Executive Summary
In Q2 2025, Kaspersky detected a substantial wave of mobile malware impacting Android and iOS, blocking 10.71 million attacks involving Trojans, adware, and unwanted applications. The campaign was notable for a surge in banking Trojans—primarily the Mamont family—pre-installed backdoors like Triada, and novel threats such as SparkKitty, which targets crypto wallet recovery codes via image theft. Attackers leveraged fake app stores, porn-viewing apps that secretly built DDoS botnets, and deceptive VPNs that intercepted OTP codes through notification hijacking. Regionalized attacks exploited localized malware families to increase efficacy and evade global threat visibility, raising risks for financial and privacy exposure worldwide.
This incident highlights a persistent trend of increasingly sophisticated mobile threats focused on financial theft and data exfiltration. The continued evolution of malware TTPs, including use of pre-installed Trojans, modular SDK-based payloads, and cross-platform attack vectors, emphasizes the urgent need for advanced endpoint protection and vigilant detection routines in the mobile security domain.
Why This Matters Now
The rapid evolution of mobile malware families, expansion into pre-installed and socially engineered app vectors, and cross-OS targeting underscore the growing urgency to address mobile security risks. As mobile devices become core to financial, identity, and productivity workflows, failure to secure these endpoints exposes enterprises and users alike to immediate fraud, privacy compromise, and regulatory scrutiny.
Attack Path Analysis
Attackers initially compromised mobile devices by distributing malicious apps via fake app stores and pre-installed trojans. Once installed, malware exploited permissions or vulnerabilities to escalate privileges, enabling access to sensitive data or other apps. The malware then attempted lateral movement by leveraging device or app-to-app interactions, or targeting other devices in the network. Command and control was established through covert channels such as encrypted communications with attacker infrastructure, often using Telegram bots or similar services. Data exfiltration occurred as screenshot images, OTP codes, or banking credentials were covertly transmitted to attacker-controlled servers. Impact included financial theft, user account compromise, and large-scale abuse such as DDoS attacks leveraging the infected device fleet.
Kill Chain Progression
Initial Compromise
Description
Users were tricked into installing malicious apps from fake app stores or encountered pre-installed trojans on new devices, granting the attacker an initial foothold.
Related CVEs
CVE-2025-24893
CVSS 9.8An eval injection vulnerability in XWiki Platform allows unauthenticated remote code execution via a malformed HTTP request.
Affected Products:
XWiki XWiki Platform – < 13.10.11, < 14.4.7, < 14.10.3
Exploit Status:
exploited in the wildCVE-2025-40600
CVSS 9.8A format string vulnerability in SonicOS SSL VPN interface allows remote code execution.
Affected Products:
SonicWall SonicOS – < 7.0.1-5050
Exploit Status:
exploited in the wildCVE-2025-20188
CVSS 10A vulnerability in Cisco IOS XE Software's Out-of-Band AP Image Download feature allows unauthenticated remote code execution.
Affected Products:
Cisco IOS XE Software – < 17.3.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Delivery via Authorized App Store or Pre-Installed Applications
Obfuscated Files or Information
Access Stored Application Data
Capture SMS Messages
Input Capture
Data from Local System
Exfiltration Over Command and Control Channel
Network Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response to Security Alerts
Control ID: 12.10.5
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Device Visibility and Health Checking
Control ID: Device Pillar – Asset Inventory and Health Metrics
NIS2 Directive – Incident Detection and Response Capabilities
Control ID: Article 21.2(e)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Mobile banking Trojans like Mamont family directly target financial institutions, with 42,220 malicious packages detected, compromising customer account security and regulatory compliance.
Financial Services
Cryptocurrency wallet targeting by SparkKitty malware and OTP interception attacks threaten digital asset security and customer authentication systems across financial platforms.
Telecommunications
Fake VPN clients intercepting OTP codes and mobile DDoS botnets compromise network infrastructure integrity and customer communication security in telecom services.
Entertainment/Movie Production
DDoS botnet embedded in adult content apps creates infrastructure vulnerabilities, while mobile malware threatens content distribution platforms and customer data protection.
Sources
- IT threat evolution in Q2 2025. Mobile statisticshttps://securelist.com/malware-report-q2-2025-mobile-statistics/117349/Verified
- Critical XWiki Platform Vulnerability: The CVE-2025-24893 Eval Injection Crisis Shaking Enterprise Collaboration Systemshttps://www.siteguarding.com/security-blog/critical-xwiki-platform-vulnerability-the-cve-2025-24893-eval-injection-crisis-shaking-enterprise-collaboration-systems/Verified
- Weekly Vulnerabilities Summary 27 Jul to 02 Aughttps://cdn.nca.gov.sa/api/files/public/upload/8d480d91-bddb-45b9-8f85-877c75b56d70_Weekly_Vulnerabilities_Summary_27_Jul_to_02_Aug---Copy.pdfVerified
- Weekly Vulnerabilities Summary 04 May to 10 Mayhttps://cdn.nca.gov.sa/api/files/public/upload/c0cb524b-2dcc-4613-8031-bf5c86a2049d_Weekly_Vulnerabilities_Summary_04_May_to_10_May---Copy.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing CNSF controls such as zero trust segmentation, egress policy enforcement, encrypted traffic inspection, and cloud-native threat detection would have limited malware propagation, blocked exfiltration, and enabled rapid detection of mobile threats across hybrid environments.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid detection of suspicious app behavior and unusual installation patterns.
Control: Zero Trust Segmentation
Mitigation: Limits malware from accessing sensitive workloads or services beyond scope.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized intra-cloud or service-to-service movement.
Control: Cloud Firewall (ACF)
Mitigation: Blocks unauthorized outbound connections and detects suspicious remote control indicators.
Control: Egress Security & Policy Enforcement
Mitigation: Stops data exfiltration attempts and raises alerts on policy-violating traffic.
Limits downstream risk and enables rapid containment of malicious activity.
Impact at a Glance
Affected Business Functions
- Enterprise Collaboration
- Network Security
- Wireless Networking
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive enterprise data, including user credentials and confidential communications.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and identity-based policy to prevent unauthorized app or user privilege escalation.
- • Apply strict egress filtering and DNS/URL controls to block malicious communication and data exfiltration from mobile and cloud workloads.
- • Deploy cloud-native anomaly detection for real-time visibility into suspicious application behaviors across all environments.
- • Implement east-west traffic inspection to prevent lateral movement between workloads and limit the scope of potential compromise.
- • Use centralized, automated policy management to orchestrate rapid detection, response, and containment of mobile malware threats.



