[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWWxuV-kZvoSGlWfAgIZxbb1koeMJLoCEibXqXWb-slw":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"3cc9ff1b-722e-4f6d-a143-597c3fc4b6eb","IT threat evolution in Q2 2026. Mobile statistics","it-threat-evolution-in-q2-2026-mobile-statistics-64f611","This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.","Kaspersky's Q2 2026 report indicates a downward trend in mobile attacks, though banking Trojans remain prevalent. A notable discovery was the Anatsa banking malware distributed via a trojanized PDF reader app on Google Play, employing a sophisticated technique to bypass app store reviews by only delivering the payload to specific installation sources.","Kaspersky reports Q2 2026 mobile threat evolution, noting Anatsa banker and dropper transitions.","Table of Contents The quarter in figuresQuarterly highlightsMobile threat statisticsTOP 20 most frequently detected types of mobile malwareMobile banking TrojansTOP 10 mobile bankers Authors Anton Kivva IT threat evolution in Q2 2026. Mobile statistics IT threat evolution in Q2 2026. Non-mobile statistics The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. These statistics are based on detection alerts from Kaspersky products, collected from users who consented to provide statistical data to Kaspersky Security Network. The quarter in figures According to Kaspersky Security Network, in Q2 2026: More than 1.99 million attacks on mobile devices utilizing malware, adware, or unwanted mobile software were blocked. The Trojan-Banker category was the most prevalent mobile malware threat with a 30.77% share of total detected applications. More than 304,000 malicious installation packages were discovered, including: 93,574 packages were related to mobile banking Trojans; 570 packages were related to mobile ransomware Trojans. Quarterly highlights Attacks on mobile devices involving malware, adware, or unwanted software continued their downward trend, falling to 1,996,823 in Q2 from 2,676,328 the previous quarter. Attacks on users of Kaspersky mobile solutions, Q4 2024 — Q2 2026 (download) We noted a downward trend in attacks driven by specific strains of pre-installed Trojans — a shift likely tied to the rollout of patched vendor firmware. In Q2, our telemetry uncovered multiple malicious loaders hosted directly on Google Play. As highlighted in a prior report (link in Russian), one such instance involved a PDF reader app trojanized to drop the Anatsa banking malware. Upon execution, the app presented users with a fake request to install an update, which served as a front to stage the banking Trojan on the victim’s device. Another notable case involves a loader we detected in the Cleanova app alongside several others. The malware sent requests to a command-and-control server containing telemetry gathered from various SDKs that track the installation source. A malicious payload was returned only for certain sources. This is a fairly interesting method for bypassing app store review processes while ensuring precise victim targeting. If an analytics SDK indicates that an arbitrary installation originated from a source outside the threat actors’ scope, the malicious logic remains dormant. This effectively hides the malware from app store scanners. Mobile threat statistics In Q2, the number of Android malware samples totaled 304,128. It remained steady compared to the previous reporting period. Detected malicious and potentially unwanted installation packages, Q2 2025 — Q2 2026 (download) The detected installation packages were distributed by type as follows: Detected mobile apps by type, Q1 — Q2 2026* (download) * Data for the previous quarter may differ slightly from previously published data due to certain verdicts being retrospectively revised. While the number of newly discovered banking Trojan variants fell precipitously, they continued to dominate the threat landscape as they did in Q1. Notably, the share of Creduz malware family among identified banking samples has grown significantly despite low activity in victim telemetry. This discrepancy suggests the threat actors are actively iterating on the malware — likely testing new features or bypasses — by generating a high volume of builds before staging a broader campaign. Share* of users attacked by the given type of malicious or potentially unwanted apps out of all targeted users of Kaspersky mobile products, Q1 — Q2 2026 (download) * The total may exceed 100% if the same users experienced multiple attack types. Within the adware category, the sharpest declines were observed in the HiddenAd and MobiDash families. Meanwhile, the proportion of users targeted by Trojan-Dropper malware increased, primarily driven by surges in banking droppers such as Trojan-Dropper.AndroidOS.Banker and Trojan-Dropper.AndroidOS.Mamont. The corresponding drop in the Trojan-Banker category is partially explained by a shift in tactics: several banking Trojans which are now being packed were subsequently reclassified as droppers. TOP 20 most frequently detected types of mobile malware Note that the malware rankings below exclude riskware or potentially unwanted software, such as RiskTool or adware. Verdict %* Q1 2026 %* Q2 2026 Difference in p.p. Change in ranking Backdoor.AndroidOS.Triada.ag 7.09 9.35 +2.25 0 DangerousObject.Multi.Generic. 5.84 5.65 -0.19 0 DangerousObject.AndroidOS.GenericML. 5.51 5.25 -0.26 0 Trojan.AndroidOS.Boogr.gsh 2.15 3.33 +1.18 +9 Backdoor.AndroidOS.Triada.z 3.08 3.23 +0.15 +3 Trojan-Banker.AndroidOS.Mamont.hl 1.10 2.48 +1.38 +22 Trojan.AndroidOS.Fakemoney.v 3.44 2.31 -1.13 -2 Trojan-Spy.AndroidOS.Btmob.e 0.00 2.27 +2.27 Trojan.AndroidOS.Triada.fe 2.98 2.18 -0.81 0 Trojan-Dropper.AndroidOS.Banker.dd 0.01 2.16 +2.15 Trojan.AndroidOS.Triada.hf 2.23 1.93 -0.29 +1 Backdoor.AndroidOS.Triada.ad 1.40 1.93 +0.53 +8 Backdoor.AndroidOS.Keenadu.a 2.73 1.88 -0.85 -3 Backdoor.AndroidOS.Triada.ab 1.72 1.79 +0.07 +2 Trojan-Banker.AndroidOS.Mamont.iv 1.03 1.63 +0.60 +16 Trojan.AndroidOS.Generic. 1.32 1.47 +0.15 +7 Backdoor.AndroidOS.Triada.ae 1.76 1.44 -0.31 -2 Trojan.AndroidOS.Fakemoney.ej 0.00 1.43 +1.43 Trojan.AndroidOS.Triada.ii 2.07 1.41 -0.66 -5 Trojan-Spy.AndroidOS.Agent.asa 0.02 1.38 +1.36 * Unique users who encountered this malware as a percentage of all attacked users of Kaspersky mobile solutions. The distribution of top malware families in Q2 largely mirrors the rankings from the previous reporting period. Newer variants of the Mamont banking Trojan climbed the leaderboards, displacing older iterations. This shift points to ongoing, active development of new variants by the threat actors behind the malware. Mobile banking Trojans In Q2, the total volume of Trojan-Banker applications dropped sharply compared to the previous quarter, totaling 93,574 installation packages. Number of installation packages for mobile banking Trojans detected by Kaspersky, Q2 2025 — Q2 2026 (download) Against the backdrop of this trend, the distribution shifted heavily toward Creduz Trojans. However, as noted earlier, this shift was not reflected in real-world attack metrics: virtually the entire leaderboard by proportion of targeted users continues to be dominated by diverse Mamont variants. TOP 10 mobile bankers Verdict %* Q1 2026 %* Q2 2026 Difference in p.p. Change in ranking Trojan-Banker.AndroidOS.Mamont.hl 3.27 11.13 +7.86 +6 Trojan-Banker.AndroidOS.Mamont.iv 3.08 7.33 +4.25 +6 Trojan-Banker.AndroidOS.Mamont.mv 0.00 5.12 +5.12 Trojan-Banker.AndroidOS.Agent.ws 3.78 4.99 +1.22 +2 Trojan-Banker.AndroidOS.Mamont.mg 0.35 4.71 +4.36 +62 Trojan-Banker.AndroidOS.Faketoken.pac 2.56 4.10 +1.54 +6 Trojan-Banker.AndroidOS.Mamont.jo 15.75 3.73 -12.02 -6 Trojan-Banker.AndroidOS.Mamont.mc 0.83 3.51 +2.67 +26 Trojan-Banker.AndroidOS.Mamont.lf 0.00 2.79 +2.79 Trojan-Banker.AndroidOS.Agent.eq 0.89 2.58 +1.69 +23 * Unique users who encountered this malware as a percentage of all users of Kaspersky mobile security solutions who encountered banking threats. Google Android Adware Mobile Malware Malware Statistics Trojan Banker Trojan Trojan Clicker Trojan-Dropper Google Play Mamont Triada Keenadu IT threat evolution in Q2 2026. Mobile statistics This site uses Akismet to reduce spam. Learn how your comment data is processed. Table of Contents The quarter in figuresQuarterly highlightsMobile threat statisticsTOP 20 most frequently detected types of mobile malwareMobile banking TrojansTOP 10 mobile bankers GReAT webinars In the same category","https:\u002F\u002Fsecurelist.com\u002Fmalware-report-q2-2026-mobile-statistics\u002F120948\u002F","https:\u002F\u002Fmedia.kasperskycontenthub.com\u002Fwp-content\u002Fuploads\u002Fsites\u002F43\u002F2026\u002F08\u002F10093530\u002Fmalware-report-q2-2026-featured-image-scaled-1.jpg","2026-08-10T10:00:09+00:00","2026-08-10T12:00:15.242057+00:00",7,[18,21,24,26,28],{"name":19,"type":20},"Kaspersky","vendor",{"name":22,"type":23},"Kaspersky Security Network","product",{"name":25,"type":23},"Android",{"name":27,"type":23},"iOS",{"name":29,"type":23},"Google Play","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":30,"icon":32,"name":33,"slug":34},null,"Malware","malware",[36,38],{"category":37},{"id":30,"icon":32,"name":33,"slug":34},{"category":39},{"id":40,"icon":32,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[44],{"type":34,"value":45,"context":46},"Anatsa","Banking malware family"]