The Containment Era is here. →Explore

Executive Summary

In Q2 2025, Kaspersky detected a substantial wave of mobile malware impacting Android and iOS, blocking 10.71 million attacks involving Trojans, adware, and unwanted applications. The campaign was notable for a surge in banking Trojans—primarily the Mamont family—pre-installed backdoors like Triada, and novel threats such as SparkKitty, which targets crypto wallet recovery codes via image theft. Attackers leveraged fake app stores, porn-viewing apps that secretly built DDoS botnets, and deceptive VPNs that intercepted OTP codes through notification hijacking. Regionalized attacks exploited localized malware families to increase efficacy and evade global threat visibility, raising risks for financial and privacy exposure worldwide.

This incident highlights a persistent trend of increasingly sophisticated mobile threats focused on financial theft and data exfiltration. The continued evolution of malware TTPs, including use of pre-installed Trojans, modular SDK-based payloads, and cross-platform attack vectors, emphasizes the urgent need for advanced endpoint protection and vigilant detection routines in the mobile security domain.

Why This Matters Now

The rapid evolution of mobile malware families, expansion into pre-installed and socially engineered app vectors, and cross-OS targeting underscore the growing urgency to address mobile security risks. As mobile devices become core to financial, identity, and productivity workflows, failure to secure these endpoints exposes enterprises and users alike to immediate fraud, privacy compromise, and regulatory scrutiny.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The lack of encrypted communications, east-west security controls on mobile devices, and insufficient anomaly detection enabled data theft, credential interception, and botnet formation.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Implementing CNSF controls such as zero trust segmentation, egress policy enforcement, encrypted traffic inspection, and cloud-native threat detection would have limited malware propagation, blocked exfiltration, and enabled rapid detection of mobile threats across hybrid environments.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Rapid detection of suspicious app behavior and unusual installation patterns.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits malware from accessing sensitive workloads or services beyond scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Prevents unauthorized intra-cloud or service-to-service movement.

Command & Control

Control: Cloud Firewall (ACF)

Mitigation: Blocks unauthorized outbound connections and detects suspicious remote control indicators.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Stops data exfiltration attempts and raises alerts on policy-violating traffic.

Impact (Mitigations)

Limits downstream risk and enables rapid containment of malicious activity.

Impact at a Glance

Affected Business Functions

  • Enterprise Collaboration
  • Network Security
  • Wireless Networking
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive enterprise data, including user credentials and confidential communications.

Recommended Actions

  • Enforce zero trust segmentation and identity-based policy to prevent unauthorized app or user privilege escalation.
  • Apply strict egress filtering and DNS/URL controls to block malicious communication and data exfiltration from mobile and cloud workloads.
  • Deploy cloud-native anomaly detection for real-time visibility into suspicious application behaviors across all environments.
  • Implement east-west traffic inspection to prevent lateral movement between workloads and limit the scope of potential compromise.
  • Use centralized, automated policy management to orchestrate rapid detection, response, and containment of mobile malware threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image