It still is common. They just replaced ActiveX plugins with native Windows apps because ActiveX has a bad rep. It's still Windows through and through, and most of those "security" apps are borderline spyware.
I have to use Korean banks and government websites daily for business, and I keep them safely segregated inside a VM.
The crypto nerds (including me) might think this is a splendid idea--perfect security!
The downside: they did this to shift the blame to the consumer if something goes wrong. If there is a credit card fraud, the consumer is automatically at fault by default, since obviously the consumer mishandled the public key crypto file. This makes sense, but this also means no chargebacks and other nasty side effects.
Also, this also meant that you had to install a bunch of ActiveX verging-on-malware-ware to get your banking shit settled. Now it supports Chrome and Firefox but holy crap, they install a ton of weird malware protection software and I'm pretty sure some of them take a cut from your computer's performance and stability. I'm just glad they don't display fucking ads.
They stoped using ActiveX in the 00s but then started requiring the user to install some rootkit-like security software that was nearly impossible to uninstall and was probably able to spy on users.
Now they some of them have an app that is basically a bundled browser accessing their regular website.