Executive Summary
In Q2 2026, Kaspersky's Security Network reported a significant decline in mobile device attacks, blocking over 1.99 million incidents involving malware, adware, or unwanted software. Notably, the Trojan-Banker category emerged as the predominant mobile malware threat, accounting for 30.77% of detected applications. Additionally, more than 304,000 malicious installation packages were identified, including 93,574 related to mobile banking Trojans and 570 associated with mobile ransomware Trojans. This period also saw the discovery of multiple malicious loaders on Google Play, such as a trojanized PDF reader app deploying the Anatsa banking malware, highlighting the evolving tactics of threat actors in targeting mobile platforms. The continued prevalence of mobile banking Trojans underscores the critical need for enhanced security measures and user vigilance, especially as attackers refine their methods to infiltrate trusted app stores and exploit user trust.
Why This Matters Now
The rise in mobile banking Trojans and the infiltration of malicious apps into trusted platforms like Google Play highlight the urgent need for robust mobile security strategies and user awareness to prevent financial and data breaches.
Attack Path Analysis
The attack began with the distribution of a trojanized PDF reader app on Google Play, leading to the installation of the Anatsa banking malware. Upon execution, the app requested an update, which installed the banking Trojan. The malware then exploited Android's accessibility features to gain elevated privileges, allowing it to perform actions such as intercepting SMS messages and capturing screen content. With elevated privileges, the malware moved laterally within the device, accessing sensitive applications and data. It established a command and control channel using HTTP to communicate with the attacker's server. The malware exfiltrated sensitive data, including banking credentials and personal information, to the attacker's server. The attack resulted in unauthorized financial transactions and potential identity theft for the affected users.
Kill Chain Progression
Initial Compromise
Description
The attacker distributed a trojanized PDF reader app on Google Play, leading to the installation of the Anatsa banking malware.
MITRE ATT&CK® Techniques
Download New Code at Runtime
Obfuscated Files or Information
Capture SMS Messages
Screen Capture
Access Sensitive Data in Device Logs
Input Capture
Exploitation for Privilege Escalation
App Store Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Mobile banking Trojans like Mamont and Creduz directly target banking applications, compromising customer credentials and financial transactions through sophisticated droppers and loaders.
Financial Services
Trojan-Banker malware threatens payment processing systems and customer data, requiring enhanced mobile security controls and zero trust segmentation for financial applications.
Insurance
Mobile banking Trojans pose significant risk to insurance mobile applications handling sensitive financial data, necessitating strengthened encryption and egress security measures.
Information Technology/IT
IT security teams must address mobile threat evolution through enhanced detection capabilities, implementing zero trust frameworks and cloud-native security fabrics against evolving malware.
Sources
- IT threat evolution in Q2 2026. Mobile statisticshttps://securelist.com/malware-report-q2-2026-mobile-statistics/120948/Verified
- Anatsa malware targeting European Android users via apps on Google Play app storehttps://www.notebookcheck.net/Anatsa-malware-targeting-European-Android-users-via-apps-on-Google-Play-app-store.804925.0.htmlVerified
- Malware Alert: Anatsa Banking Trojan Has Recorded Over 150,000 Infections on Google Playhttps://www.techtimes.com/articles/301834/20240220/malware-alert-anatsa-banking-trojan-recorded-over-150-000-infections.htmVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the malware's ability to move laterally within the device and exfiltrate sensitive data, thereby reducing the attack's blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise may not be directly constrained by CNSF, as it primarily focuses on post-compromise activities.
Control: Zero Trust Segmentation
Mitigation: By implementing Zero Trust Segmentation, the malware's ability to exploit elevated privileges could be constrained, limiting its access to sensitive applications and data.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely restrict the malware's lateral movement within the device, reducing its ability to access additional applications and data.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control could detect and potentially disrupt unauthorized command and control communications, limiting the malware's ability to receive instructions.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the malware's ability to exfiltrate sensitive data by enforcing strict outbound traffic policies.
While CNSF controls may not prevent the initial financial impact, they could likely reduce the overall damage by limiting the malware's ability to access and exfiltrate sensitive data.
Impact at a Glance
Affected Business Functions
- Mobile Banking Services
- Customer Account Management
- Financial Transactions Processing
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive banking credentials and personal information of affected users.
Recommended Actions
Key Takeaways & Next Steps
- • Implement application-layer filtering to detect and block malicious apps during download and installation.
- • Enforce strict access controls and least privilege principles to prevent unauthorized privilege escalation.
- • Utilize endpoint detection and response (EDR) solutions to monitor and block lateral movement within devices.
- • Deploy network monitoring tools to detect and block unauthorized command and control communications.
- • Educate users on recognizing and avoiding phishing attempts and suspicious app installations.



