Android banking malware operators are undergoing a tactical transformation in their approach to delivering malicious software, increasingly leaning towards dropper-based packaging to circumvent mobile app-store security measures. This shift represents a significant evolution in how threats are classified and the methods employed in their distribution, rather than merely expanding their overall reach.
According to Kaspersky, a cybersecurity firm, telemetry data for the second quarter of 2026 revealed that there were 1,996,823 blocked attacks related to malware, adware, and other potentially unwanted mobile programs. This figure represents a decrease from the 2,676,328 incidents documented in the first quarter of the same year. However, this apparent decline in attacks belies a more profound strategic shift within cybercriminal circles.
Kaspersky’s findings indicate that banking payloads are now being concealed within loader applications, which are then categorized as Trojan-Droppers rather than the more conventional Trojan-Banker classification. This alteration has led to a notable change in the rankings of threat categories. Despite Trojan-Bankers still being the predominant form of mobile malware—making up 30.77% of detected applications—there has been a shocking rise in Trojan-Dropper incidents, highlighting a changing landscape in mobile threats.
Although there was a drop in new banking-Trojan packages introduced compared to the first quarter, financial malware continues to dominate the scene. Operators are adapting their delivery methodologies, experimenting with new software builds, and rapidly cycling through different variants to maintain their effectiveness against cybersecurity measures.
One of the more common techniques now exploited by malware authors involves separating the malicious payload from its initial benign application form. This strategy allows a trojanized utility to pass through the preliminary app review with minimal or dormant malicious capabilities, thus enabling the activation or retrieval of a banking Trojan only after the initial installation. An illustrative case involved a PDF reader available on Google Play, which duped users into accepting a fake update prompt that subsequently installed the Anatsa banking malware. This method effectively transforms a routine software update from a seemingly innocuous operation into a delivery mechanism for harmful payloads, minimizing the visibility of the actual banking components during the vetting process.
As highlighted in a report circulated by Kaspersky, a staggering 304,128 Android malware samples were identified in the second quarter, including 93,574 mobile banking Trojan packages and 570 mobile ransomware packs. Another notable loader was detected within the Cleanova application, utilizing a more meticulous approach to its malware deployment strategy. This particular malware collected data through installation-source analytics SDKs and sent it back to a command-and-control server. The server would only dispatch a malicious payload if it determined that the app was installed from a source specified by the operators, hinting at a targeted and strategic deployment mechanism.
This source-aware filtering system, while sophisticated, offers an efficient way for cybercriminals to circumvent app-store scrutiny while maintaining targeted campaign efficacy. The disparity in detection rankings underscores this shift, as Trojan-Dropper.AndroidOS.Banker.dd surged from a mere 0.01% of attacked Kaspersky mobile users in the first quarter to an alarming 2.16% in the second quarter. Meanwhile, Malay variants, particularly the Mamont family, gained notoriety, with Trojan-Banker.AndroidOS.Mamont.hl accounting for 2.48% of attacked users in overall malware rankings. The emergence of new Mamont builds replacing older variants also illustrates continuous development within this malware family.
Creduz has similarly emerged as a notable player amongst newly identified banking samples, despite generating relatively low victim telemetry. This contradiction suggests that operators may be excessively creating new builds to trial different features, delivery methods, or evasion tactics ahead of broader distribution. Kaspersky’s prior reports have also pointed to Mamont and Creduz as leading Android banking malware families, reinforcing their persistent and evolving role in the cyber threat ecosystem.
For defenders and consumers alike, the key takeaway is that a decline in direct banker detections should not be misconstrued as a reduced financial malware risk. The dropper model conceals malicious intent until late in the execution process and enables quick replacement of payloads without needing to reconstruct the initial lure. Android users are therefore advised to approach unexpected in-app update prompts, especially from document readers and utilities, with heightened caution. Enabling Play Protect, avoiding sideloading applications, and carefully scrutinizing permissions, particularly those related to Accessibility and SMS access, are prudent steps.
Furthermore, security teams should adopt a more holistic approach, correlating app provenance, installation referrer data, outbound command-and-control traffic, and the timing of payload retrieval, rather than solely relying on static APK classifications. As the landscape of mobile threats continues to evolve, such proactive measures will be crucial in fortifying defenses against increasingly sophisticated cyber threats.
