Android banking trojans are increasingly reaching victims not as apps in their own right, but as payloads fetched by innocuous looking loader apps, several of which made it onto Google Play. That is one of the clearer trends in Kaspersky's mobile threat report for the second quarter of 2026.
A dropper is a small, clean-looking app whose real job is to install something worse once the user has already trusted it. The report, written by Anton Kivva, says Kaspersky's telemetry uncovered multiple malicious loaders hosted directly on Google Play during the quarter. In one case a trojanized PDF reader app presented users with a fake request to install an update, which served as a front to stage the Anatsa banking malware on the victim's device.
Dormant until the right victim arrives
The more interesting case involves a loader Kaspersky detected in an app called Cleanova, alongside several others. The malware sent requests to a command-and-control server carrying telemetry gathered from the analytics SDKs that track where an installation came from, and a malicious payload was returned only for certain sources. If an install originated outside the threat actors' scope, the malicious logic simply remained dormant. Kaspersky calls this a fairly interesting method for bypassing app store review processes while ensuring precise victim targeting, and the logic is hard to argue with: a store scanner is never one of the advertising campaigns the operators are paying for, so it never sees anything happen.
The numbers
- More than 1.99 million attacks on mobile devices utilising malware, adware or unwanted mobile software were blocked in Q2, down from 2,676,328 the previous quarter.
- More than 304,000 malicious installation packages were discovered, including 93,574 related to mobile banking trojans and 570 related to mobile ransomware trojans.
- Trojan-Banker was the most prevalent mobile malware category, with a 30.77% share of total detected applications.
- Backdoor.AndroidOS.Triada.ag was the single most frequently detected verdict at 9.35%, up from 7.09% in Q1.
The overall decline continues a downward trend that Kaspersky ties in part to specific strains of pre-installed trojans falling away, a shift likely linked to the rollout of patched vendor firmware. Some of the movement between categories is bookkeeping rather than behaviour: the drop in the Trojan-Banker category is partly explained by a shift in tactics, with several banking trojans now being packed and subsequently reclassified as droppers. The proportion of users hit by Trojan-Dropper malware rose accordingly, driven by surges in the Banker and Mamont banking dropper families.
One family worth watching is Creduz, whose share of identified banking samples grew significantly despite low activity in victim telemetry. Kaspersky reads that discrepancy as the threat actors actively iterating on the malware, likely testing new features or bypasses by generating a high volume of builds, before staging a broader campaign. In other words, the samples are showing up before the victims do.
What you should do
The advice has not changed much, but the dropper trend sharpens it. Treat any in-app prompt to install an update from outside the store as hostile, because that is precisely the step the Anatsa loader depended on. Keep Google Play Protect switched on, review which apps hold accessibility and install-packages permissions, and on managed fleets restrict sideloading outright. Store presence is not a safety guarantee when the malicious behaviour is deliberately withheld from whoever is reviewing the app.
Android banking malware keeps converging on a small set of proven techniques: fake overlay screens that mimic a bank login, as with the Rokarolla trojan built to loot around 200 apps, and abuse of legitimate platform features, as in the RedHook trojan's use of wireless debugging tools.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.