Remote Access Trojan Infections Surge 55% As Malware Becomes a Growing Driver of US Credit Union Fraud: BioCatch
A recent report from cybersecurity firm BioCatch reveals that Remote Access Trojan (RAT) infections have exploded by 55% at US credit unions, making RAT-enabled schemes responsible for roughly 15% of all credit union fraud this year.
The report , which draws on data from over 200 financial institutions, shows credit unions being increasingly targeted by fraudsters using RATs as part of account takeover attacks.
Attempted account takeovers (ATO) involving RATs rose about 50% during the first half of 2025 even as attempts at account opening fraud declined by about 18%. Fraud carried out via stolen devices is also on the rise.
BioCatch says the shift in tactics reflects a broader evolution in digital banking threats where traditional defenses are being tested by increasingly sophisticated tools.
“Fraudsters are pivoting to multi-channel approaches to drain accounts. Through digital banking, they are able to collect card information and add it to digital wallets. They can then use these cards at ATMs, for in-store purchases, and more. In many cases, victims cannot recover any of the stolen money. This type of activity has increased significantly so far this year, rising from just 8% of all fraudulent activity reported by BioCatch’s credit union customers at the beginning of 2025 to 18% in August.”
Credit unions, which often have fewer resources than large banks for threat detection and cybersecurity infrastructure, appear especially exposed to RAT attacks and card-based fraud.
According to BioCatch, coordinated efforts with regulatory agencies and technology partners may also be needed to cut off fraud in its evolving forms before it becomes unmanageable.
Generated Image: Midjourney
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
COC the Game Changer: When Everything in GameFi Becomes "Verifiable", the Era of P2E 3.0 Begins
The article analyzes the development of the GameFi sector from Axie Infinity to Telegram games, pointing out that Play to Earn 1.0 failed due to the collapse of its economic model and trust issues, while Play for Airdrop was short-lived because it could not retain users. COC Game has introduced the VWA mechanism, which verifies key data on-chain in an attempt to address trust issues and build a sustainable economic model. Summary generated by Mars AI. This summary was generated by the Mars AI model, and its accuracy and completeness are still being iteratively updated.

BTC Volatility Weekly Review (November 17 - December 1)
Key metrics (from 4:00 PM HKT on November 17 to 4:00 PM HKT on December 1): BTC/USD: -9.6% (...

When all GameFi tokens have dropped out of the TOP 100, can COC reignite the narrative with a Bitcoin economic model?
On November 27, $COC mining will be launched. The opportunity to mine the first block won't wait for anyone.

Ethereum's Next Decade: From "Verifiable Computer" to "Internet Property Rights"
Fede, the founder of LambdaClass, provides an in-depth explanation of anti-fragility, the 1 Gigagas scaling goal, and the vision for Lean Ethereum.

