and cantonal banks – usually via PDF-reader bait apps in the Play Store that fetch the malicious payload after installation.
How to protect yourself
On Android: install only from the Play Store, keep sideloading disabled, install a mobile security app with banking protection (Bitdefender Mobile, Norton 360 Mobile, Kaspersky Mobile). Review app permissions critically – a PDF reader does not need accessibility-service access.