<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec" -->

---
title: Q2 2026 Android threat landscape | daily.dev
description: Kaspersky&#x27;s Q2 2026 Android threat report reveals over 1.99 million blocked mobile attacks, down from 2.68 million the prior quarter. Trojan-Banker was the...
canonical: https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Q2 2026 Android threat landscape | daily.dev
og:description: Kaspersky&#x27;s Q2 2026 Android threat report reveals over 1.99 million blocked mobile attacks, down from 2.68 million the prior quarter. Trojan-Banker was the...
og:url: https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec
og:image: https://api.daily.dev/og/posts/QcztCJoEc.png
og:image:alt: Q2 2026 Android threat landscape
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Q2 2026 Android threat landscape

**[Securelist](https://daily.dev/sources/securelist)** · 6 min read · 0 upvotes · 0 comments

## Summary

Kaspersky's Q2 2026 Android threat report reveals over 1.99 million blocked mobile attacks, down from 2.68 million the prior quarter. Trojan-Banker was the most prevalent threat category at 30.77% of detected apps, with 304,128 total malicious packages found including 93,574 banking Trojans. Key highlights include malicious loaders found on Google Play — notably a trojanized PDF reader dropping the Anatsa banking malware — and the Cleanova app using SDK telemetry to selectively deliver payloads only to targeted users, evading app store review. The Mamont banking Trojan family dominated real-world attack metrics with multiple new variants climbing the rankings. A tactical shift was observed as several banking Trojans are now being packed and reclassified as droppers, inflating the Trojan-Dropper category while deflating Trojan-Banker counts.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securelist.com/malware-report-q2-2026-mobile-statistics/120948>

## Questions this post answers

### How are Android malware authors bypassing Google Play store review processes?

One documented technique involves using SDK telemetry to check the installation source before delivering a malicious payload. The malware sends requests to a C2 server with data from analytics SDKs; a payload is returned only for installations from targeted sources. If the install originated outside the threat actors' scope, the malicious logic stays dormant, hiding the malware from app store scanners.

_Developers shipping Android apps can track evasion techniques like these on daily.dev to stay ahead of supply chain risks._

### What was the most prevalent Android malware category in Q2 2026 according to Kaspersky?

Trojan-Banker was the most prevalent mobile malware category in Q2 2026, accounting for 30.77% of all detected applications. A total of 93,574 banking Trojan installation packages were discovered. The Mamont banking Trojan family dominated real-world attack metrics, with multiple new variants — including Mamont.hl at 11.13% and Mamont.iv at 7.33% — topping the banker leaderboard.

_Security engineers tracking Android banking threats find the latest Kaspersky telemetry and related research on daily.dev._

### How did the Anatsa banking malware spread via Google Play?

Anatsa was distributed through a trojanized PDF reader app hosted on Google Play. When executed, the app presented users with a fake update request, which was used to stage the Anatsa banking Trojan on the victim's device. The loader disguised itself as a legitimate utility to pass app store review before delivering the malicious payload post-install.

_Teams defending against mobile banking trojans can follow dropper and loader research as it breaks on daily.dev._

## Similar posts on daily.dev

- [Android threat report for Q3 2025](https://daily.dev/posts/android-threat-report-for-q3-2025-zgtp46iwr) · Securelist · 0 upvotes · 0 comments
- [The mobile threat landscape in 2025](https://daily.dev/posts/the-mobile-threat-landscape-in-2025-dgwmy2dst) · Securelist · 0 upvotes · 0 comments
- [Kaspersky financial threat report 2025](https://daily.dev/posts/kaspersky-financial-threat-report-2025-svaqauf36) · Securelist · 0 upvotes · 0 comments
- [New Rokarolla Android malware targets 217 banking, crypto apps](https://daily.dev/posts/new-rokarolla-android-malware-targets-217-banking-crypto-apps-w7sotfpil) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#google-play](https://daily.dev/tags/google-play), [#kaspersky](https://daily.dev/tags/kaspersky)

[View this post on daily.dev](https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Q2 2026 Android threat landscape","url":"https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec"},"datePublished":"2026-08-10T10:02:06.177Z","dateModified":"2026-08-10T10:02:46.085Z","description":"Kaspersky's Q2 2026 Android threat report reveals over 1.99 million blocked mobile attacks, down from 2.68 million the prior quarter. Trojan-Banker was the...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2167a0df145feff49ec8d16e5c1d09fe?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2167a0df145feff49ec8d16e5c1d09fe?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Securelist","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Securelist","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/e4b9f556af7a4e74a179787362dd5b07","url":"https://daily.dev/sources/securelist"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,google-play,kaspersky","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Securelist","item":"https://daily.dev/sources/securelist"},{"@type":"ListItem","position":3,"name":"Q2 2026 Android threat landscape"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec#faq","mainEntity":[{"@type":"Question","name":"How are Android malware authors bypassing Google Play store review processes?","acceptedAnswer":{"@type":"Answer","text":"One documented technique involves using SDK telemetry to check the installation source before delivering a malicious payload. The malware sends requests to a C2 server with data from analytics SDKs; a payload is returned only for installations from targeted sources. If the install originated outside the threat actors' scope, the malicious logic stays dormant, hiding the malware from app store scanners. Developers shipping Android apps can track evasion techniques like these on daily.dev to stay ahead of supply chain risks."}},{"@type":"Question","name":"What was the most prevalent Android malware category in Q2 2026 according to Kaspersky?","acceptedAnswer":{"@type":"Answer","text":"Trojan-Banker was the most prevalent mobile malware category in Q2 2026, accounting for 30.77% of all detected applications. A total of 93,574 banking Trojan installation packages were discovered. The Mamont banking Trojan family dominated real-world attack metrics, with multiple new variants — including Mamont.hl at 11.13% and Mamont.iv at 7.33% — topping the banker leaderboard. Security engineers tracking Android banking threats find the latest Kaspersky telemetry and related research on daily.dev."}},{"@type":"Question","name":"How did the Anatsa banking malware spread via Google Play?","acceptedAnswer":{"@type":"Answer","text":"Anatsa was distributed through a trojanized PDF reader app hosted on Google Play. When executed, the app presented users with a fake update request, which was used to stage the Anatsa banking Trojan on the victim's device. The loader disguised itself as a legitimate utility to pass app store review before delivering the malicious payload post-install. Teams defending against mobile banking trojans can follow dropper and loader research as it breaks on daily.dev."}}]}
```

