Download the PDF version
Malware

Early Malware Detection: catching the malware nobody has named yet

Published:
24/9/2026

Generative AI has broken the assumption on which the security industry was built: that malware evolves slowly enough to be catalogued.

For decades, defence against malware relied on a single mechanism: classification. Someone captures a sample, analyses it, assigns it to a family and publishes a signature. Everyone downstream is then protected against that variant. It is an elegant arrangement, and it has held for decades, on one condition nobody thought to write down: that malware evolves slowly enough to be catalogued before it does real damage. 

Generative AI has removed that condition. Building a new variant of a banking trojan used to take a criminal developer weeks; it now takes hours, and costs close to nothing. The malware is not necessarily cleverer than it was. There is simply far more of it, arriving far faster. And a variant built an hour ago has no signature of its own, however well understood its ancestors are.

A signature is evidence of yesterday’s malware. It cannot describe software nobody has seen yet, because describing what has already been seen is the entire mechanism. Signature-based detection is retrospective by construction. To a defence built on signatures, an application without a name is invisible.

The scale of the problem

Kaspersky recorded a 188% surge in NFC relay attacks on smartphones during the first four months of 2026, driven by malware families including SuperCard X, PhantomCard and NGate. Behind figures like that sits an attack surface of roughly 3.8 billion digital banking users.

SuperCard X shows what that gap looks like in practice. When Cleafy’s Threat Intelligence team uncovered the campaign in April 2025, antivirus engines did not yet recognise it. It was already relaying stolen card data through live NFC relays, funding fraud against real customers, and formally, it did not exist. Having no name, it was absent from the defences that look for names.

It is not an isolated case, and the scale is the point. Cleafy’s researchers found a TeaBot dropper on the official Google Play Store disguised as a QR code scanner, with more than 100,000 downloads behind it; the family’s target list eventually reached around 400 banking, crypto and insurance apps. ToxicPanda, identified by the same team in October 2024, had already reached over 1,500 devices and customers of 16 institutions across Europe and Latin America by the time it was named, with more than half the cases in Italy. Each of these was operating at that scale before anyone had a name for it.

Over the past 12 months, Cleafy’s Early Detection has processed 3,887,399 unique APKs from 10 different countries.

Of these, 70,767 were flagged as malware and classified into more than 50 active malware families, a third of which were entirely new, discovered during 2026, and automatically identified by Early Detection. Precision reached 99.9%: after manual verification by our Threat Intelligence team, virtually all of these 70k APKs were confirmed as mobile malware, with fewer than one false positive per month.

94.67% of all mobile malware signatures released by our Threat Intelligence team were automatically flagged as malicious by Cleafy’s Early Detection in real time, before any human review.

A bank’s options against unknown malware: wait, block, or decide

A bank that spots an unfamiliar application on a customer’s device has had two courses of action available, and both cost something.

  • Wait. Hold off until somebody, somewhere, proves the application malicious, and concede the whole of that gap to the fraudster.
  • Act anyway. Move on incomplete evidence, and risk disrupting legitimate customers.

One choice costs money, the other costs trust. Neither is a strategy. Both are a decision about which cost to absorb.

The third course is to decide. Assess what the application is doing and reach a judgement while the gap is still open. That is what Cleafy built Mobile Malware Early Detection to do. Proprietary AI models pre-classify suspicious mobile applications in real time, before a formal signature exists, and issue a signal that works inside a bank’s existing rules and policies: step-up authentication, transaction holds, watchlists, with no redesign of fraud operations.

A signature is evidence of yesterday’s malware.

How accurate is early malware detection?

An early verdict is worth nothing if the fraud team cannot trust it. Early Detection is calibrated to stay silent rather than to guess: 99.9% of its pre-classifications are confirmed true positives, and it flags 96% of applications that are later confirmed malicious before any formal signature exists.

The rest are cases where the service declines to call it, judging the evidence too thin for a high-confidence verdict. Manual analysis and conventional signatures pick those up afterwards. Coverage stays complete, and the false alarms stay absent, which is the trade most fraud teams would make every time. Early Detection complements threat intelligence rather than replacing it.

Analysts are not asked to trust a black box either. Every pre-classification arrives with a plain-language explanation: the suspected malware family, an analysis of the permissions the application requests, and the reasons it was flagged. The reasoning can be read before the verdict is acted on.

None of this is experimental. The capability has been running in production at a major European bank for more than a year, its signals feeding live fraud and security decisioning, before becoming generally available.

Where signature-based detection still fits

The signature still has work to do. It confirms, it records, and it catches the borderline cases Early Detection deliberately leaves alone. What it can no longer be is the place where defence begins, because the timeline has moved and the signature has not.

Banks have spent decades getting better at recognising malware. The exposure now sits in the hours before there is anything to recognise.

Read more articles

Artificial intelligence

Every bank has an AI strategy. None has AI where the risk lives.

Read more

Regulation

Attackers don't have a compliance deadline. Banks now have two.

Read more

Artificial intelligence

The criminals’ AI is already in production. Banking’s isn’t.

Read more