Kaspersky's Q2 2026 Android threat report reveals over 1.99 million blocked mobile attacks, down from 2.68 million the prior quarter. Trojan-Banker was the most prevalent threat category at 30.77% of detected apps, with 304,128 total malicious packages found including 93,574 banking Trojans. Key highlights include malicious loaders found on Google Play — notably a trojanized PDF reader dropping the Anatsa banking malware — and the Cleanova app using SDK telemetry to selectively deliver payloads only to targeted users, evading app store review. The Mamont banking Trojan family dominated real-world attack metrics with multiple new variants climbing the rankings. A tactical shift was observed as several banking Trojans are now being packed and reclassified as droppers, inflating the Trojan-Dropper category while deflating Trojan-Banker counts.

6m read timeFrom securelist.com
Post cover image
Table of contents
The quarter in figuresQuarterly highlightsMobile threat statisticsTOP 20 most frequently detected types of mobile malwareMobile banking Trojans

Questions this post answers

How are Android malware authors bypassing Google Play store review processes?

One documented technique involves using SDK telemetry to check the installation source before delivering a malicious payload. The malware sends requests to a C2 server with data from analytics SDKs; a payload is returned only for installations from targeted sources. If the install originated outside the threat actors' scope, the malicious logic stays dormant, hiding the malware from app store scanners. Developers shipping Android apps can track evasion techniques like these on daily.dev to stay ahead of supply chain risks.

What was the most prevalent Android malware category in Q2 2026 according to Kaspersky?

Trojan-Banker was the most prevalent mobile malware category in Q2 2026, accounting for 30.77% of all detected applications. A total of 93,574 banking Trojan installation packages were discovered. The Mamont banking Trojan family dominated real-world attack metrics, with multiple new variants — including Mamont.hl at 11.13% and Mamont.iv at 7.33% — topping the banker leaderboard. Security engineers tracking Android banking threats find the latest Kaspersky telemetry and related research on daily.dev.

How did the Anatsa banking malware spread via Google Play?

Anatsa was distributed through a trojanized PDF reader app hosted on Google Play. When executed, the app presented users with a fake update request, which was used to stage the Anatsa banking Trojan on the victim's device. The loader disguised itself as a legitimate utility to pass app store review before delivering the malicious payload post-install. Teams defending against mobile banking trojans can follow dropper and loader research as it breaks on daily.dev.

127 Impressions