The latest quarterly report from Kaspersky Security Network reveals a significant decline in mobile malware attacks, with 1.99 million incidents blocked in Q2 2026, down from 2.68 million in the previous quarter. This downward trend is attributed to various factors, including the rollout of patched vendor firmware that has mitigated specific strains of pre-installed Trojans. The report highlights the ongoing dominance of banking Trojans, which accounted for 30.77% of all detected mobile malware applications during this period. For a detailed analysis, you can refer to the full report on Kaspersky’s website.
The Landscape of Mobile Malware
In Q2 2026, Kaspersky identified over 304,000 malicious installation packages, with a notable 93,574 linked to mobile banking Trojans. This category remains a primary concern for mobile users, as these threats continue to evolve. Interestingly, while the number of newly discovered banking Trojan variants has decreased, the existing ones, particularly from the Creduz family, are being actively developed, indicating that threat actors are likely testing new features or methods to bypass security measures.
Despite the overall decline in mobile malware attacks, the report indicates that the Trojan-Banker category remains a significant threat. The telemetry data suggests that the proportion of users targeted by Trojan-Dropper malware has increased, particularly with the emergence of banking droppers like Trojan-Dropper.AndroidOS.Banker. This shift in tactics, where banking Trojans are now being repackaged as droppers, complicates the threat landscape further.
Noteworthy Threats and Attack Techniques
Among the notable threats identified in Q2 2026, Kaspersky’s telemetry uncovered malicious loaders hosted directly on Google Play. One alarming instance involved a trojanized PDF reader app that dropped the Anatsa banking malware. Upon execution, the app prompted users to install a fake update, which was a ruse to deploy the banking Trojan on the device. This method exemplifies the sophisticated techniques employed by cybercriminals to bypass app store security measures.
Another case involved a loader detected in the Cleanova app, which communicated with a command-and-control server to gather telemetry from various SDKs tracking installation sources. This approach allows attackers to deliver malicious payloads selectively, depending on the installation source, effectively evading app store scrutiny. Such tactics highlight the need for continuous vigilance and advanced detection mechanisms in mobile security.
Current Trends in Mobile Banking Trojans
The report indicates a sharp decline in the total volume of Trojan-Banker applications, with 93,574 installation packages detected in Q2 2026. However, the distribution of threats has shifted towards newer variants of the Mamont banking Trojan, which have gained traction among users. The Mamont variants dominate the leaderboard in terms of the proportion of targeted users, despite the emergence of the Creduz family.
As the threat landscape evolves, the top ten mobile bankers identified in the report reflect this shift. The Trojan-Banker.AndroidOS.Mamont.hl variant saw a significant increase in its user encounter rate, rising from 3.27% in Q1 to 11.13% in Q2. This trend underscores the active development and deployment of new malware variants by threat actors, necessitating ongoing monitoring and adaptive security measures.
In conclusion, while the overall number of mobile malware attacks has decreased, the persistence and evolution of banking Trojans present a formidable challenge for users and security professionals alike. The findings from Kaspersky’s Q2 2026 report serve as a crucial reminder of the need for robust mobile security solutions and user awareness to combat these evolving threats.
Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.


