Mobile Malware Declines in Q2 2026, But Banking Trojans and Google Play Threats Persist
Kaspersky's Q2 2026 report indicates a significant drop in mobile attack volumes, yet highlights ongoing threats from sophisticated banking Trojans and malicious applications infiltrating Google Play.

Kaspersky's latest analysis of the IT threat landscape in the second quarter of 2026 reveals a notable decrease in mobile-specific attacks, with blocked threats falling to just under 2 million. This represents a substantial reduction from the previous quarter's figures, suggesting a potential shift in threat actor focus or increased effectiveness of defensive measures against widespread mobile malware.
Despite the overall decline, the report emphasizes that Trojan-Banker malware remains the most prevalent threat category, accounting for over 30% of all detected malicious mobile applications. This persistent dominance underscores the continued lucrative nature of financial data theft for cybercriminals, who are constantly evolving their tactics to compromise banking credentials and financial accounts.
A significant concern highlighted in the Q2 findings is the continued presence of malicious loaders directly hosted on Google Play. One such instance involved a seemingly innocuous PDF reader app that, upon execution, prompted users to install a fake update. This update served as a delivery mechanism for the Anatsa banking Trojan, silently infecting the victim's device.
Another sophisticated threat observed on Google Play utilized SDK telemetry to evade detection. This loader, found within the Cleanova app, sent collected data to a command-and-control server. Crucially, it only delivered its malicious payload if the installation source, identified through SDK telemetry, matched the threat actors' predefined targets. This method allows malware to remain dormant and undetected during app store reviews, ensuring it is only deployed against carefully selected victims.
The total number of detected Android malware samples remained relatively stable, hovering around 304,000. While the overall volume of newly discovered banking Trojan variants saw a sharp decrease, their impact was amplified by the significant growth of the Creduz malware family. This suggests that threat actors are actively developing and iterating on existing banking malware, likely preparing for future, larger-scale campaigns.
The report also noted a decline in adware families like HiddenAd and MobiDash. However, this was offset by an increase in users targeted by Trojan-Dropper malware, particularly those designed to deliver banking Trojans such as Trojan-Dropper.AndroidOS.Banker and Trojan-Dropper.AndroidOS.Mamont. This shift indicates a tactical evolution where banking Trojans are increasingly being delivered via dropper mechanisms, sometimes reclassified from their original Trojan-Banker designation.
While the overall trend shows a reduction in mobile threats, the persistence of banking Trojans and the innovative evasion techniques employed by malware found on official app stores like Google Play indicate that mobile security remains a critical concern. The ongoing development and adaptation by threat actors necessitate continuous vigilance and robust security solutions to protect users from financial fraud and data theft.