Skip to main content
Emerging ThreatsMalware & Ransomware

Mobile Malware Attacks Decline, Banking Trojans Persist

Smartphone on cluttered desk with blank screen in soft daylight.

"More than 1.99 million attacks on mobile devices utilizing malware, adware, or unwanted mobile software were blocked." — Kaspersky Security Network

Kaspersky: overall volumes fall but threats persist

According to telemetry from Kaspersky Security Network, attacks on mobile devices that involved malware, adware, or unwanted software fell to 1,996,823 in Q2 2026, down from 2,676,328 the previous quarter. The number of Android malware samples discovered in Q2 stood at 304,128, a level described as steady compared with the prior reporting period. Kaspersky also reported more than 304,000 malicious installation packages found during the quarter, including 93,574 packages related to mobile banking Trojans and 570 packages connected to mobile ransomware Trojans.

Google Play loaders and an SDK-based evasion technique

Kaspersky’s telemetry identified multiple malicious loader apps hosted directly on Google Play in Q2. One example was a trojanized PDF reader that presented users with a fake update prompt; the prompt was used to stage the Anatsa banking malware. Another loader discovered in the Cleanova app sent requests to a command-and-control server that included telemetry from various analytics SDKs to indicate the installation source. The server returned a malicious payload only for specific installation sources; if the SDK telemetry showed an installation was outside the actors’ scope, the malicious logic remained dormant. Kaspersky described this as a method that can bypass app store review processes while enabling precise victim targeting.

Banking Trojans: Creduz builds up, Mamont dominates user impact

The Trojan-Banker category remained the most prevalent mobile malware class, accounting for 30.77% of total detected applications. Q2 saw a sharp fall in the total volume of Trojan-Banker installation packages to 93,574, but the distribution among families shifted. Kaspersky noted a strong increase in the share of Creduz among identified banking samples, coupled with limited activity in victim telemetry — a pattern Kaspersky interpreted as threat actors generating a high volume of builds (likely testing features or bypasses) before broader campaigns.

By contrast, the practical impact on users continued to be dominated by Mamont variants. In the top-10 mobile bankers by proportion of targeted users, Trojan-Banker.AndroidOS.Mamont.hl rose to 11.13% (from 3.27% in Q1), Mamont.iv to 7.33%, and additional Mamont variants (mv, mg, jo, mc, lf) populated the leaderboard. Kaspersky pointed to ongoing, active development of new Mamont variants even as some banking Trojans were repackaged and reclassified as droppers.

Triada and the top mobile malware families

The top-20 most frequently detected mobile malware types showed a heavy presence of Triada family members. Backdoor.AndroidOS.Triada.ag increased to 9.35% of attacked users (up 2.25 percentage points from Q1) and Triada variants appear repeatedly through the ranking (Triada.z, Triada.fe, Triada.hf, Triada.ad, Triada.ab, Triada.ae, Triada.ii). Other notable movements included DangerousObject detections (Generic and GenericML) and jumps for several droppers and spy families: Trojan.AndroidOS.Boogr.gsh rose to 3.33% and Trojan-Spy.AndroidOS.Btmob.e registered 2.27% after being absent in Q1.

Kaspersky also recorded a rise in Trojan-Dropper activity, driven primarily by banking droppers such as Trojan-Dropper.AndroidOS.Banker and Trojan-Dropper.AndroidOS.Mamont; for example, Trojan-Dropper.AndroidOS.Banker.dd moved from 0.01% in Q1 to 2.16% in Q2. Within adware, the most pronounced declines were observed in HiddenAd and MobiDash families.

What this means for mobile security teams, app stores, and end users

  • Mobile security teams should monitor large volumes of Creduz builds and rising Mamont variants: Kaspersky’s data shows active iteration even when victim telemetry remains low.
  • App store operators and platform owners must watch SDK-origin signals as an evasion vector: Kaspersky detailed loaders that check analytics SDK telemetry before activating malicious payloads, a technique that can conceal malicious behavior from automated reviewers.
  • Enterprises and device managers should note the reported link between reduced pre-installed Trojan activity and the rollout of patched vendor firmware; Kaspersky observed a downward trend in attacks driven by pre-installed strains likely tied to that firmware rollout.
  • End users should be wary of in-app prompts to "install updates" and of sideload-like behaviors in apps that otherwise appear legitimate — Kaspersky’s examples include a trojanized PDF reader used to drop Anatsa.

Kaspersky’s Q2 findings show two concurrent trends: a decline in overall blocked attack counts and the persistence of active, adaptive development by banking malware operators. The spotlight on SDK-based targeting and loader staging raises a pointed question for defenders and app-store reviewers alike: can detection and review processes keep pace with malware that hides behind installation-source telemetry? The answer will shape whether the next wave of builds Kaspersky observed translates into broader impact or remains an exercise in refinement.

Original report