Your browser is out of date. The site may not function correctly. Please update your browser.
Published:
Read Time: 3 mins
The PlayPraetor threat demonstrates a shift in fraud tactics that many UK financial institutions are not equipped to detect
UK banks are watching the wrong signals as sophisticated Android malware from Europe prepares to cross borders, according to fraud prevention and management company Cleafy. The emergence of PlayPraetor, a new Android banking trojan already targeting EU and other global financial institutions, highlights a fundamental shift in digital banking fraud that could leave UK banks dangerously exposed.
Unlike traditional malware focused on credential theft, PlayPraetor represents a new breed of threat that establishes access and lays the groundwork for fraud long before any transaction occurs. Built as Malware-as-a-Service and designed for scale, these new fraud threats combine remote control, credential harvesting, and session hijacking with sophisticated stealth capabilities that allow it to hide behind permission trickery and user manipulation.
"This isn't just another malware threat – it's confirmation that attackers have shifted their focus much earlier in the fraud chain," said Federico Valentini, Head of Threat Intelligence and Incident Response at Cleafy. “We’re seeing this with other recent malware attacks, including SuperCard X earlier this year, yet banks are still looking at where fraud lands, instead of where it starts. PlayPraetor shows just how far before a fraudulent transaction the attack actually begins."
The threat landscape supports these concerns. Global data shows banking trojan attacks on smartphones nearly tripled in 2024, surging 196% from 420,000 to 1.24 million incidents. More than a quarter of mobile threats in Q1 2025 were banking trojans, with 99% of mobile malware targeting Android devices.
The UK's vulnerability is demonstrated by recent history. SharkBot quietly infiltrated UK devices through side-loaded apps, targeting 22 UK banks. Anatsa (TeaBot) conducted over 30,000 malicious installs via official Play Store apps disguised as PDF readers, while FluBot spread through SMS scams targeting major UK banks including HSBC, Santander, Lloyds, and Halifax.
"The UK banking sector is deeply integrated with Europe's digital infrastructure," Valentini continued. "Once tooling and tactics prove successful elsewhere, they travel fast. It's not a matter of if PlayPraetor will land in the UK, it's when."
Traditional fraud detection systems struggle with modern threats that don't behave like conventional malware. PlayPraetor and similar tools use overlays, remote access, and accessibility abuse while maintaining the appearance of legitimate sessions – making them invisible to systems designed to catch obvious fraud signals.
Cleafy's FxDR platform addresses this challenge by providing session intelligence that spots behavioural anomalies and fingerprints before transactions occur. Rather than reacting to completed fraud, the technology enables banks to see emerging threats during the digital journey.
"Fraud that looks like fraud is easy to catch," added Valentini. “With greater visibility into session anomalies and behavioural fingerprints, banks can see fraud long before most systems would even classify something as risky, helping them to move from 'Did we block it?' to ‘We saw it coming.’”
As more banking fraud adopts modular, highly scalable and successful technical and business models that can be rapidly adapted to new markets, UK financial institutions are being urged to strengthen their defences beyond traditional endpoint security and transaction monitoring to session-level visibility. With the rise in mobile fraud, and Android providing expanding attack surfaces, early detection capabilities are essential for safeguarding customers and institutions.
To find out more visit www.cleafy.com
ENDS
Images can be downloaded here.
Ends
Cleafy is a fraud prevention and management solution for digital banking and payment service providers. Its AI-powered platform brings together fraud management and cybersecurity, using multidimensional detection to track and neutralise threats before they result in fraud – in real time, and with minimal impact on the user experience. Founded in 2014 by tech alumni of the Polytechnic University of Milan, Cleafy sets the standard in proactive fraud prevention for leading banks and financial institutions, securing billions of transactions across over 120 million accounts globally.
For more information visit www.cleafy.com