IT threat evolution in Q2 2026. Non-mobile statistics
The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. These statistics are based on detection alerts from Kaspersky products, collected from users who consented to provide statistical data to Kaspersky Security Network.
The quarter in figures
According to Kaspersky Security Network, in Q2 2026:
- More than 1.99 million attacks on mobile devices utilizing malware, adware, or unwanted mobile software were blocked.
- The Trojan-Banker category was the most prevalent mobile malware threat with a 30.77% share of total detected applications.
- More than 304,000 malicious installation packages were discovered, including:
- 93,574 packages were related to mobile banking Trojans;
- 570 packages were related to mobile ransomware Trojans.
Quarterly highlights
Attacks on mobile devices involving malware, adware, or unwanted software continued their downward trend, falling to 1,996,823 in Q2 from 2,676,328 the previous quarter.
Attacks on users of Kaspersky mobile solutions, Q4 2024 — Q2 2026 (download)
We noted a downward trend in attacks driven by specific strains of pre-installed Trojans — a shift likely tied to the rollout of patched vendor firmware.
In Q2, our telemetry uncovered multiple malicious loaders hosted directly on Google Play. As highlighted in a prior report (link in Russian), one such instance involved a PDF reader app trojanized to drop the Anatsa banking malware. Upon execution, the app presented users with a fake request to install an update, which served as a front to stage the banking Trojan on the victim’s device.
Another notable case involves a loader we detected in the Cleanova app alongside several others. The malware sent requests to a command-and-control server containing telemetry gathered from various SDKs that track the installation source. A malicious payload was returned only for certain sources. This is a fairly interesting method for bypassing app store review processes while ensuring precise victim targeting. If an analytics SDK indicates that an arbitrary installation originated from a source outside the threat actors’ scope, the malicious logic remains dormant. This effectively hides the malware from app store scanners.
Mobile threat statistics
In Q2, the number of Android malware samples totaled 304,128. It remained steady compared to the previous reporting period.
Detected malicious and potentially unwanted installation packages, Q2 2025 — Q2 2026 (download)
The detected installation packages were distributed by type as follows:
Detected mobile apps by type, Q1 — Q2 2026* (download)
* Data for the previous quarter may differ slightly from previously published data due to certain verdicts being retrospectively revised.
While the number of newly discovered banking Trojan variants fell precipitously, they continued to dominate the threat landscape as they did in Q1. Notably, the share of Creduz malware family among identified banking samples has grown significantly despite low activity in victim telemetry. This discrepancy suggests the threat actors are actively iterating on the malware — likely testing new features or bypasses — by generating a high volume of builds before staging a broader campaign.
Share* of users attacked by the given type of malicious or potentially unwanted apps out of all targeted users of Kaspersky mobile products, Q1 — Q2 2026 (download)
* The total may exceed 100% if the same users experienced multiple attack types.
Within the adware category, the sharpest declines were observed in the HiddenAd and MobiDash families. Meanwhile, the proportion of users targeted by Trojan-Dropper malware increased, primarily driven by surges in banking droppers such as Trojan-Dropper.AndroidOS.Banker and Trojan-Dropper.AndroidOS.Mamont. The corresponding drop in the Trojan-Banker category is partially explained by a shift in tactics: several banking Trojans which are now being packed were subsequently reclassified as droppers.
TOP 20 most frequently detected types of mobile malware
Note that the malware rankings below exclude riskware or potentially unwanted software, such as RiskTool or adware.
| Verdict | %* Q1 2026 | %* Q2 2026 | Difference in p.p. | Change in ranking |
| Backdoor.AndroidOS.Triada.ag | 7.09 | 9.35 | +2.25 | 0 |
| DangerousObject.Multi.Generic. | 5.84 | 5.65 | -0.19 | 0 |
| DangerousObject.AndroidOS.GenericML. | 5.51 | 5.25 | -0.26 | 0 |
| Trojan.AndroidOS.Boogr.gsh | 2.15 | 3.33 | +1.18 | +9 |
| Backdoor.AndroidOS.Triada.z | 3.08 | 3.23 | +0.15 | +3 |
| Trojan-Banker.AndroidOS.Mamont.hl | 1.10 | 2.48 | +1.38 | +22 |
| Trojan.AndroidOS.Fakemoney.v | 3.44 | 2.31 | -1.13 | -2 |
| Trojan-Spy.AndroidOS.Btmob.e | 0.00 | 2.27 | +2.27 | |
| Trojan.AndroidOS.Triada.fe | 2.98 | 2.18 | -0.81 | 0 |
| Trojan-Dropper.AndroidOS.Banker.dd | 0.01 | 2.16 | +2.15 | |
| Trojan.AndroidOS.Triada.hf | 2.23 | 1.93 | -0.29 | +1 |
| Backdoor.AndroidOS.Triada.ad | 1.40 | 1.93 | +0.53 | +8 |
| Backdoor.AndroidOS.Keenadu.a | 2.73 | 1.88 | -0.85 | -3 |
| Backdoor.AndroidOS.Triada.ab | 1.72 | 1.79 | +0.07 | +2 |
| Trojan-Banker.AndroidOS.Mamont.iv | 1.03 | 1.63 | +0.60 | +16 |
| Trojan.AndroidOS.Generic. | 1.32 | 1.47 | +0.15 | +7 |
| Backdoor.AndroidOS.Triada.ae | 1.76 | 1.44 | -0.31 | -2 |
| Trojan.AndroidOS.Fakemoney.ej | 0.00 | 1.43 | +1.43 | |
| Trojan.AndroidOS.Triada.ii | 2.07 | 1.41 | -0.66 | -5 |
| Trojan-Spy.AndroidOS.Agent.asa | 0.02 | 1.38 | +1.36 |
* Unique users who encountered this malware as a percentage of all attacked users of Kaspersky mobile solutions.
The distribution of top malware families in Q2 largely mirrors the rankings from the previous reporting period. Newer variants of the Mamont banking Trojan climbed the leaderboards, displacing older iterations. This shift points to ongoing, active development of new variants by the threat actors behind the malware.
Mobile banking Trojans
In Q2, the total volume of Trojan-Banker applications dropped sharply compared to the previous quarter, totaling 93,574 installation packages.
Number of installation packages for mobile banking Trojans detected by Kaspersky, Q2 2025 — Q2 2026 (download)
Against the backdrop of this trend, the distribution shifted heavily toward Creduz Trojans. However, as noted earlier, this shift was not reflected in real-world attack metrics: virtually the entire leaderboard by proportion of targeted users continues to be dominated by diverse Mamont variants.
TOP 10 mobile bankers
| Verdict | %* Q1 2026 | %* Q2 2026 | Difference in p.p. | Change in ranking |
| Trojan-Banker.AndroidOS.Mamont.hl | 3.27 | 11.13 | +7.86 | +6 |
| Trojan-Banker.AndroidOS.Mamont.iv | 3.08 | 7.33 | +4.25 | +6 |
| Trojan-Banker.AndroidOS.Mamont.mv | 0.00 | 5.12 | +5.12 | |
| Trojan-Banker.AndroidOS.Agent.ws | 3.78 | 4.99 | +1.22 | +2 |
| Trojan-Banker.AndroidOS.Mamont.mg | 0.35 | 4.71 | +4.36 | +62 |
| Trojan-Banker.AndroidOS.Faketoken.pac | 2.56 | 4.10 | +1.54 | +6 |
| Trojan-Banker.AndroidOS.Mamont.jo | 15.75 | 3.73 | -12.02 | -6 |
| Trojan-Banker.AndroidOS.Mamont.mc | 0.83 | 3.51 | +2.67 | +26 |
| Trojan-Banker.AndroidOS.Mamont.lf | 0.00 | 2.79 | +2.79 | |
| Trojan-Banker.AndroidOS.Agent.eq | 0.89 | 2.58 | +1.69 | +23 |
* Unique users who encountered this malware as a percentage of all users of Kaspersky mobile security solutions who encountered banking threats.
IT threat evolution in Q2 2026. Mobile statistics
