---
title: "Q2 2026 Android threat landscape"
url: https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec
source_url: https://securelist.com/malware-report-q2-2026-mobile-statistics/120948
type: article
source: "Securelist"
published: 2026-08-10T10:02:06.177Z
updated: 2026-08-10T10:02:46.085Z
tags: ["security", "google-play", "kaspersky"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Q2 2026 Android threat landscape

**[Securelist](https://daily.dev/sources/securelist)** · 6 min read · 0 upvotes · 0 comments

## Summary

Kaspersky's Q2 2026 Android threat report reveals over 1.99 million blocked mobile attacks, down from 2.68 million the prior quarter. Trojan-Banker was the most prevalent threat category at 30.77% of detected apps, with 304,128 total malicious packages found including 93,574 banking Trojans. Key highlights include malicious loaders found on Google Play — notably a trojanized PDF reader dropping the Anatsa banking malware — and the Cleanova app using SDK telemetry to selectively deliver payloads only to targeted users, evading app store review. The Mamont banking Trojan family dominated real-world attack metrics with multiple new variants climbing the rankings. A tactical shift was observed as several banking Trojans are now being packed and reclassified as droppers, inflating the Trojan-Dropper category while deflating Trojan-Banker counts.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securelist.com/malware-report-q2-2026-mobile-statistics/120948>

## Questions this post answers

### How are Android malware authors bypassing Google Play store review processes?

One documented technique involves using SDK telemetry to check the installation source before delivering a malicious payload. The malware sends requests to a C2 server with data from analytics SDKs; a payload is returned only for installations from targeted sources. If the install originated outside the threat actors' scope, the malicious logic stays dormant, hiding the malware from app store scanners.

_Developers shipping Android apps can track evasion techniques like these on daily.dev to stay ahead of supply chain risks._

### What was the most prevalent Android malware category in Q2 2026 according to Kaspersky?

Trojan-Banker was the most prevalent mobile malware category in Q2 2026, accounting for 30.77% of all detected applications. A total of 93,574 banking Trojan installation packages were discovered. The Mamont banking Trojan family dominated real-world attack metrics, with multiple new variants — including Mamont.hl at 11.13% and Mamont.iv at 7.33% — topping the banker leaderboard.

_Security engineers tracking Android banking threats find the latest Kaspersky telemetry and related research on daily.dev._

### How did the Anatsa banking malware spread via Google Play?

Anatsa was distributed through a trojanized PDF reader app hosted on Google Play. When executed, the app presented users with a fake update request, which was used to stage the Anatsa banking Trojan on the victim's device. The loader disguised itself as a legitimate utility to pass app store review before delivering the malicious payload post-install.

_Teams defending against mobile banking trojans can follow dropper and loader research as it breaks on daily.dev._

## Similar posts on daily.dev

- [Q1 2026 Android threat landscape](https://daily.dev/posts/q1-2026-android-threat-landscape-atez3y1aq) · Securelist · 0 upvotes · 0 comments
- [Mobile cyberthreat report for Q2 2025](https://daily.dev/posts/mobile-cyberthreat-report-for-q2-2025-29ar9ydnl) · Securelist · 1 upvotes · 0 comments
- [Android threat report for Q3 2025](https://daily.dev/posts/android-threat-report-for-q3-2025-zgtp46iwr) · Securelist · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#google-play](https://daily.dev/tags/google-play), [#kaspersky](https://daily.dev/tags/kaspersky)

[View this post on daily.dev](https://daily.dev/posts/q2-2026-android-threat-landscape-qcztcjoec)
