In short: Android banking trojans do not steal money by hacking your bank — they trick you on the phone itself. A malicious app gains the Accessibility service and paints a fake input screen on top of your real banking app. You type your login, password and code, and the data flows straight to the attacker. Almost every such trojan reaches the phone through an APK installed outside Google Play. The core defense is simple: never install apps from side links, and never grant Accessibility to anything that does not genuinely need it. A VPN encrypts your traffic and lowers risk on public Wi-Fi, but it will not remove the trojan from your device.
What an overlay attack is and why it is so hard to spot
An overlay attack is a technique where malware displays its own screen on top of a legitimate app, visually identical to the original. You open your bank, see the familiar login form and enter your details — but the top layer belongs to the trojan, not the bank.
To draw over other apps and control the phone at the same time, these trojans need the Accessibility Service. It was built to help people with disabilities — it can read screen content, tap buttons and enter text on the user behalf. In an attacker hands, those same abilities become a remote control: the malware taps Allow on its own, intercepts your input and confirms transactions.
That is why an infection is nearly impossible to notice by eye: the interface looks native, elements seem to tap themselves, and confirmations happen in the background. According to researchers, modern families such as OverlayPhantom and Rokarolla use this approach against dozens of banking and cryptocurrency apps at once.
How the trojan steals money: the infection chain
The attack is almost always broken into stages. First a harmless-looking loader (a dropper) lands on the phone, then it pulls down the real malicious payload and begs for the permissions it needs. Here is the typical flow, step by step.
| Stage | What the trojan does | What the victim sees |
|---|---|---|
| 1. Delivery | A loader arrives as a link in SMS, a messenger or an ad, disguised as a well-known app | Update your app, Parcel delayed, Install this viewer |
| 2. Install | The user installs an APK outside Google Play | An ordinary app install screen |
| 3. Access request | Asks to enable Accessibility under the excuse of optimization or a system update | A pushy dialog with an Enable button |
| 4. Takeover | Reads the screen, draws fake forms over the bank, intercepts SMS codes | Nothing unusual — the interface looks native |
| 5. Theft | Enters data and confirms transfers via remote operator commands | Withdrawals the victim only learns about later |
According to write-ups on OverlayPhantom, the operator can send dozens of remote commands to an infected phone: simulate taps and swipes, change clipboard contents and open fake input windows. Rokarolla also intercepts SMS and records on-screen activity — enough to defeat both login and one-time-code confirmation.
How the trojan gets onto your phone
The key fact: almost all Android banking trojans come not from the official store but from an APK installed from the side. Google Play is not perfect, but it is reviewed — a random link is not. Typical delivery channels:
- SMS and messengers — track your parcel, pay for delivery, your account is locked, each with a download link.
- Fake updates — a site offers to update your browser, Flash Player or a system component.
- Clones of popular apps — the trojan poses as a messenger, a banking or a government app.
- Ads and pop-ups — aggressive banners with a Download now button.
- Install-for-hire services — shady platforms that bypass Android protections for a fee and plant someone else APK on the device.
A second trap hides here too — malicious clones of VPNs and boosters. How to tell a safe app from a fake is covered in our guide to dangerous VPN apps, and the same rules apply to any program.
Signs your phone is infected
The trojan tries to stay invisible, but there are usually indirect symptoms:
- Your banking app hangs on a white or blank screen before login.
- The phone seems to act on its own: the screen flickers, elements tap without you.
- The battery drains fast and the body heats up even when idle.
- Unfamiliar apps or unnamed icons have appeared.
- You receive SMS codes you never requested, or codes vanish from notifications.
- Your bank sends alerts about logins and transactions you never made.
To tell a trojan from an ordinary glitch, use our breakdown of the signs your phone is hacked — if several points match, treat it as an infection.
Checklist: how to protect yourself in advance
Prevention beats treatment. These steps close off almost the entire attack path:
- Install apps only from Google Play or your phone maker official store. A prompt to download an APK is a stop signal.
- Never enable Accessibility at an app request unless it is a trusted tool for people with disabilities. A bank, a game or an optimizer does not need it.
- Keep Google Play Protect on (Play Store, profile icon, Play Protect) — it scans installed apps for malicious behavior.
- Do not disable Restricted Settings — since Android 13 the system blocks side-loaded APKs from Accessibility and notification access by default.
- Turn on Advanced Protection on Android 16/17 if available: it blocks installs from unknown sources and limits Accessibility to verified tools.
- Review app permissions and strip anything extra — details in our guide to dangerous app permissions.
- Move away from SMS codes where you can: an authenticator app or passkeys are harder to intercept. How to harden a login, using a messenger as an example, is in our piece on protecting your account from hijacking.
- Do not follow pay / update / unlock links from SMS, and install nothing through them.
What to do if you suspect an infection
If the symptoms match, act fast and in order — this is a case where minutes matter, because the trojan may be trying to move money right now.
- Take the phone offline — enable airplane mode or turn off the internet to cut the trojan link to its control server.
- Contact your bank from another device, freeze cards and transfers, and change your online-banking password.
- Boot into Safe Mode — only system apps run there, so the malware cannot block its own removal.
- Find and remove the suspicious app. If removal is blocked, first strip its Accessibility and Device Admin rights.
- Run a scan with Google Play Protect and a reputable antivirus.
- Change passwords for key accounts (email, bank, government services) from a clean device.
- When in doubt, factory reset — it is the most reliable way to clear a deeply embedded trojan.
After that, harden the money side of things — how to build safe banking on a phone systematically is covered in our guide to secure online banking.
Does a VPN protect against banking trojans
Let us be blunt, because it matters: a VPN does not remove malware from your phone and does not stop a trojan from drawing a fake screen. If a malicious app is already installed and has Accessibility, encrypting your traffic changes nothing about that. Any service promising virus protection through a VPN is being dishonest.
What a VPN does do is cut off some of the paths the trojan uses to reach you and reduce the surrounding risks:
- it encrypts traffic on public Wi-Fi, where phishing pages with update links are often served — more on this in our article on how to stop phone tracking;
- it hides your real IP and shrinks the data your provider and ad networks collect;
- app filtering in LiMP VPN helps limit which software gets network access at all.
The logic is this: install-and-permission hygiene protects you from the trojan itself, while a VPN covers the transport and privacy around it. If you use banking on your phone and public networks a lot, keeping encryption on makes sense — you can set it up on Android in a couple of minutes with the LiMP VPN app for Android, and compare options on the pricing page.
Frequently asked questions
Can an overlay banking trojan infect an iPhone?
Classic overlay trojans are an Android problem, because Android has the Accessibility service and allows APKs from the side. On iOS apps are strictly sandboxed and cannot draw over other apps, so this scenario is virtually absent on iPhone. Phishing links and fake login pages, however, are dangerous on any platform.
Will an antivirus protect me from these trojans?
A good mobile antivirus and Google Play Protect improve your odds of catching known malware, but offer no guarantee: fresh families disguise themselves and evade signatures. Antivirus is a supplement, not a replacement for the rule of not installing APKs from links and not granting Accessibility.
The trojan intercepts my SMS bank codes — how do I defend against that?
Yes, many trojans read one-time codes straight from notifications. So wherever possible, move from SMS to an authenticator app or passkeys, which are harder to intercept. And never read codes out over the phone to someone calling from your bank.
What are Restricted Settings on Android?
It is a protection introduced in Android 13: apps installed from outside the store do not get Accessibility or notification access by default. If the system offers to lift that restriction for a side-loaded APK, it is almost always a trap.
Is an APK safe if I scan it with an antivirus before installing?
Scanning lowers the risk but does not remove it: malware can download its dangerous part after install or masquerade as a clean file. It is safer simply not to install apps outside official stores.
Do I need to delete my banking app after an infection?
Not by itself: it is the phone that is compromised, not the banking app. First remove the malware (Safe Mode, strip rights, factory reset if unsure), then reinstall your bank from the store and change passwords from a clean device.
Will a VPN protect me from a banking trojan?
A VPN will not remove the malware or stop the screen overlay. It encrypts traffic and reduces risk on public Wi-Fi, but protection from the trojan itself comes from install and permission hygiene, not from a VPN.
