<?xml version="1.0"?>
<rss version="2.0"><channel><title>Virus reviews</title><link>https://news.drweb.com/news/</link><description>Doctor Web news - Virus reviews</description><image><url>https://st.drweb.com/static/drweb_logo_en.gif</url><link>https://news.drweb.com/news/</link><title>Dr.Web anti-virus</title></image><item><guid>https://news.drweb.com/show/?i=15274&amp;lng=en</guid><title>Doctor Web’s Q2 2026 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=15274&amp;lng=en&amp;c=10</link><pubDate>Wed, 01 Jul 2026 04:00:00 GMT</pubDate><description>&lt;p&gt;July 1, 2026&lt;/p&gt;

&lt;p&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans were less active in the second quarter (Q2) of 2026—by 31.83%, compared to the first quarter (Q1). At the same time, they remained the most widespread Android malware: this family accounted for 23.28% of all malware detections. These trojans steal various confidential data, such as SMS containing one-time codes from credit organizations and logins and passwords for accessing online bank accounts, and they can also display phishing windows. As in the previous quarter, users were more likely to encounter the Android.Banker.Mamont subfamily, which includes various malicious apps.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;Over the last three months, the ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; continued to be less active. However, they remain some of the most common malicious Android programs, and some of their modifications are still among the leaders in terms of the number of malware detections.&lt;/p&gt;

&lt;p&gt;With a share of over 66%, the most widespread potentially dangerous software was again programs to which junk code had been added to obfuscate their logic; these are detected as &lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt;. Such modification is performed using the hacker modding tool NP Manager. Threat actors also use these tools to protect malicious apps like the &lt;b&gt;Android.Banker.Mamont&lt;/b&gt; banking trojans from being detected by anti-viruses.&lt;/p&gt;

&lt;p&gt;In second place again were apps that had also been modified with the help of the NP Manager tool but by using its other functionality. For instance, this tool provides various modules for protecting and obfuscating the apps’ code as well as for bypassing digital signature verification once apps are modified. Malware creators use this functionality to protect malicious software from anti-viruses. Dr.Web anti-virus products detect programs modified in this way as &lt;a href="https://vms.drweb.com/search/?q=Tool.NPMod&amp;lng=en"&gt;&lt;b&gt;Tool.NPMod&lt;/b&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Programs modified using the &lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt; utility were again among the most frequently detected potentially dangerous apps. To make modifications, this tool downloads specially crafted scripts from the Internet.&lt;/p&gt;

&lt;p&gt;The most active unwanted programs in Q2 were &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt; apps, which behave like anti-virus software. They supposedly detect various threats and then ask users to buy the full version of the software to “cure” the infection. Such programs accounted for over 44% of all unwanted apps detected on Android devices.&lt;/p&gt;

&lt;p&gt;The most widespread adware programs were &lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt; modules, which can be built into Android apps. They display notifications containing misleading ads. These modules also collect various personal data. In addition, users encountered &lt;a href="https://vms.drweb.com/search/?q=Adware.Bastion&amp;lng=en"&gt;&lt;b&gt;Adware.Bastion&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;. These are optimization apps that periodically create notifications with misleading messages about alleged system errors and low memory. The programs display ads during “optimization”. Once again &lt;b&gt;Adware.Opensite.15&lt;/b&gt; programs were highly active. Fraudsters promote them as apps offering cheats that can supposedly help users obtain various game resources. However, these apps only load websites with advertisements.&lt;/p&gt;

&lt;p&gt;At the beginning of June, Doctor Web’s experts informed users about &lt;a href="https://vms.drweb.com/search/?q=Android.MagicAd.1&amp;lng=en"&gt;&lt;b&gt;Android.MagicAd.1&lt;/b&gt;&lt;/a&gt;, which can bypass Android OS security limitations and display background ads. To do this, &lt;a href="https://vms.drweb.com/search/?q=Android.MagicAd.1&amp;lng=en"&gt;&lt;b&gt;Android.MagicAd.1&lt;/b&gt;&lt;/a&gt; exploits third-party programs and also uses specific techniques, which it selects, based on the infected device’s manufacturer. Details about this trojan can be found in the corresponding &lt;a href="https://news.drweb.com/show/?i=15262&amp;lng=en" target="_blank"&gt;news release&lt;/a&gt; on our website.&lt;/p&gt;

&lt;p&gt;Over the course of Q2, Doctor Web’s malware analysts discovered more malicious programs on Google Play that subscribe victims to paid services. Among them were members of the &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojan families.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;PRINCIPAL TRENDS OF Q2 2026&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans remain the most common malicious Android programs.&lt;/li&gt;
        &lt;li&gt;Malware creators continued actively using Android software modding tools to protect banking trojans from being detected by anti-viruses.&lt;/li&gt;
        &lt;li&gt;The activity of the ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; decreased again.&lt;/li&gt;
        &lt;li&gt;The &lt;a href="https://vms.drweb.com/search/?q=Android.MagicAd.1&amp;lng=en"&gt;&lt;b&gt;Android.MagicAd.1&lt;/b&gt;&lt;/a&gt; trojan was discovered; it uses third-party programs to bypass Android OS restrictions for displaying background ads.&lt;/li&gt;
        &lt;li&gt;New malicious programs emerged on Google Play.&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h3&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/01_malware_q2_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/01_malware_q2_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1812&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious &lt;i&gt;WhatsApp&lt;/i&gt; messenger mods that can covertly load various websites in the background.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.675.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4236&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Trojan apps designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Android.Banker.Mamont.80.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A banking trojan that intercepts SMS containing one-time codes from credit organizations, hijacks the contents of notifications, and collects other confidential information. This includes technical data about the infected device, the list of installed apps, and information about the SIM card, phone calls, and sent and received SMS.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan app that loads the website hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/02_unwanted_q2_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/02_unwanted_q2_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/03_riskware_q2_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/03_riskware_q2_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs to which junk code has been added, using hacker tools for modifying Android apps. Such modification is performed to scramble the apps’ logic. This technique is often found in banking trojans and pirated software.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.3&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. This tool contains modules for obfuscating and protecting the apps’ code as well as for bypassing their digital signature verification after they have been modified. The obfuscation it adds is often used to make the malware more difficult to detect and analyze.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads from the Internet specially prepared scripts, which can be crafted and added to a common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/04_adware_q2_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/04_adware_q2_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Bastion&amp;lng=en"&gt;&lt;b&gt;Adware.Bastion&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for optimization programs that periodically create notifications containing misleading messages. They inform users about alleged low memory and system errors in order to display ads during “optimization”.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Opensite.15&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Apps passed off as cheat tools for obtaining resources in games. In fact, they are created to display ads. These programs receive a configuration from a remote server and use it to open a target website containing ads like banners, pop-up windows, video clips, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An adware module that can be built into Android apps. It displays notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, this module collects a variety of confidential data and is able to download other apps and initiate their installation.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An adware module that malicious actors embed into cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display unwanted ads.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Airpush&amp;lng=en"&gt;&lt;b&gt;Adware.Airpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware modules that can be built into Android apps and display various ads. Depending on the modules’ version and modification, these can be notifications containing ads, pop-up windows or banners. Malicious actors often use these modules to distribute malware by offering their potential victims diverse software for installation. Moreover, such modules collect personal information and send it to a remote server.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Threats on Google Play&lt;/h3&gt;

&lt;p&gt;During Q2 2026, Doctor Web’s virus analysts discovered several new trojan apps from the &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt; family, which subscribe users to premium services. They were distributed under the guise of various programs: the &lt;i&gt;ShowLounge - TV &amp; Dramas&lt;/i&gt; online cinema (&lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.25&lt;/b&gt;), the &lt;i&gt;AIM: Crosshair Asist&lt;/i&gt; app for gamers (&lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.26&lt;/b&gt;), the &lt;i&gt;True Cargo Drive&lt;/i&gt; game (&lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.27&lt;/b&gt;), the &lt;i&gt;Battery 3D: Charge Effects&lt;/i&gt; tool (&lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.28&lt;/b&gt;), and the &lt;i&gt;PixStudio - Photo Editor&lt;/i&gt; picture-editing software (&lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.29&lt;/b&gt;). In total, these were downloaded at least 2.6 million times.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/05_Android.Subscription.26_GP.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/05_Android.Subscription.26_GP.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/06_Android.Subscription.29_GP.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/06_Android.Subscription.29_GP.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Examples of &lt;b&gt;Android.Subscription&lt;/b&gt; trojan apps detected on Google Play in Q2 2026&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Malicious programs of this type load websites that subscribe users to paid mobile services via the Wap Click technology. Potential victims are asked for their mobile phone number, and, once they provide it, an attempt is made to activate the corresponding services.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojan apps, which also subscribe victims to paid services, were again distributed via Google Play. Malicious actors passed them off as the messengers &lt;i&gt;Chat Messages&lt;/i&gt; (&lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2625&lt;/b&gt;) and &lt;i&gt;Easy Messages&lt;/i&gt; (&lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2632&lt;/b&gt;), and also as the system optimization tools &lt;i&gt;Smart File Cleaner&lt;/i&gt;, &lt;i&gt;Junk Clean Master&lt;/i&gt;, and &lt;i&gt;Fast Cleaner&lt;/i&gt; (&lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2614&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2618&lt;/b&gt;, and &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2626&lt;/b&gt;, respectively).&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/07_Android.Joker.2632_1_Easy_Messages.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_mobile_q2/07_Android.Joker.2632_1_Easy_Messages.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;One of the malicious programs in which &lt;b&gt;Android.Joker&lt;/b&gt; trojans were concealed&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q2%202026%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank"&gt;Indicators of compromise&lt;/a&gt;&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15275&amp;lng=en</guid><title>Doctor Web’s Q2 2026 virus activity review</title><link>https://news.drweb.com/show/?i=15275&amp;lng=en&amp;c=10</link><pubDate>Wed, 01 Jul 2026 03:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;July 1, 2026&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;newslead&gt;According to statistics collected by the Dr.Web anti-virus, the total number of threats detected in the second quarter (Q2) of 2026 was up by 5.72% from Q1. The number of unique threats increased by 95.32%. Ad-displaying programs and trojans, malicious crypto-miners, and trojans used to run other malware were most frequently discovered on protected devices.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;In email traffic, malicious scripts and different types of trojans, such as downloaders, droppers, password stealers, and miners, were most regularly detected. Also commonly encountered were backdoors, phishing documents, and various exploits.&lt;/p&gt;

&lt;p&gt;Users whose files were affected by encoder trojans had primarily encountered &lt;b&gt;Trojan.Encoder.35534&lt;/b&gt;, &lt;b&gt;Trojan.Encoder.41868&lt;/b&gt;, and &lt;b&gt;Trojan.Encoder.37400&lt;/b&gt;. At the same time, Doctor Web’s Technical Support Service registered slightly fewer user requests for decryption, compared to the previous quarter.&lt;/p&gt;

&lt;p&gt;In Q2 2026, Doctor Web’s Internet analysts observed an increase in the number of phishing attacks targeting MAX messenger users. Fraudsters also exploited the current news agenda and adapted popular scam schemes accordingly.&lt;/p&gt;

&lt;p&gt;In May, we &lt;a href="https://news.drweb.com/show/?i=15253&amp;lng=en" target="_blank"&gt;warned&lt;/a&gt; about the spread of JobStealer, a malicious program targeting macOS and Windows users. Under the pretext of conducting online job interviews, cybercriminals passed it off as video-conferencing software. The JobStealer trojan pilfers various confidential information, including data from almost 300 browser crypto wallet extensions, Telegram messenger files, passwords and bank card data saved in browsers, and cookie files.&lt;/p&gt;

&lt;p&gt;In June, Doctor Web’s anti-virus laboratory experts &lt;a href="https://news.drweb.com/show/?i=15262&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about &lt;a href="https://vms.drweb.com/search/?q=Android.MagicAd.1&amp;lng=en"&gt;&lt;b&gt;Android.MagicAd.1&lt;/b&gt;&lt;/a&gt;, a new advertising trojan capable of displaying background ads thanks to its ability to bypass Android OS restrictions. To do this, the trojan exploits third-party apps. The technique it uses depends on the target device’s manufacturer.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans were among the malicious Android programs most commonly detected on protected Android devices. At the same time, malware writers continued actively using various tools for modding Android apps to shield their malware from anti-virus detection. During the second quarter, our virus analysts discovered a number of new trojan programs on Google Play that are designed to subscribe users to paid mobile services.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;Principal trends in Q2 2026&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;The number of threats detected on protected devices increased.&lt;/li&gt;
        &lt;li&gt;Significantly more unique files were among the threats detected.&lt;/li&gt;
        &lt;li&gt;Compared to Q1, fewer requests to decrypt files affected by encoder trojans were registered.&lt;/li&gt;
        &lt;li&gt;Scammers started ramping up their attacks on users of the Russian messenger MAX.&lt;/li&gt;
        &lt;li&gt;&lt;b&gt;Android.Banker&lt;/b&gt; banking trojans remained the most widespread malware for Android devices.&lt;/li&gt;
        &lt;li&gt;Doctor Web’s experts discovered an ad-displaying trojan that can bypass Android OS restrictions and display background ads.&lt;/li&gt;
        &lt;li&gt;Threat actors distributed JobStealer, malware designed to steal confidential data from macOS and Windows computer users.&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;According to Doctor Web’s statistics service&lt;/h3&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/01_stat_q2_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/01_stat_q2_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common threats in Q2 2026&lt;/p&gt;

&lt;dl&gt;
    &lt;dt&gt;Adware.Downware.20091&lt;/dt&gt;
    &lt;dt&gt;Adware.Downware.20766&lt;/dt&gt;
    &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
    &lt;dt&gt;Trojan.Siggen31.34463&lt;/dt&gt;
    &lt;dd&gt;A trojan written in the Go programming language and designed to download various miner trojans and adware into infected systems. This malware is a DLL file located at &lt;span class="string"&gt;%appdata%\utorrent\lib.dll&lt;/span&gt;. To launch, it exploits a DLL Search Order Hijacking vulnerability in the uTorrent client.&lt;/dd&gt;
    &lt;dt&gt;Trojan.BPlug.4268&lt;/dt&gt;
    &lt;dd&gt;The detection name for a malicious component of the WinSafe browser extension. This component is a JavaScript file that displays intrusive ads in browsers.&lt;/dd&gt;
    &lt;dt&gt;Trojan.Starter.8319&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious XML scripts that launch &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malware and its components.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Statistics for malware discovered in email traffic&lt;/h3&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/02_mail_traffic_q2_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/02_mail_traffic_q2_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most widespread threats in email traffic in Q2 2026&lt;/p&gt;

&lt;dl&gt;
    &lt;dt&gt;X97M.DownLoader.2343&lt;/dt&gt;
    &lt;dd&gt;An XLSX file (the Microsoft Excel spreadsheet format) with an OLE object that downloads a malicious file onto an attacked computer.&lt;/dd&gt;
    &lt;dt&gt;W97M.DownLoader.2938&lt;/dt&gt;
    &lt;dd&gt;A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.&lt;/dd&gt;
    &lt;dt&gt;Exploit.CVE-2017-11882.123&lt;/dt&gt;
    &lt;dt&gt;Exploit.CVE-2018-0798.4&lt;/dt&gt;
    &lt;dd&gt;Exploits designed to take advantage of Microsoft Office software vulnerabilities that allow an attacker to run arbitrary code.&lt;/dd&gt;
    &lt;dt&gt;JS.Muldrop.1171&lt;/dt&gt;
    &lt;dd&gt;A malicious JavaScript that executes malware hidden in it on the target system.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Encryption ransomware&lt;/h3&gt;

&lt;p&gt;In Q2 2026, the number of requests made to decrypt files affected by encoder trojans decreased slightly—by 2.67%, compared to Q1 2026.&lt;/p&gt;

&lt;p&gt;The dynamics of the decryption requests received by Doctor Web’s Technical Support Service:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/03_encoder_requests_q2_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/03_encoder_requests_q2_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common encoders of Q2 2026&lt;/p&gt;

&lt;ul class="list"&gt;
   &lt;li&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 14.47% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;b&gt;Trojan.Encoder.41868&lt;/b&gt; — 5.26% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;b&gt;Trojan.Encoder.37400&lt;/b&gt; — 3.95% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt; — 3.29% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;b&gt;Trojan.Encoder.44197&lt;/b&gt; — 2.63% of user requests&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Network fraud&lt;/h3&gt;

&lt;p&gt;One of the trends Doctor Web’s Internet analysts observed in the second quarter of 2026 was that, against the backdrop of a growing audience for the Russian messenger MAX, threat actors began more actively attacking users of this service. In doing so, the attackers utilize well-known schemes that previously targeted users of other messengers, like Telegram and WhatsApp. For instance, our experts found many fraudulent websites created to steal MAX accounts under the guise of various voting events. The potential victim is asked to vote in a particular contest, but to do so, the user must log in to their account by providing a mobile phone number and the security code received after entering it. When the user enters all of the requested data, the attackers gain access to their account.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/04_fake_max_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/04_fake_max_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a phishing site that fraudsters use to gain access to a victim’s MAX messenger account&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;During Q2 2026, Doctor Web’s Internet analysts observed the emergence of more fraudulent investing-related websites. Cybercriminals follow today’s trends and continue to actively exploit the topic of artificial intelligence (AI). For example, on some websites, they offered potential victims the opportunity to join a new investment project allegedly linked to large Russian credit organizations. Malicious actors promised access to a specialized chatbot, based on the ChatGPT neural network, that assists with investing. To become members of this “project”, website visitors had to register by providing their personal information.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/05_fake_invest_gptbot_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/05_fake_invest_gptbot_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fraudulent website offers the chance to register in an investment project allegedly related to a Russian bank and then gain access to a specialized financial chatbot based on the ChatGPT neural network&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;At the same time, scammers tried to lure Russian-speaking users by exploiting the names of not only Russian banks but also foreign credit institutions. For example, cybercriminals presented a number of pseudo-investment service websites as being related to South Korean banks.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/06_fake_korean_invest_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/06_fake_korean_invest_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;One of the fraudulent sites offering Russian-speaking users the chance to join some investment project belonging to a South Korean bank and promising an income starting from 2,000,000 South Korean won&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;In Q2 2026, scammers trying to hijack account data for various services remained active. Among the many phishing websites discovered were fake Internet resources of transport companies. One was targeting the customers of a Russian express delivery service. Potential victims were asked to log in to their account by using the mobile phone number linked to the account, or to log in via Gosuslugi &lt;i&gt;(Госуслуги)&lt;/i&gt;. At the same time, even after “logging in” to the account using the first method, the user was shown a second phishing form that looked like authorization via Gosuslugi was required.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/07_fake_transport_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/07_fake_transport_q2_2026.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/08_fake_gos_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/08_fake_gos_q2_2026.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Using a fraudulent website, threat actors could steal data from several accounts at once—from a personal account on the transport company’s website and from the Gosuslugi web portal&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Our specialists also identified new phishing sites for credit organizations of various countries. For instance, scammers asked depositors of one US bank to log in to their account and check the availability of a higher interest rate for “loyal customers”:&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/09_fake_usa_bank_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/09_fake_usa_bank_q2_2026.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/10_fake_usa_banklogin_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/10_fake_usa_banklogin_q2_2026.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;In another case, a phishing website was designed to look like it belonged to one of the Ecuadorian banks and asked users for their online banking account login and password:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/11_fake_ecuador_bank_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/11_fake_ecuador_bank_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;Another phishing scheme targeted British users. Cybercriminals created fake government service websites where individuals could pay a parking fine.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/12_fake_uk_parking1_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/12_fake_uk_parking1_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;Potential victims were asked for detailed personal information, supposedly to verify their identity, after which they were redirected to a page for paying the “fine”.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/13_fake_uk_parking2_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/13_fake_uk_parking2_q2_2026.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/14_fake_uk_parking3_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/14_fake_uk_parking3_q2_2026.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The alleged opportunity for citizens to get various gratuitous payments remains a common fraudulent scheme. However, cybercriminals are constantly adapting it to current events. For example, in the run-up to Russia Day celebrations, fake websites of Russian credit organizations began emerging, with scammers promising special holiday payments. On one such site, users were supposedly eligible to receive between 5,000 and 300,000 rubles for taking a survey:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/15_fake_russia_pay_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/15_fake_russia_pay_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;In another variant of the scheme, users could supposedly expect to receive “assistance” in the amount of 5,000 rubles after completing a survey:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/16_fake_russia_help_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/16_fake_russia_help_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;Amid speculative reports of fuel shortages in some Russian regions, a number of these sites promised vouchers for 20 to 200 liters of free fuel:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/17_fake_russia_fuel_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/17_fake_russia_fuel_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;After answering a few simple questions, visitors to these sites were asked to undergo an “identity check” in order to receive the promised reward. For this, they had to provide their first and last names, mobile phone number, and bank card number. Fraudsters could then use this information to steal the victims’ money.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/18_fake_russia_payoutcard_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/18_fake_russia_payoutcard_q2_2026.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/19_fake_russia_payoutdata_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/19_fake_russia_payoutdata_q2_2026.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;Fake FIFA (the International Federation of Association Football) websites were also among the unwanted Internet portals identified in Q2 2026. On these, users were allegedly able to officially purchase tickets to 2026 FIFA World Cup matches, brand souvenirs, and various premium services. Just like on the legitimate site, visitors to such fakes were asked to log in to a FIFA ID account, but the authentication form for entering the login and password in this case was accepting any data at all.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/20_fake_fifaid_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/20_fake_fifaid_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Fake FIFA ID account login form&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;When football enthusiasts selected the product they were interested in, they were asked to complete the purchase and make payment. During the payment process, users were redirected to the website of one of the services included in the Dr.Web anti-virus database for non-recommended Internet resources.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/21_fake_fifa_purchase_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/21_fake_fifa_purchase_q2_2026.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/22_fake_fifa_pay_q_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/22_fake_fifa_pay_q_2026.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fake FIFA website allegedly allowing users to officially purchase licensed products and services&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Our experts also identified a number of spam campaigns aimed at distributing links to fake Russian marketplace websites, where the attackers offered potential victims the opportunity to participate in an “anniversary prize draw”. The fraudsters promised the chance to win money prizes—up to 1,000,000 rubles—as well as computer and mobile gadgets:&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/23_fake_marketplace_prize1_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/23_fake_marketplace_prize1_q2_2026.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/24_fake_marketplace_prize2_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/24_fake_marketplace_prize2_q2_2026.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;To participate in this “promotion”, users had to click the corresponding button on these websites, after which the prize drawing process would be simulated. After several attempts, the potential victim was told that they had won several gifts and supposedly had their choice of either the prizes themselves—at the marketplace pickup point—or their cash equivalent—by transfer to a bank account:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/25_fake_marketplace_prize3_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/25_fake_marketplace_prize3_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;If the option to receive prizes at the pick-up point was chosen, these websites would report that the required goods were out of stock, but the user could allegedly still exchange them for money. For that to happen, the potential victim had to provide their bank card number:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/26_fake_marketplace_prize4_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/26_fake_marketplace_prize4_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;Once the number was entered, the sites asked the victim to pay the state fee to “officially register the winnings”:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/27_fake_marketplace_prize5_q2_2026.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/july/review_common_q2/27_fake_marketplace_prize5_q2_2026.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The fraudsters’ victims never actually received any prizes. They not only handed over their bank card details but also their money.&lt;/p&gt;

&lt;div class="notrecommend"&gt;
    &lt;a href="https://antifraud.drweb.com/dangerous_urls/?lng=en"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;
&lt;/div&gt;

&lt;h3&gt;Malicious and unwanted programs for mobile devices&lt;/h3&gt;

&lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q2 2026, users encountered banking trojans less frequently; however, these trojan apps remained the most widespread malware. In addition, the activity of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; ad-displaying trojans continued to decrease.&lt;/p&gt;

&lt;p&gt;The programs &lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Tool.NPMod&amp;lng=en"&gt;&lt;b&gt;Tool.NPMod&lt;/b&gt;&lt;/a&gt;, which were modified using the NP Manager modding tool, were the most commonly detected, potentially dangerous software. Malware creators use this tool to protect malicious software from being detected by anti-viruses. The most prevalent unwanted apps were &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt; fake anti-viruses. To “cure” threats that were allegedly detected, they demand that users purchase the full version of the software.&lt;/p&gt;

&lt;p&gt;Topping the list of the most commonly detected adware programs were &lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt; modules, which display misleading notifications and collect confidential data. The Android OS optimization apps &lt;a href="https://vms.drweb.com/search/?q=Adware.Bastion&amp;lng=en"&gt;&lt;b&gt;Adware.Bastion&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; were widespread again. They create notifications with informational messages about supposed memory insufficiencies and system errors to display ads during “optimization”. &lt;b&gt;Adware.Opensite.15&lt;/b&gt; advertising programs also remained highly active. Threat actors distribute them under the guise of cheating apps, which supposedly can help users obtain various in-game resources. But these programs, in fact, only load websites with ads.&lt;/p&gt;

&lt;p&gt;In June, Doctor Web’s specialists &lt;a href="https://news.drweb.com/show/?i=15262&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about &lt;a href="https://vms.drweb.com/search/?q=Android.MagicAd.1&amp;lng=en"&gt;&lt;b&gt;Android.MagicAd.1&lt;/b&gt;&lt;/a&gt;, a trojan capable of bypassing Android OS restrictions and displaying background ads. For that, &lt;a href="https://vms.drweb.com/search/?q=Android.MagicAd.1&amp;lng=en"&gt;&lt;b&gt;Android.MagicAd.1&lt;/b&gt;&lt;/a&gt; exploits third-party apps and also utilizes different methods, which it selects, based on the infected device’s manufacturer.&lt;/p&gt;

&lt;p&gt;Over the course of Q2, our malware analysts uncovered more trojan apps on Google Play from the &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt; families, which subscribe users to paid services. Combined, they were downloaded at least 2,600,000 times.&lt;/p&gt;

&lt;p&gt;The most noteworthy Q2 2026 events involving mobile malware&lt;/p&gt;

&lt;ul class="list"&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans remained the most commonly detected malware on devices protected with Dr.Web anti-virus products.&lt;/li&gt;
    &lt;li&gt;Malicious actors continued actively using specialized Android app-modding tools to shield banking trojans from anti-virus detection.&lt;/li&gt;
    &lt;li&gt;The activity of the ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; decreased again.&lt;/li&gt;
    &lt;li&gt;Doctor Web’s malware analysts discovered &lt;a href="https://vms.drweb.com/search/?q=Android.MagicAd.1&amp;lng=en"&gt;&lt;b&gt;Android.MagicAd.1&lt;/b&gt;&lt;/a&gt;, a trojan that exploits third-party programs to bypass Android OS restrictions and display background ads.&lt;/li&gt;
    &lt;li&gt;More trojan apps subscribing users to paid services were detected on Google Play.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;To find out more about the security-threat landscape for mobile devices in Q2 2026, read our &lt;a href="https://news.drweb.com/show/review/?lng=en&amp;i=15274" target="_blank"&gt;special overview&lt;/a&gt;.&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15135&amp;lng=en</guid><title>Doctor Web’s Q1 2026 virus activity review</title><link>https://news.drweb.com/show/?i=15135&amp;lng=en&amp;c=10</link><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;April 1, 2026&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;newslead&gt;According to statistics collected by the Dr.Web anti-virus, the total number of threats detected in the first quarter (Q1) of 2026 decreased by 6.77%, compared to the fourth quarter of last year. The number of unique threats decreased by 11.98%. Adware programs and ad-displaying trojans, malicious downloader apps, and backdoors were most commonly detected on protected devices.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;Most widely encountered in email traffic were malicious scripts, backdoors, and various trojans. Threat actors also used emails to distribute phishing documents and exploits.&lt;/p&gt;

&lt;p&gt;Users whose files were affected by encoder trojans had primarily encountered &lt;b&gt;Trojan.Encoder.35534&lt;/b&gt;, &lt;b&gt;Trojan.Encoder.29750&lt;/b&gt; and &lt;b&gt;Trojan.Encoder.41868&lt;/b&gt;.&lt;/p&gt;

&lt;p&gt;In Q1 2026, Doctor Web’s Internet analysts detected new phishing websites, including fake online resources of credit organizations and marketplaces as well as a number of other unwanted sites.&lt;/p&gt;

&lt;p&gt;The mobile device segment saw increased activity on the part of banking trojans. At the same time, our malware analysts noted the growing popularity of a method used to prevent malicious programs from being detected by anti-viruses. This method involves adding junk code to the apps.&lt;/p&gt;

&lt;p&gt;In January, Doctor Web’s experts informed users about the &lt;b&gt;Android.Phantom&lt;/b&gt; trojan clickers, which use machine learning and video broadcasting to boost clicks on websites. In addition, over the past three months, we detected the emergence of yet more malware on Google Play, including trojans that subscribe users to paid services.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;Principal trends in Q1 2026&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;The number of threats detected on protected devices decreased&lt;/li&gt;
        &lt;li&gt;Fewer unique files exist among the threats that were detected&lt;/li&gt;
        &lt;li&gt;Compared to the previous observation period, fewer users requested help to decrypt files affected by encoder trojans&lt;/li&gt;
        &lt;li&gt;Banking trojans for Android devices continued to increase their activity&lt;/li&gt;
        &lt;li&gt;Users were at risk of encountering &lt;b&gt;Android.Phantom&lt;/b&gt; clicker trojans, which use machine learning, among other techniques, to boost clicks on websites&lt;/li&gt;
        &lt;li&gt;More malicious apps were discovered on Google Play&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;According to Doctor Web’s statistics service&lt;/h3&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/01_stat_q1_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/01_stat_q1_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common threats in Q1 2026&lt;/p&gt;

&lt;dl&gt;
    &lt;dt&gt;Trojan.Siggen31.34463&lt;/dt&gt;
    &lt;dd&gt;A trojan written in the Go programming language and designed to download various miner trojans and adware into infected systems. This malware is a DLL file located at &lt;span class="string"&gt;%appdata%\utorrent\lib.dll&lt;/span&gt;. To launch, it exploits a DLL Search Order Hijacking vulnerability in the uTorrent torrent client.&lt;/dd&gt;
    &lt;dt&gt;Adware.Downware.20655&lt;/dt&gt;
    &lt;dt&gt;Adware.Downware.20766&lt;/dt&gt;
    &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
    &lt;dt&gt;Trojan.BPlug.4268&lt;/dt&gt;
    &lt;dd&gt;The detection name for a malicious component of the WinSafe browser extension. This component is a JavaScript file that displays intrusive ads in browsers.&lt;/dd&gt;
    &lt;dt&gt;Adware.Siggen.33379&lt;/dt&gt;
    &lt;dd&gt;A fake Adblock Plus browser ad blocker that is installed on the system by other malware to display advertisements.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Statistics for malware discovered in email traffic&lt;/h3&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/02_mail_traffic_q1_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/02_mail_traffic_q1_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common threats in email traffic in Q1 2026&lt;/p&gt;

&lt;dl&gt;
    &lt;dt&gt;JS.DownLoader.1225&lt;/dt&gt;
    &lt;dd&gt;Heuristic detection for ZIP archives containing JavaScripts with suspicious names.&lt;/dd&gt;
    &lt;dt&gt;W97M.DownLoader.2938&lt;/dt&gt;
    &lt;dd&gt;A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.&lt;/dd&gt;
    &lt;dt&gt;Exploit.CVE-2017-11882.123&lt;/dt&gt;
    &lt;dt&gt;Exploit.CVE-2018-0798.4&lt;/dt&gt;
    &lt;dd&gt;Exploits designed to take advantage of Microsoft Office software vulnerabilities that allow an attacker to run arbitrary code.&lt;/dd&gt;
    &lt;dt&gt;JS.Redirector.514&lt;/dt&gt;
    &lt;dd&gt;A malicious script that redirects users to a web page controlled by fraudsters.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Encryption ransomware&lt;/h3&gt;

&lt;p&gt;In Q1 2026, the number of requests made to decrypt files affected by encoder trojans decreased by 31.51%, compared to Q4 2025. The decline occurred against the backdrop of the New Year holidays and the associated long weekend, during which a number of cybercriminals may have suspended their activity and gone on vacation. At the same time, users who nonetheless suffered from encoder trojan attacks during this period may not have immediately responded to incidents that had occurred.&lt;/p&gt;

&lt;p&gt;The dynamics of the decryption requests received by Doctor Web’s Technical Support Service:&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/03_encoder_requests_q1_2026_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/03_encoder_requests_q1_2026_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common encoders of Q1 2026&lt;/p&gt;

&lt;ul class="list"&gt;
   &lt;li&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 15.59% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.29750&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.29750&lt;/b&gt;&lt;/a&gt; — 3.23% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;b&gt;Trojan.Encoder.41868 &lt;/b&gt; — 3.23% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.26996&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.26996&lt;/b&gt;&lt;/a&gt; — 1.62% of user requests&lt;/li&gt;
   &lt;li&gt;&lt;b&gt;Trojan.Encoder.44383 &lt;/b&gt; — 1.61% of user requests&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Network fraud&lt;/h3&gt;

&lt;p&gt;Over the past three months, Doctor Web’s Internet analysts discovered a number of new fake marketplace websites on which fraudsters offer the chance to join in a “clearance sale” of supposedly unredeemed orders. The fraudulent scheme works like this: the “unclaimed” goods from the orders are divided into different categories (electronics, clothes, footwear, cosmetics, etc.) and are allegedly packed into the corresponding surprise boxes. Their content is unknown and is claimed to possibly include expensive items. At the same time, potential victims are offered a chance to buy these boxes at a relatively low price, which is the main lure of this scam.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/04_market.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/04_market.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fake marketplace site promises a “sale of unclaimed orders” that are supposedly overflowing warehouses&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;When a user selects one of the boxes, they are asked to place an order and provide personal information that may include their first and last names, mobile phone number, and email address. Next, the user is redirected to the payment page to pay via the Faster Payments System (&lt;em&gt;“Система быстрых платежей”&lt;/em&gt;, &lt;em&gt;“СБП”&lt;/em&gt;, or &lt;em&gt;“SBP”&lt;/em&gt;). As a result, the victim loses their money and provides confidential data to the fraudsters.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/05_market.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/05_market.2.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/06_market.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/06_market.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;After placing an “order”, the victim is asked to pay for it via the Faster Payments System&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Our experts also identified many websites for services offering various financial products, such as the ability to swiftly obtain a microloan, a regular loan, or go through bankruptcy proceedings. Such services do not provide these products themselves, as users expect, and are only intermediaries between clients and financial institutions. They provide paid access to a selection of potentially suitable options, while the aggregation of such financial offers is available from free sources. Moreover, these services do not guarantee a successful result when an application is submitted. At the same time, access is granted not after a one-time payment, but after a paid subscription involving periodic debits is taken out.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/07_finance.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/07_finance.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;One of the websites requiring users to pay in order to access a service for selecting financial offers. Users believe they are making a one-time payment for access, but unbeknownst to them, they are signing up for a subscription&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;In some cases, such resources can mislead users by offering them one type of service, like job placements, but actually provide subscription access to the aforementioned financial offers for loans, microloans, etc.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/08_job.2.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/08_job.3.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A website promises to help visitors find a job, but once payment is made to access the service, financial proposals (loans, microloans, etc.) from the website’s partners may be offered instead&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Among the phishing sites identified in Q1 2026 were fake web resources for the Green Marathon (&lt;em&gt;“Зеленый Марафон”&lt;/em&gt;) charity race. They offer visitors the opportunity to register for the marathon, but these sites are not affiliated with the event and are designed to collect users’ confidential data.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/09_maraphon.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/09_maraphon.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;One of the fake sites for the Green Marathon charity race&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Doctor Web’s Internet analysts also discovered more fake investment service websites that were supposedly affiliated with various credit organizations. Among them were sites targeting audiences from Russia, Kazakhstan, and other countries. Scammers promise potential victims high profits and, in order to “access” pseudo-investment platforms, they are asked to take a short survey and register an account by providing personal information.&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/10_phishing_bank.2.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/10_phishing_bank.3.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a phishing website that malicious actors pass off as an official resource for an investment service of one Russian bank&lt;/em&gt;&lt;/p&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/11_phishing_bank.2.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_common_q1/11_phishing_bank.3.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a phishing site that cybercriminals present as an official online resource for an investment service of one Kazakhstani credit institution&lt;/em&gt;&lt;/p&gt;

&lt;div class="notrecommend"&gt;
    &lt;a href="https://antifraud.drweb.com/dangerous_urls/?lng=en"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;
&lt;/div&gt;

&lt;h3&gt;Malicious and unwanted programs for mobile devices&lt;/h3&gt;

&lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q1 2026, the growth in activity observed in Q4 last year with regards to &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans continued to trend upward. The most widespread among them were members of the &lt;b&gt;Android.Banker.Mamont&lt;/b&gt; subfamily. At the same time, the number of detections of the ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; decreased yet again.&lt;/p&gt;

&lt;p&gt;Topping the list of the most commonly detected potentially dangerous software were apps to which junk code has been added with the help of Android program modification tools (such apps containing junk code are detected as &lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt;). Currently, this technique is actively being used to protect banking trojans from anti-virus detection. In addition, programs modified using the NP Manager tool remained prevalent (these are detected as &lt;a href="https://vms.drweb.com/search/?q=Tool.NPMod&amp;lng=en"&gt;&lt;b&gt;Tool.NPMod&lt;/b&gt;&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;The most widely detected unwanted software programs were &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt; fake anti-viruses, which demand that users purchase the full version of the software to “cure” threats that had supposedly been found. The most active ad-displaying software programs in Q1 were &lt;a href="https://vms.drweb.com/search/?q=Adware.Bastion&amp;lng=en"&gt;&lt;b&gt;Adware.Bastion&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; and &lt;b&gt;Adware.Opensite.15&lt;/b&gt;. The former are optimization apps that create notifications containing informational messages about supposed low memory and system errors in order to display ads during “optimization”.  The latter are fake cheat software for obtaining in-game resources, but, in reality, they load websites containing ads.&lt;/p&gt;

&lt;p&gt;In January 2026, our anti-virus laboratory &lt;a href="https://news.drweb.com/show/?i=15110&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about the &lt;b&gt;Android.Phantom&lt;/b&gt; trojan clickers. These malicious programs use machine learning and video broadcasts to boost clicks on websites. Cybercriminals distributed them in several ways: via the GetApps app catalog for Xiaomi devices, Telegram channels, Discord servers, third-party software collections, and malicious sites.&lt;/p&gt;

&lt;p&gt;Over the past three months, Doctor Web’s virus analysts discovered new threats on Google Play. Among them were &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt; trojans, which subscribe users to paid services.&lt;/p&gt;

&lt;p&gt;The following Q1 2026 events involving mobile malware are the most noteworthy&lt;/p&gt;

&lt;ul class="list"&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans became the most widespread threats for Android devices.&lt;/li&gt;
    &lt;li&gt;Cybercriminals increasingly used Android app modding tools to protect banking trojans from anti-virus detection.&lt;/li&gt;
    &lt;li&gt;The trend of decreasing activity on the part of &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans continued.&lt;/li&gt;
    &lt;li&gt;Users were at risk of encountering &lt;b&gt;Android.Phantom&lt;/b&gt; trojans, which use machine learning and video broadcasts to artificially boost clicks on websites.&lt;/li&gt;
    &lt;li&gt;Malicious apps were again distributed via Google Play.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;To find out more about the security-threat landscape for mobile devices in Q1 2026, read our &lt;a href="https://news.drweb.com/show/review/?i=15136&amp;lng=en" target="_blank"&gt;special overview&lt;/a&gt;.&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15136&amp;lng=en</guid><title>Doctor Web’s Q1 2026 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=15136&amp;lng=en&amp;c=10</link><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;April 1, 2026&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, the trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;, which display intrusive ads, continued to decline in activity in the first quarter (Q1) of 2026. Compared to the fourth quarter of last year, they were detected on protected devices 32.70% and 7.09% less often, respectively. They lost their lead to &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans, whose activity increased by more than 2.5 times over the course of the last three months. As a result, they have become the most widespread Android threats. Such malicious apps intercept SMS containing transaction confirmation codes coming from banks, display phishing windows, and can also imitate the appearance of real banking software to steal confidential data. Users were most likely to encounter trojans from the &lt;b&gt;Android.Banker.Mamont&lt;/b&gt; subfamily, which includes a variety of malicious programs.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;In Q1, widely common were apps to which junk code had been added to obfuscate their logic (these accounted for 15.35% of all detections registered). This modification is performed using NP Manager hacker tools for modding Android software. Since last fall, these tools are actively being used in the &lt;b&gt;Android.Banker.Mamont&lt;/b&gt; trojan family to evade anti-virus detection. That is why we warn users when a particular app has been altered in such a way. Dr.Web Anti-virus products detect such apps as &lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Other widespread potentially dangerous software, despite a 31.65% decrease in the number of detections, was again software modified with the help of the NP Manager tool. (Dr.Web detects them as &lt;a href="https://vms.drweb.com/search/?q=Tool.NPMod&amp;lng=en"&gt;&lt;b&gt;Tool.NPMod&lt;/b&gt;&lt;/a&gt;). This tool contains various modules for protecting and obfuscating the apps’ code as well as for bypassing digital signature verification once apps are modified. Cybercriminals use it to protect malware so that anti-viruses have a harder time detecting it.&lt;/p&gt;

&lt;p&gt;The most prevalent unwanted software was &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;—fake anti-viruses that allegedly detect threats and demand that users purchase the full version to “cure” the infection. Moreover, users again encountered apps from the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt; families. The former supposedly allow users to earn money by completing various tasks. The latter are apps modified using the CloudInject cloud service. Via this service, the programs are given dangerous system permissions as well as an obfuscated code whose functionality cannot be controlled.&lt;/p&gt;

&lt;p&gt;The most frequently detected adware programs were &lt;a href="https://vms.drweb.com/search/?q=Adware.Bastion&amp;lng=en"&gt;&lt;b&gt;Adware.Bastion&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; optimization apps. These periodically create notifications containing misleading messages that inform users about alleged low memory and system errors. Their goal is to display ads during “optimization”. Another popular adware was &lt;b&gt;Adware.Opensite.15&lt;/b&gt;—programs which cybercriminals pass off as cheat tools for obtaining resources in games. In reality, such apps load various ad-filled websites. &lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;—programs with built-in ad-displaying modules—were also widespread once again.&lt;/p&gt;

&lt;p&gt;In January, Doctor Web &lt;a href="https://news.drweb.com/show/?i=15110&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about a new family of trojan clickers, dubbed &lt;b&gt;Android.Phantom&lt;/b&gt;. Our virus analysts identified several distribution sources for these malicious apps. One was the official app catalog for Xiaomi devices—GetApps, where the trojans were found to be embedded in several games. Moreover, threat actors distributed the clickers within the mods of popular software via various Telegram channels, Discord servers, online software collections, and malicious websites.&lt;/p&gt;

&lt;p&gt;Using &lt;b&gt;Android.Phantom&lt;/b&gt; trojans, cybercriminals manipulate ad clicks on websites with the help of both machine-learning technologies and WebRTC, a technology for transmitting streaming data (including video) through a browser. The trojans load target websites along with JavaScript code for simulating user actions in WebView. Interaction with ads occurs in one of two modes. If a device supports WebRTC, &lt;b&gt;Android.Phantom&lt;/b&gt; clickers broadcast a virtual screen with the loaded website to the attackers, who then control the website manually or using an automated system.&lt;/p&gt;

&lt;p&gt;If WebRTC is not available, automated JavaScript scripts utilizing the TensorFlowJS framework are used. The clickers download the required behavioral model from a remote server as well as JavaScript containing the framework itself and all of the functions necessary for the model to operate and interact with target sites.&lt;/p&gt;

&lt;p&gt;Over the course of Q1, Doctor Web’s anti-virus laboratory identified new threats on Google Play. Among them were many &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojans as well as the malicious apps &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.23&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.24&lt;/b&gt;. All of them are designed to subscribe users to paid services.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;Principal trends of Q1 2026&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans became the most common Android threats.&lt;/li&gt;
        &lt;li&gt;Cybercriminals have begun using Android app modding tools more often to protect banking trojans.&lt;/li&gt;
        &lt;li&gt;The ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; continued to be less active.&lt;/li&gt;
        &lt;li&gt;The spread of &lt;b&gt;Android.Phantom&lt;/b&gt; trojan apps, which utilize machine learning and video broadcasts to boost clicks on websites, was notable.&lt;/li&gt;
        &lt;li&gt;New malware was detected on Google Play.&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h3&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/01_malware_q1_2026_en.2.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/01_malware_q1_2026_en.3.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;Android.Banker.Mamont.80.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A banking trojan that intercepts SMS containing one-time codes from credit organizations, hijacks the contents of notifications, and collects other confidential information. This includes technical data about the infected device, the list of installed apps, and information about the SIM card, phone calls, and sent and received SMS.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan app that loads the website hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.675.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan app designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Android.Packed.57.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for an obfuscator used to protect apps, including malicious ones (for example, some &lt;b&gt;Android.SpyMax&lt;/b&gt; banking trojan versions).&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1812&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious &lt;em&gt;WhatsApp&lt;/em&gt; messenger mods that can covertly load various websites in the background.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/02_unwanted_q1_2026_en.2.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/02_unwanted_q1_2026_en.3.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, modders can remotely manage these apps—blocking them, displaying custom dialogs, tracking when other software is being installed or removed from a device, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Program.SnoopPhone.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An application designed to monitor the activity of Android device owners. It allows intruders to read SMS, collect call information, track device location, and record the surroundings.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/03_riskware_q1_2026_en.2.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/03_riskware_q1_2026_en.3.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscator.TrashCode&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscator.TrashCode&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs to which junk code has been added, using hacker tools for modifying Android apps. Such modification is performed to scramble the apps’ logic. This technique is often found in banking trojans and pirated software.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.3&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. This tool contains modules for obfuscating and protecting the apps’ code as well as for bypassing their digital signature verification after they have been modified. The obfuscation it adds is often used to make the malware more difficult to detect and analyze.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads from the Internet specially prepared scripts, which can be crafted and added to a common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/04_adware_q1_2026_en.2.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/04_adware_q1_2026_en.3.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Bastion&amp;lng=en"&gt;&lt;b&gt;Adware.Bastion&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for optimization programs that periodically create notifications containing misleading messages. They inform users about alleged low memory and system errors in order to display ads during “optimization”.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An adware module that can be built into Android apps. It displays notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, this module collects a variety of confidential data and is able to download other apps and initiate their installation.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Opensite.15&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Apps passed off as cheat tools for obtaining resources in games. In fact, they are created to display ads. These programs receive a configuration from a remote server and use it to open a target website containing ads like banners, pop-up windows, video clips, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An adware module that malicious actors embed into cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display obnoxious ads.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Airpush.7.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware modules that can be built into Android apps and display various ads. Depending on the modules’ version and modification, these can be notifications containing ads, pop-up windows or banners. Malicious actors often use these modules to distribute malware by offering their potential victims diverse software for installation. Moreover, such modules collect personal information and send it to a remote server.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Threats on Google Play&lt;/h3&gt;

&lt;p&gt;In Q1 2026, Doctor Web’s anti-virus laboratory experts discovered more &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; malicious programs, which subscribe victims to paid services. The trojans were concealed in a number of tools for optimizing the operation of Android devices, and were distributed under the guise of messengers, multimedia, and other software. In total, they have been installed at least 370,000 times.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/05_Android.Joker.2524.jpg" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/05_Android.Joker.2524.1.jpg"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/06_Android.Joker.2511.jpg" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/06_Android.Joker.2511.1.jpg"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Examples of &lt;b&gt;Android.Joker&lt;/b&gt; malware detected on Google Play in Q1 2026. &lt;b&gt;Android.Joker.2511&lt;/b&gt; was built into the messenger Private Chat Message, and &lt;b&gt;Android.Joker.2524&lt;/b&gt;—into the camera app Magic Camera&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Moreover, our malware analysts discovered the malicious programs, &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.23&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.24&lt;/b&gt;, which are also designed to subscribe users to paid services. These trojans load websites, where a paid mobile subscription is activated with the help of Wap Click technology. On these sites, users are asked to provide their mobile phone number, after which an attempt is made to automatically activate a subscription. Both trojans were downloaded from Google Play over 1.5 million times in total.&lt;/p&gt;

&lt;div class="img img-two-v same-height"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/07_Android.Subscription.23.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/07_Android.Subscription.23.1.png"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/08_Android.Subscription.24.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/april/review_mobile_q1/08_Android.Subscription.24.1.png"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The &lt;b&gt;Android.Subscription.23&lt;/b&gt; and &lt;b&gt;Android.Subscription.24&lt;/b&gt; malicious programs were distributed as Stream Hive and Prime Link, apps for managing personal finances, but their only functionality was loading websites to subscribe Android device owners to paid mobile services&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q1%202026%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank"&gt;Indicators of compromise&lt;/a&gt;&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15102&amp;lng=en</guid><title>Doctor Web’s virus activity review for 2025</title><link>https://news.drweb.com/show/?i=15102&amp;lng=en&amp;c=10</link><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;January 15, 2026&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;newslead&gt;In 2025, trojans designed to display ads were one of the most active threats. Users also encountered various malicious scripts and trojan programs that launch other malware in infected systems. In email traffic, trojan downloaders, backdoors, exploits, malicious scripts, and phishing documents were most commonly detected.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;Among mobile threats, the most widespread were ad-displaying trojans and fake apps used in a variety of fraudulent schemes. An increase in banking trojan activity was also observed. At the same time, Doctor Web’s virus analysts discovered dozens of new malicious, unwanted, and adware programs on Google Play.&lt;/p&gt;

&lt;p&gt;Compared to 2024, Doctor Web received fewer user requests to decrypt files affected by encoder trojans. Meanwhile, over the last year, our Internet analysts detected more fraudulent websites created to steal &lt;i&gt;Telegram&lt;/i&gt; accounts. Moreover, unwanted financial websites were popular once again.&lt;/p&gt;

&lt;p&gt;In 2025, Doctor Web’s anti-virus laboratory investigated several targeted attacks, one of which was carried out on a Russian engineering company. During the attack, threat actors used a number of malicious apps in an attempt to obtain confidential data from infected computers. Our experts ascertained that the Scaly Wolf hacker group was involved in the attack. Another incident occurred when a Russian government organization was attacked by the Cavalry Werewolf hacker group. Doctor Web’s virus analysts discovered many of the malicious tools used by these threat actors and also studied the features of the group and the actions it typically performs in compromised networks.&lt;/p&gt;

&lt;p&gt;Throughout last year, Doctor Web also reported on other information security incidents. In January, our anti-virus laboratory discovered an active campaign that was being orchestrated by cybercriminals who were using a variety of different malware programs to mine Monero cryptocurrency. In April, we informed users about a trojan that cybercriminals had imbedded in the firmware of several budget Android smartphone models in order to use it to steal cryptocurrency. Also in April, our experts identified an Android trojan that malicious actors had embedded into a version of a popular mapping software program and were using to spy on Russian military personnel.&lt;/p&gt;

&lt;p&gt;In July, Doctor Web informed users about a new family of trojans designed to steal cryptocurrency and passwords. Malicious actors distributed them under the guise of game mods, patches, and cheats. In August, our virus analysts warned about the distribution of a multi-functional backdoor for mobile devices that was targeting employees of Russian businesses. Cybercriminals remotely controlled this malware and used it to steal confidential data and spy on victims.&lt;/p&gt;

&lt;p&gt;In October, we published information about a backdoor for Android devices that cybercriminals were distributing as part of modified versions of the &lt;i&gt;Telegram X&lt;/i&gt; messenger. This malicious program steals logins and passwords for &lt;i&gt;Telegram&lt;/i&gt; accounts and other sensitive data. With its help, the attackers can control the victims’ hacked accounts and gain full control over the messenger itself, performing various actions on behalf of account owners.&lt;/p&gt;

&lt;p&gt;In December, we released an article about a trojan that artificially increases the popularity of websites by pretending to be a real human so that its actions are not blocked by the anti-bot protection on the sites. This malware independently seeks out target websites in search engines, opens them, and performs clicks on the opened web pages, based on the parameters it receives from the threat actors.&lt;/p&gt;

&lt;p&gt;The year 2025 also saw a rise in the popularity of ClickFix attacks, in which malicious actors use social engineering to trick users into running malicious code on their devices.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;Principal trends of the year&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;Trojans designed to display ads were highly active&lt;/li&gt;
        &lt;li&gt;New targeted attacks occurred&lt;/li&gt;
        &lt;li&gt;Attacks using the ClickFix method became more popular&lt;/li&gt;
        &lt;li&gt;The number of incidents involving encoder trojans decreased&lt;/li&gt;
        &lt;li&gt;The number of Android banking trojan detections increased&lt;/li&gt;
        &lt;li&gt;New cases of Android device firmware infections were identified&lt;/li&gt;
        &lt;li&gt;Various malicious and unwanted programs were again distributed via Google Play&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;The most notable events of 2025&lt;/h3&gt;

&lt;p&gt;In January 2025, Doctor Web’s specialists &lt;a href="https://news.drweb.com/show/?i=14976&amp;lng=en" target="_blank"&gt;uncovered&lt;/a&gt; a campaign to mine Monero cryptocurrency using the malicious miner SilentCryptoMiner. Its files were disguised as various software, like programs for making video calls. When infecting computers, they removed other miners that might have been previously installed in the system. As part of this campaign, the attackers used steganography, a technique that allows certain data to be hidden among other data (for example, in images), to distribute some of the malicious components. After the specially crafted images were downloaded, the corresponding SilentCryptoMiner components were extracted from them and launched.&lt;/p&gt;

&lt;p&gt;In April, our virus analysts &lt;a href="https://news.drweb.com/show/?i=15002&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about the &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; trojan found in the firmware of a number of budget Android smartphone models. Threat actors built this trojan into a modified version of &lt;i&gt;WhatsApp&lt;/i&gt; messenger, which they then preinstalled on devices after compromising the supply chain of some manufacturers. &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; intercepts messages sent in the trojanized messenger, searches for the Tron and Ethereum crypto wallet addresses in them, and replaces the addresses with those that belong to the attackers. At the same time, the malware conceals this substitution, and victims see the correct crypto wallet addresses in such messages.&lt;/p&gt;

&lt;p&gt;Later in April, Doctor Web’s experts &lt;a href="https://news.drweb.com/show/?i=15006&amp;lng=en" target="_blank"&gt;discovered&lt;/a&gt; the &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; trojan, which cybercriminals embedded into a version of Alpine Quest mapping software and used it to spy on Russian military personnel. The malware collected confidential information and allowed the attackers to steal files from the infected devices.&lt;/p&gt;

&lt;p&gt;In July, Doctor Web released &lt;a href="https://news.drweb.com/show/?i=15036&amp;lng=en" target="_blank"&gt;news material&lt;/a&gt; on its website covering &lt;a href="https://vms.drweb.com/search/?q=Trojan.Scavenger&amp;lng=en"&gt;&lt;b&gt;Trojan.Scavenger&lt;/b&gt;&lt;/a&gt; malicious programs, which are designed to steal cryptocurrency and passwords. The attackers distributed these under the guise of game mods, cheats, patches, etc. The trojans were launched using legitimate software, including via the exploitation of DLL Search Order Hijacking class vulnerabilities.&lt;/p&gt;

&lt;p&gt;In August, our specialists &lt;a href="https://news.drweb.com/show/?i=15047&amp;lng=en" target="_blank"&gt;notified&lt;/a&gt; users about the spread of the multi-functional backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt;, which was targeting representatives of Russian companies. The malware, disguised as anti-viruses, was distributed via direct messages in messengers. Once the target devices were infected, &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; collected confidential data and allowed the attackers to spy on victims.&lt;/p&gt;

&lt;p&gt;Also in August, Doctor Web’s anti-virus laboratory &lt;a href="https://news.drweb.com/show/?i=15046&amp;lng=en" target="_blank"&gt;released a study&lt;/a&gt; on a targeted attack that was perpetrated by the Scaly Wolf group against a Russian engineering company. Cybercriminals deployed a number of malicious tools, one of the main ones being the modular backdoor Updatar. It allowed the attackers to collect confidential data from the infected computers.&lt;/p&gt;

&lt;p&gt;In October, Doctor Web’s experts &lt;a href="https://news.drweb.com/show/?i=15076&amp;lng=en" target="_blank"&gt;warned&lt;/a&gt; about the &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; backdoor built into maliciously modified versions of the &lt;i&gt;Telegram X&lt;/i&gt; messenger. &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; steals logins and passwords for &lt;i&gt;Telegram&lt;/i&gt; accounts along with some other confidential data. The malware allows threat actors to gain full control over a user’s account and to control the messenger, performing actions in it on behalf of the victim. For example, the attackers can covertly join and leave &lt;i&gt;Telegram&lt;/i&gt; channels and also conceal newly authorized devices in the interface of the trojanized &lt;i&gt;Telegram X&lt;/i&gt;.&lt;/p&gt;

&lt;p&gt;In November, we published a &lt;a href="https://news.drweb.com/show/?i=15078&amp;lng=en" target="_blank"&gt;study&lt;/a&gt; on a targeted attack that the Cavalry Werewolf hacker group had carried out against a Russian government organization. During their investigation of the incident, Doctor Web’s experts discovered many of the attackers’ malicious tools, including open-source instruments. Our virus analysts studied the group’s features and found that the threat actors prefer to use reverse shell backdoors and often use the &lt;i&gt;Telegram&lt;/i&gt; API to control infected computers. Moreover, they begin their attacks by sending phishing emails purporting to come from government agencies and attach malware disguised as various official documents to these messages.&lt;/p&gt;

&lt;p&gt;In December, Doctor Web published its &lt;a href="https://news.drweb.com/show/?i=15090&amp;lng=en" target="_blank"&gt;analysis&lt;/a&gt; of the &lt;a href="https://vms.drweb.com/search/?q=Trojan.ChimeraWire&amp;lng=en"&gt;&lt;b&gt;Trojan.ChimeraWire&lt;/b&gt;&lt;/a&gt; malware, which artificially increases the popularity of websites, while pretending to be human. This trojan searches target sites via the Google and Bing search engines, opens the sites it has found, and performs clicks on their web pages in accordance with tasks received from the malicious actors. &lt;a href="https://vms.drweb.com/search/?q=Trojan.ChimeraWire&amp;lng=en"&gt;&lt;b&gt;Trojan.ChimeraWire&lt;/b&gt;&lt;/a&gt; is installed on computers by a number of malicious programs that exploit DLL Search Order Hijacking class vulnerabilities.&lt;/p&gt;

&lt;p&gt;During 2025, attacks using the ClickFix method became more popular. This method is based on social engineering, when cybercriminals trick potential victims into running malicious code themselves. When users visit a malicious or compromised website, it informs them of a supposed error or the need to update their browser and offers to “fix” the problem. Depending on the attack variant involved, users are either asked to copy the strings provided on the web page or to just click the corresponding button (for example, “Update” or “Fix”). In the latter case, the contents that the attackers need will be automatically copied into the clipboard. Next, users are encouraged to run a command line or a PowerShell terminal, paste the clipboard contents in there, and press the “Enter” button on their keyboard. As a result, victims will execute malicious code themselves, which will initiate an infection chain. More information about ClickFix attacks can be found in the corresponding &lt;a href="https://news.drweb.com/show/?i=15074&amp;lng=en" target="_blank"&gt;article&lt;/a&gt; on our website.&lt;/p&gt;

&lt;h3&gt;The malware landscape&lt;/h3&gt;

&lt;p&gt;According to statistics collected by the Dr.Web anti-virus, the total number of threats detected in 2025 increased by 5.45%, compared to 2024. The number of unique threats decreased by 15.89%. Users most often encountered various malicious scripts and adware trojans. In addition, trojans that launch other malicious apps were commonly detected. Users were also targeted by trojans created in the AutoIt scripting language and distributed as part of other malware to make the latter more difficult to detect.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/01_stat_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/01_stat_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;VBS.KeySender.6&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;VBS.KeySender.7&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious script that, in an infinite loop, searches for windows containing the text &lt;span class="string"&gt;mode extensions&lt;/span&gt;, &lt;span class="string"&gt;разработчика&lt;/span&gt;, and &lt;span class="string"&gt;розробника&lt;/span&gt; and sends them an Escape key press event, forcibly closing them.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.BPlug.4242&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for a malicious component of the WinSafe browser extension. This component is a JavaScript file that displays intrusive ads in browsers.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Starter.8319&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Starter.8326&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Starter.8332&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious XML scripts that launch &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malware and its components.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
    &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Siggen30.53926&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name of an Electron framework host process modified by threat actors. It mimics a Steam application component (Steam Client WebHelper) and loads a JavaScript backdoor.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;JS.MalVpn.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious script that various malicious programs use to connect to C2 servers.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Siggen31.34463&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan written in the Go programming language and designed to download various miner trojans and adware into infected systems. This malware is a DLL file located at &lt;span class="string"&gt;%appdata%\utorrent\lib.dll&lt;/span&gt;. To launch, it exploits a DLL Search Order Hijacking vulnerability in the uTorrent torrent client.&lt;/dd&gt;
&lt;/dl&gt;

&lt;p&gt;In email traffic, trojans that download and install other malware were most commonly detected in 2025. Threat actors also distributed various backdoors, exploits, phishing documents, and malicious scripts via email messages.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/02_email_traffic_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/02_email_traffic_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;W97M.DownLoader.2938&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Exploit.CVE-2017-11882.123&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Exploit.CVE-2018-0798.4&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Exploits designed to take advantage of Microsoft Office software vulnerabilities and allow an attacker to run arbitrary code.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;JS.Phishing.684&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;JS.Phishing.745&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious JavaScript script that generates a phishing web page.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;BackDoor.AgentTeslaNET.20&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Spyware designed to steal confidential information. For example, it collects and sends logins and passwords from numerous programs, such as browsers, messengers, email clients, databases, and more, to the attackers. It also steals clipboard contents, implements Keylogging functionality, and can take screenshots.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Win32.Expiro.153&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A file virus that infects Windows executable files. Its main purpose is to steal passwords for various programs.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;JS.DownLoader.1225&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Heuristic detection for ZIP archives containing JavaScripts with suspicious names.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.PackedNET.3223&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Detection for malicious programs protected with a packer.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1413&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for a packed version of the &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malicious app, written in the AutoIt scripting language. This trojan is distributed as part of a group of several malicious applications, including a miner, a backdoor, and a self-propagating module. &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; performs various malicious actions that make it difficult for the main payload to be detected.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Encryption ransomware&lt;/h3&gt;

&lt;p&gt;Compared with 2024, in 2025, Doctor Web’s technical support service registered 35.98% fewer user requests to decrypt files affected by encryption trojans. The dynamics of when those requests were registered is shown in the graph below:&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/03_encoder_requests_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/03_encoder_requests_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common encoders of 2025:&lt;/p&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; &lt;span class="font-normal"&gt;(23.22% of user requests)&lt;/span&gt;&lt;/dt&gt;
    &lt;dd&gt;An encoder trojan also known as Mimic. It uses the &lt;span class="string"&gt;everything.dll&lt;/span&gt; library from the legitimate software Everything, which is designed to instantly locate files on Windows computers.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt; &lt;span class="font-normal"&gt;(3.33% of user requests)&lt;/span&gt;&lt;/dt&gt;
    &lt;dd&gt;An encoder trojan based on the source code of the Conti encoder malware. It encrypts files using the ChaCha20 algorithm. Now that some of the threat actors’ C2 servers have been taken down and the private RSA encryption keys have been disclosed, files affected by some modifications of this trojan can be decrypted.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35067&lt;/b&gt; &lt;span class="font-normal"&gt;(2.50% of user requests)&lt;/span&gt;&lt;/dt&gt;
    &lt;dd&gt;An encoder trojan also known as Macop (&lt;b&gt;Trojan.Encoder.30572&lt;/b&gt; is one of its other variants). It is small in size, about 30-40 Kbytes. This is partially due to the fact that the trojan does not carry third-party cryptographic libraries and uses exclusively CryptoAPI functions for encryption and key generation. It uses the AES-256 algorithm to encrypt files, and the keys themselves are encrypted with RSA-1024.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.41868&lt;/b&gt; &lt;span class="font-normal"&gt;(2.31% of user requests)&lt;/span&gt;&lt;/dt&gt;
    &lt;dd&gt;An encoder whose artifacts indicate that the hacker group C77L was involved in its creation.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.29750&lt;/b&gt; &lt;span class="font-normal"&gt;(2.13% of user requests)&lt;/span&gt;&lt;/dt&gt;
    &lt;dd&gt;A ransomware trojan with multiple versions. Its current modifications use the AES-256+RSA algorithm to encrypt files.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Network fraud&lt;/h3&gt;

&lt;p&gt;In 2025, Doctor Web’s Internet analysts observed an increase in the number of phishing websites created for stealing &lt;i&gt;Telegram&lt;/i&gt; messenger accounts. Malicious actors used various techniques: fake authentication and authorization pages, fake messages from &lt;i&gt;Telegram&lt;/i&gt; support warning of alleged messenger-usage violations requiring account “verification”, etc.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/04_scam_01_telegram_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/04_scam_01_telegram_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a phishing website informing the user that they must verify their Telegram account due to a violation of the platform’s terms of service&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Similar sites were also created to target users of other services, such as gaming platforms, online stores, and so on. The fakes could look like genuine Internet resources and invited potential victims to log into their account. If users fell for the trick, their confidential information ended up in the attackers’ hands.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/05_fake_steam_login_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/05_fake_steam_login_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fake website for the Steam platform displays a phishing form for entering a login and password&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Users once again encountered various types of fraudulent online resources offering all sorts of gifts and bonuses as well as the chance to participate in certain “lucrative promotions”. Commonplace were fake sites of Russian marketplaces where visitors could supposedly participate in a prize drawing. The “winnings” were programmed into the websites, and to “receive” the prizes, victims were required to make a certain payment—for example, supposedly in the form of a tax, then a delivery fee for the goods, and then a fee to insure them. In other variations of this scam, the desired item was allegedly unavailable, but a cash equivalent was offered instead. To “get” the money, the user was also required to make some payments: in the form of fees, insurance, etc. In the end, the victim never received any prize.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/06_fake_market_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/06_fake_market_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a fake marketplace website offering the chance to participate in a “prize drawing”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Variants of similar schemes included fake transport company websites targeting residents of Great Britain. These offered people the chance to participate in a drawing for transport cards that were supposedly timed to a certain event and allowed free use of public transportation services. After a “win”, fraudsters asked victims to provide personal data and pay a small “fee”.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/07_scam_transportcard_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/07_scam_transportcard_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fraudulent website, allegedly belonging to a transportation company, offers people the chance to participate in a transport card drawing&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;All sorts of fraudulent finance-themed sites remained relevant. Once again popular with scammers were web resources offering opportunities to make money by trading on the market using automated systems based on unique algorithms and artificial intelligence technologies. Such sites are created to target users from many countries. They usually request personal information from users wanting to register a “request” or an “account”. Such information ends up in the attackers’ hands—for them to use at their own discretion. Threat actors can resell the data or continue luring potential victims into the fake investment service, demanding that users deposit money into the “trading” account.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/08_scam_appleAI_trade_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/08_scam_appleAI_trade_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;One fraudulent site offering access to an “investment platform” based on AI technologies was allegedly related to the Apple Corporation&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Many of these sites are created using similar templates in the form of a fake chat with a “virtual assistant” or an “employee” of a particular company, and the fraudsters contact potential victims by assuming one of those roles. Users are asked to answer several questions and then provide personal data.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/09_scam_france_ai_trade_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/09_scam_france_ai_trade_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;On one of the websites, scammers offered French users access to non-existent automated trading software called Trader AI, which would allegedly allow them to make money, starting from €3,500&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;One Internet resource advertised an investment service that was supposedly built directly on the basis of the &lt;i&gt;Telegram&lt;/i&gt; messenger. This website promised an income of €10,000 per month, thanks to automated trading of global company shares “directly in the phone’s browser”.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/10_scam_telegram_platform_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/10_scam_telegram_platform_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fraudulent website invites users to join a “Telegram platform” that supposedly trades stocks automatically&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Scammers also offered potential victims a chance to make money using “trading bots” that were supposedly created with the participation of large companies and services such as &lt;i&gt;Telegram&lt;/i&gt;, &lt;i&gt;WhatsApp&lt;/i&gt;, &lt;i&gt;TikTok&lt;/i&gt;, and others.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/11_scam_whatsap_bot_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/11_scam_whatsap_bot_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a website that invited potential victims to use a non-existent trading bot, allegedly related to the WhatsApp messenger&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Throughout 2025, our Internet analysts discovered new fraudulent sites offering users in many countries, including Russia and countries of the CIS (Commonwealth of Independent States) and Europe, opportunities to invest in the oil and gas sector. Typically, on such sites, potential victims are also asked to provide personal information, such as their first and last names, mobile phone number, email address, etc.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/12_scam_kyrgyzgaz_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/12_scam_kyrgyzgaz_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fraudulent site targeting Kyrgyz citizens offers them the opportunity to “make money from oil and gas”, promising large profits&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Our analysts observed the emergence of more fraudulent websites offering “government support” in the form of payments or compensation. For instance, commonly occurring in the Russian Internet segment were fraudulent web resources purporting to be connected to the &lt;i&gt;Gosuslugi (Госуслуги)&lt;/i&gt; portal.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/13_scam_fakegosuslugi_viplati_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/13_scam_fakegosuslugi_viplati_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a fraudulent website purporting to be linked to the Gosuslugi service and promising Russian users stable payments from the government and a major oil and gas company. To “participate” in the “payment program”, victims were asked to provide personal data&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Our experts also noted the emergence of more fake education project websites. These offered users opportunities to take various education and training courses to improve their financial literacy, master a particular profession, etc. To “access” the training, potential victims, as in many other similar schemes, were also asked for personal information.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/14_scam_study_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/14_scam_study_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;One of the fraudulent sites offering users the opportunity to learn English&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Doctor Web’s Internet analysts detected new fraudulent sites selling theater tickets. On such resources, fraudsters offer potential victims discounted tickets for purchase, but after making “payment”, the victims do not receive them.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/15_fake_bilet_theater_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/15_fake_bilet_theater_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a fraudulent website selling non-existent theater tickets&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;In addition, new fake websites for private cinemas were also common. As in the case with the theater tickets, scammers offer potential victims movie tickets for purchase, but the victims end up handing over their money to the fraudsters.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_common/16_fake_cinema_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_common/16_fake_cinema_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The fake site of a private cinemaв&lt;/em&gt;&lt;/p&gt;

&lt;h3&gt;Mobile devices&lt;/h3&gt;

&lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, in 2025, users were most likely to encounter the ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;  and also &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; programs, which, instead of providing the declared functionality, can load various websites, including fraudulent and malicious ones. &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; trojans were more active. These are multifunctional threats that cybercriminals embed into the firmware of Android devices. Moreover, the number of &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojan attacks increased. At the same time, &lt;b&gt;Android.SpyMax&lt;/b&gt; banking trojans were less active.&lt;/p&gt;

&lt;p&gt;Last year, malware creators continued using various techniques to protect their malicious Android apps. One method involved converting DEX code to C code (also known as DCC).&lt;/p&gt;

&lt;p&gt;The most common unwanted apps were &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt; programs. These offer users virtual rewards for completing various tasks and promise them that they can convert these rewards into real money. But, in reality, these apps do not have such an option. In addition, the apps &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; were also frequently detected on protected devices. The former imitates the work of anti-viruses and detects non-existent threats, offering to “cure” infections for users if they purchase the full version of the software. The latter are programs modified via a popular cloud service. When they are being modified, dangerous system permissions and an obfuscated code, whose purpose cannot be controlled, are added to them.&lt;/p&gt;

&lt;p&gt;Programs modified with the NP Manager utility (these programs are detected as &lt;b&gt;Tool.NPMod&lt;/b&gt;) became the most widespread riskware. The NP Manager tool obfuscates the code of the modified programs and allows their digital signature verification to be bypassed. The most active adware apps in 2025 were &lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; programs, third-party &lt;i&gt;WhatsApp&lt;/i&gt; messenger mods that automatically open advertising links when the messenger is in use.&lt;/p&gt;

&lt;p&gt;In 2025, new cases of Android device firmware infections were identified. Our company informed users about one of them in April. Threat actors had preinstalled &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; malware into the system storage area of a number of budget smartphone models and used it to steal cryptocurrency from users. Other attackers managed to implant dangerous &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; trojans into the firmware of some other Android smartphone models. In addition, more cases of Android TV box sets having their firmware infected with new versions of the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; trojan, which our company &lt;a href="https://news.drweb.com/show/?i=14900&amp;lng=en" target="_blank"&gt;discovered&lt;/a&gt; in 2024, have been recorded.&lt;/p&gt;

&lt;p&gt;Over the past year, Doctor Web’s anti-virus laboratory identified a number of dangerous malicious programs. In April, we informed users about the &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; trojan, which was hidden in Alpine Quest mapping software that had been modified by threat actors. &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; targeted Russian military personnel and sent the attackers information about their infected devices: mobile phone numbers and accounts, collected phonebook contacts, geolocation data, and information about the files stored in the devices’ memory. It could also steal certain files when commanded to do so by the attackers. Malicious actors were interested in getting their hands on confidential documents sent via messengers and also in obtaining Alpine Quest location log files.&lt;/p&gt;

&lt;p&gt;In August, our specialists warned about the &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; backdoor, which cybercriminals had disguised as an anti-virus and were distributing via direct messages in messengers. &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; steals confidential information and allows criminals to spy on users. Employees of Russian companies were this backdoor’s main target.&lt;/p&gt;

&lt;p&gt;In October, we informed users about the multi-functional backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;, which our virus analysts discovered in modified versions of the &lt;i&gt;Telegram X&lt;/i&gt; messenger. This malware is also used to steal confidential data, including &lt;i&gt;Telegram&lt;/i&gt; logins and passwords, incoming SMS, chats in the messenger, and clipboard data. At the same time, the backdoor allows attackers to completely control the messenger and the victim’s hacked &lt;i&gt;Telegram&lt;/i&gt; account. To control the backdoor, cybercriminals used both a C2 server and a Redis database—something not seen previously in Android threats. &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; mainly targeted users in Indonesia and Brazil.&lt;/p&gt;

&lt;p&gt;To find out more about the security-threat landscape for mobile devices in 2025, read our &lt;a href="https://news.drweb.com/show/?i=15104&amp;lng=en" target="_blank"&gt;special overview&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;Prospects and possible trends&lt;/h3&gt;

&lt;p&gt;In the New Year 2026, adware trojans that help cybercriminals make illegal profits will likely remain one of the most common threats to users. We can expect that malicious actors will increasingly use banking trojans, which also allow them to enrich themselves.&lt;/p&gt;

&lt;p&gt;Further growth in the popularity of various tools and techniques that help conceal malicious activity may occur. Such techniques include the use of packers and obfuscators, malicious droppers and multi-stage downloaders, and steganography to conceal payloads. In addition, when creating malicious software, cybercriminals, including those with little programming experience, will increasingly resort to the help of AI assistants. As a result, more families of malware will emerge, and the number of threats will increase.&lt;/p&gt;

&lt;p&gt;Government and corporate structures will once again be in the crosshairs of cybercriminals, resulting in further targeted attacks. New cases of firmware infections in Android smartphones, TV box sets and other types of mobile devices are also likely to occur, especially in the budget segment. Online scammers will remain active.&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15104&amp;lng=en</guid><title>Doctor Web’s review of virus activity on mobile devices in 2025</title><link>https://news.drweb.com/show/?i=15104&amp;lng=en&amp;c=10</link><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;January 15, 2026&lt;/b&gt;&lt;/p&gt;

&lt;h3&gt;Overview&lt;/h3&gt;

&lt;p&gt;&lt;newslead&gt;In 2025, Android device users were most likely to encounter ad-displaying trojans and fake apps used for fraudulent purposes.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;As in the previous year, the most common unwanted software programs were those offering game-like tasks to complete in exchange for virtual rewards. Users were promised the ability to convert their rewards into real money, but, in reality, no such opportunities were provided.&lt;/p&gt;

&lt;p&gt;The most active riskware programs were apps modified with the NP Manager tool. This tool obfuscates and protects the code of modified programs so that it becomes more difficult to be analyzed and detected, and also allows digital signature verification to be bypassed once the programs are modified. The most commonly detected adware programs were unofficial WhatsApp messenger mods that automatically open advertising links when the app is in use.&lt;/p&gt;

&lt;p&gt;Last year, new cases of malware being implanted into the firmware of various Android device models were recorded. We informed users about one of them in spring 2025. Cybercriminals had managed to pre-install the &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; trojan on several budget smartphone models and used it to steal their victims’ cryptocurrency.&lt;/p&gt;

&lt;p&gt;Also in spring, our specialists discovered the &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; trojan, which threat actors had embedded into a modified version of Alpine Quest mapping software. This malware targeted Russian military personnel and was used for cyberespionage purposes.&lt;/p&gt;

&lt;p&gt;In late summer, Doctor Web’s anti-virus laboratory informed users about &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt;, a backdoor being distributed via popular messengers. The attackers used it to spy on employees of Russian companies and collect their confidential information.&lt;/p&gt;

&lt;p&gt;Already in the fall, we warned about the dangerous &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; backdoor, which cybercriminals had embedded into modifications of the Telegram X messenger. This malicious program allowed intruders to hack their victims’ Telegram accounts and control the messenger on behalf of the account owners.&lt;/p&gt;

&lt;p&gt;Over the last 12 months, Doctor Web's anti-virus laboratory identified more than 180 threats on Google Play, which have been downloaded over 2,165,000 times. Among them were various trojans that subscribe users to paid services and fake apps used for fraud, as well as new adware and unwanted software.&lt;/p&gt;

&lt;p&gt;In 2025, malware creators continued utilizing various techniques aimed at complicating the analysis of malicious Android programs and evading anti-viruses. Converting DEX code into C code was one of the popular methods employed. In addition, our virus analysts noted that when creating malware, threat actors are using AI assistants that help write their apps’ code.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;Principal trends in 2025&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;Ad-displaying trojans were once again the most common Android threats&lt;/li&gt;
        &lt;li&gt;The NP Manager tool, used to obfuscate the code of modified apps and allow digital signature verification to be bypassed after the apps are modified, has grown in popularity&lt;/li&gt;
        &lt;li&gt;Banking trojans were more active&lt;/li&gt;
        &lt;li&gt;New cases of Android devices with infected firmware have been identified&lt;/li&gt;
        &lt;li&gt;Cybercriminals continued using both new and well-known techniques to protect malware from detection and analysis&lt;/li&gt;
        &lt;li&gt;Malware creators have been actively using AI assistants to write malicious code&lt;/li&gt;
        &lt;li&gt;New threats emerged on Google Play&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;The most notable events of 2025&lt;/h3&gt;

&lt;p&gt;In April 2025, Doctor Web’s experts &lt;a href="https://news.drweb.com/show/?i=15002&amp;lng=en" target="_blank"&gt;uncovered&lt;/a&gt; a large-scale campaign to steal cryptocurrency from Android device owners. Threat actors compromised the supply chain of several Chinese manufacturers and embedded the &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; trojan into the firmware of several budget smartphone models. Malware creators built this trojan into a modified version of WhatsApp messenger. For this, they used the &lt;a href="https://github.com/LSPosed/LSPatch" target="_blank"&gt;LSPatch&lt;/a&gt; instrument, which allows them to alter the apps’ operating logic without changing their code.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; intercepts messages sent and received in the messenger, searches for the addresses of the Tron and Ethereum crypto wallets in them, and replaces them with addresses belonging to the attackers. At the same time, the trojan conceals this substitution, and in such messages, victims are shown the correct wallets. &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; also sends all &lt;em&gt;jpg&lt;/em&gt;, &lt;em&gt;png&lt;/em&gt;, and &lt;em&gt;jpeg&lt;/em&gt; images to threat actors in order to search for saved mnemonic phrases that allow access to crypto wallets. Cybercriminals also embedded &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; in dozens of other apps, including popular crypto wallet programs, QR scanners, and other messengers, like Telegram. These modifications were distributed through malicious websites.&lt;/p&gt;

&lt;p&gt;In 2025, new cases emerged of malware being preinstalled into the system area of Android devices. One malicious group, for example, was able to embed new versions of dangerous &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; trojans into the firmware of a number of budget smartphones. Triada malware poses a threat because it can infect the Zygote system process. This process is directly involved in launching all applications in the system, so Triada trojans can subsequently inject themselves into any application on the device, effectively gaining complete control over it. Threat actors use these trojans to download and install other malware as well as unwanted apps and adware. Moreover, attackers can use them to spy on victims, subscribe users to paid services, and so on. New cases of Android TV box sets having infected firmware were also identified. These cases involved new versions of the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; trojan, which our company &lt;a href="https://news.drweb.com/show/?i=14900&amp;lng=en" target="_blank"&gt;discovered&lt;/a&gt; in 2024. The Vo1d malware is a backdoor that places its component into the system area of infected devices and can covertly download and install third-party software upon receiving attackers’ commands.&lt;/p&gt;

&lt;p&gt;Also in April, our anti-virus laboratory &lt;a href="https://news.drweb.com/show/?i=15006&amp;lng=en" target="_blank"&gt;detected&lt;/a&gt; a campaign to distribute the &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; spyware trojan, targeting Russian military personnel. Threat actors embedded this malware into one of the versions of Alpine Quest mapping software and distributed it via their Telegram channel, which they passed off as the official one. A Russian Android app catalog was another source for its distribution.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/01_Android.Spy.1292.origin_tg_group_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/01_Android.Spy.1292.origin_tg_group_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The Telegram channel that attackers used to distribute a malicious Alpine Quest modification containing &lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; sent a variety of confidential data to the cybercriminals, including mobile phone number and account information, phone book contacts, and the device’s geolocation and the files stored in its memory. The trojan could also steal certain files when commanded to do so by the attackers. Threat actors were interested in confidential documents that users sent via popular messaging apps as well as the Alpine Quest app’s location log file.&lt;/p&gt;

&lt;p&gt;In August, we &lt;a href="https://news.drweb.com/show/?i=15047&amp;lng=en" target="_blank"&gt;reported&lt;/a&gt; on cases of the &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; backdoor being distributed via direct messages in popular messaging apps. The attackers offered potential victims an “anti-virus” that could be installed from the APK file attached to the messages. This file was, in fact, concealed malware. Our anti-virus laboratory discovered the first &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; versions in January 2025 and has been monitoring their activity ever since, which allowed us to quickly identify this campaign.&lt;/p&gt;

&lt;div class="img img-two-v same-height mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/02_Android.Backdoor.916.origin_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/02_Android.Backdoor.916.origin_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/03_Android.Backdoor.916.origin_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/03_Android.Backdoor.916.origin_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt; misleads users by imitating the operation of an anti-virus&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;When installed on an Android device, &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; allows confidential information to be stolen and users to be spied on. For instance, via this backdoor, threat actors can listen to conversations, broadcast from a device’s camera, track geolocation, and steal content from messengers and browsers. Moreover, &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; implements keylogger functionality to intercept entered text, including passwords. According to our experts, the backdoor is used in targeted attacks and is not intended for mass distribution. The primary target for cybercriminals is employees of Russian companies.&lt;/p&gt;

&lt;p&gt;In October, Doctor Web &lt;a href="https://news.drweb.com/show/?i=15076&amp;lng=en" target="_blank"&gt;published&lt;/a&gt; information on the multi-functional backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;, which our malware analysts discovered in modified versions of the Telegram X messenger. The main source of its distribution was via malicious websites to which potential victims are directed through ads in mobile programs. On such sites, users are encouraged to install Telegram X, supposedly to find a partner for conversation and dating. And these Internet resources are primarily targeting residents of Indonesia and Brazil. At the same time, we also detected this backdoor in a number of third-party Android app catalogs.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/04_Android.Backdoor.Baohuo.1.origin_website_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/04_Android.Backdoor.Baohuo.1.origin_website_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;An example of a malicious website from which the trojan version of Telegram X was downloaded&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;One of &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;’s tasks is to steal confidential data. For example, the malicious program steals the login and password from the victim’s Telegram account, the messenger’s chat history, incoming SMS, and the phone book contacts; it can also intercept the clipboard contents. However, threat actors use it not only as a spyware tool. With the help of &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;, they can practically control both the hacked account and the messenger itself, altering its functionality. For instance, the backdoor allows threat actors to covertly add and remove users from Telegram channels, join conversations on their behalf and conceal devices authorized for their account. To perform actions that require changing the app’s operating logic, the Xposed framework is used. Cybercriminals control the backdoor both in the traditional way–via a C2 server–and by sending commands through the Redis database, something not seen previously in other Android malware. The total number of devices infected with &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; exceeded 58,000, while over 3,000 different models of smartphones, tablets, TV box sets, and even cars with Android-based on-board computers, were affected.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/05_Android.Backdoor.Baohuo.1.origin_map_en_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/05_Android.Backdoor.Baohuo.1.origin_map_en_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Countries with the highest number of devices infected with &lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h3&gt;Statistics&lt;/h3&gt;

&lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, the most common Android threats in 2025 were various malicious programs. Users encountered them in 81.11% of cases. These were followed by potentially dangerous apps, whose share was 10.73%. Adware apps, detected in 5.89% of cases, ranked third. Unwanted programs were the least detected threats as they accounted for 2.27% of detections.&lt;/p&gt;

&lt;p&gt;Compared to the previous year, the share of malicious and potentially dangerous programs increased, while the share of unwanted software and adware decreased.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/06_2025_threat_type_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/06_2025_threat_type_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;&lt;b&gt;Malicious programs&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;For several years, ad-displaying trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family have been the most commonly detected malware. In 2025, the situation did not change, although over the course of the last 12 months, their share slightly decreased from 31.95% to 27.42%.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/07_Android.HiddenAds_dynamics_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/07_Android.HiddenAds_dynamics_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;These trojans display intrusive ads in the form of full-screen banners and videos. To make it harder for users to detect and delete them from their infected devices, such malicious programs try to “hide” after installation. For example, they can conceal or substitute their icons in the home screen menu.&lt;/p&gt;

&lt;p&gt;The most active member of this family, accounting for more than a third of detections, was &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt;. This trojan came to the attention of our virus analysts back in 2024, and has been in the lead ever since. &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt; is one of many variants of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1994&lt;/b&gt;, a malicious app known since 2021. Several new versions of the latter, like &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.666.origin&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.673.origin&lt;/b&gt;, were also distributed in 2025. It is possible that over time they may also rise to the top positions, as previously happened with other &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1994&lt;/b&gt; modifications.&lt;/p&gt;

&lt;p&gt;Over the course of 2025, users again encountered Aegis, a subfamily of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;. But the share of such trojans in the total number of times the family was detected significantly decreased—from 17.37% to 3.11%. These trojans can automatically run after installation. Among the most active variants were &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.8.origin&lt;/b&gt;.&lt;/p&gt;

&lt;p&gt;The second most common malware programs were the ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;, whose share increased from 5.38% to 15.64%. &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7859&lt;/b&gt; was the top modification among them. These trojans were followed by &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;—fake programs that cybercriminals use for fraudulent purposes. &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malware can load various websites instead of providing the declared functionality. Such trojans accounted for 10.94% of detections, which is lower than the 2024 figure, when their share was 18.28%. Such a decrease was, in part, due to the fact that the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt; trojan was less active. However, this malicious program still remains the most widespread member of the family. Its main task is to load online casino websites.&lt;/p&gt;

&lt;p&gt;The share of trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.Spy&amp;lng=en"&gt;&lt;b&gt;Android.Spy&lt;/b&gt;&lt;/a&gt; family, which implement a variety of spyware functionality, decreased from 11.52% to 3.09%. At the same time, the activity of banking trojans increased. Their share of the total number of malware detections was 6.94%, compared to 6.29% a year earlier.&lt;/p&gt;

&lt;p&gt;In 2025, the number of software packer detections increased from 5.49% to 6.01%. Threat actors can use such instruments to shield malware from detection and analysis. Malicious apps containing the packer &lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57146&lt;/b&gt; were most commonly detected on protected devices.&lt;/p&gt;

&lt;p&gt;Various malicious WhatsApp messenger mods were also widespread. Among them were modifications (Dr.Web detects them as &lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1812&lt;/b&gt;) that load websites without the victims noticing. Multi-functional trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; family also increased their activity—from 2.74% to 7.48%. Cybercriminals can embed such trojans into the firmware of Android devices.&lt;/p&gt;

&lt;p&gt;The ten malicious programs most commonly detected in 2025:&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/08_2025_malware_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/08_2025_malware_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4214&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.655.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4213&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.666.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Trojan apps designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7859&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan app that displays obnoxious ads. It is a special software module that developers incorporate into applications.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan app that loads the website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1812&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious WhatsApp messenger mods that can covertly load various websites in the background.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57146&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious apps that are packed with a popular commercial code obfuscator.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5847&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for a packer for &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; trojans that is designed to protect them from being detected and analyzed. Threat actors most often use the packer together with the malicious Telegram messenger mods in which these trojans are embedded.&lt;/dd&gt;
&lt;/dl&gt;

&lt;p&gt;&lt;b&gt;Unwanted software&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; apps were once again the most widespread unwanted software of 2025, accounting for 51.96% of detections. These programs offer users a reward for completing certain tasks and supposedly allow them to convert the reward into real money. In reality, no actual payouts are made. Along with &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;, other similar programs, like &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.16&lt;/b&gt;, also became widespread. However, users encountered them much less frequently.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; apps, which imitate the operation of anti-virus software and detect non-existent threats, were in second place with a share of 10.37%. In order for the infection to be “cured”, they encourage users to buy the full version of the software.&lt;/p&gt;

&lt;p&gt;With a share of 6.41%, &lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; apps, which are modified in the CloudInject cloud service, were the third most frequently encountered unwanted software. Variants of them, detected as &lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5&lt;/b&gt;, accounted for 5.08% and came in close behind them, occupying fourth place. Changes to such programs are made directly on a remote server, while access to the service is provided by the utility &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;, which is only a shell for working with it. When apps are modified, dangerous system permissions and an obfuscated code are added to them. Moreover, modders can remotely control the modified apps via the CloudInject service. For example, they can lock the apps and demand that a code be entered to further use them.&lt;/p&gt;

&lt;p&gt;In 2025, there was a slight increase in the number of apps detected that can be utilized to monitor users and control their activity. In the hands of malicious actors, such instruments become spyware. For example, the share of the &lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; app and its variant, &lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;, increased from 2.40% to 2.91% and from 0.21% to 0.97%, respectively. The share of &lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; increased from 2.03% to 2.56%, and its variant &lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt; increased from 0.90% to 1.02%. &lt;b&gt;Program.SnoopPhone.1.origin&lt;/b&gt;'s figure increased from 0.31% to 1.01%.&lt;/p&gt;

&lt;p&gt;The ten unwanted programs most commonly detected in 2025:&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/09_2025_unwanted_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/09_2025_unwanted_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, modders can remotely manage these apps—blocking them, displaying custom dialogs, tracking when other software is being installed or removed from a device, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for a program that allows users to be monitored via their Android devices. Malicious actors can utilize it to track a target device’s location, take photos and video with the camera, eavesdrop via the microphone, record audio, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for various modifications of an application that is designed to record videos and take photos in the background, using built-in Android device cameras. It can operate covertly by allowing notifications about ongoing recordings to be disabled. It also allows an app’s icon and name to be replaced with fake ones. This functionality makes this software potentially dangerous.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Program.SnoopPhone.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An application designed to monitor the activity of Android device owners. It allows intruders to read SMS, collect call information, track device location, and record the surroundings.&lt;/dd&gt;
&lt;/dl&gt;

&lt;p&gt;&lt;b&gt;Riskware&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;In 2025, the most widespread, potentially dangerous software programs were apps modified using NP Manager, a tool that has been designed to modify programs and that contains various modules for obfuscating and protecting the apps’ code. It is also used to bypass digital signature verification after changes have been made to the apps. Threat actors often use this tool to protect malicious programs in order to make it harder for anti-viruses to detect them. Compared to 2024, the share of such apps increased from 24.52% to 53.59%, and they accounted for more than half of the riskware detections. Most commonly detected on protected devices were variants &lt;b&gt;Tool.NPMod.3&lt;/b&gt; (32.85%), &lt;b&gt;Tool.NPMod.1&lt;/b&gt; (12.61%), &lt;b&gt;Tool.NPMod.1.origin&lt;/b&gt; (3.02%), and &lt;b&gt;Tool.NPMod.4&lt;/b&gt; (2.31%).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt; programs—frameworks for developing Android apps in the Lua programming language—were detected more frequently. Their share is now 8.11%, up from 3.93%. Such frameworks require many system permissions, including permission to use the Accessibility Service. Programs created with their help are based on Lua scripts that are encrypted and then decrypted right before execution. Such scripts can potentially be malicious. The share of apps modified with &lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt; increased from 8.16% to 10.06%. This utility modifies installed apps by downloading specially prepared scripts from the Internet.&lt;/p&gt;

&lt;p&gt;At the same time, the share of &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt; utilities, which allow Android apps to be launched without installing them, decreased from 33.10% to 10.55%. The most commonly detected variants of this family in 2025 were &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14.origin&lt;/b&gt; (4.66%), &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.6.origin&lt;/b&gt; (2.07%), and &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7.origin&lt;/b&gt; (1.88%). In addition, the share of the programs protected with the software packer &lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; decreased from 13.17% to 2.58%.&lt;/p&gt;

&lt;p&gt;The ten riskware apps most commonly detected on protected Android devices in 2025:&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/10_2025_riskware_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/10_2025_riskware_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.3&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.4&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. This tool contains modules for obfuscating and protecting the apps’ code as well as for bypassing their digital signature verification after they are modified. The obfuscation it adds is often used in malware to make it more difficult to detect and analyze.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for some potentially dangerous versions of a specialized framework for developing Android software in the Lua scripting language. The main logic of Lua-based apps resides in the corresponding scripts that are encrypted and decrypted by the interpreter before execution. By default, this framework often requests access to a large number of system permissions in order to operate, including permission to use theAccessibility Service in Android. As a result, the Lua scripts that it executes can potentially perform various malicious actions in accordance with the acquired permissions.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads from the Internet specially prepared scripts, which can be crafted and added to the common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A riskware platform that allows applications to launch APK files without installing them. It creates a virtual runtime environment in the context of the apps in which they are integrated. The APK files, launched with the help of this platform, can operate as if they are part of such programs and can also obtain the same permissions.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A packer tool designed to protect Android applications from unauthorized modification and reverse engineering. This tool is not malicious in itself, but it can be used to protect both harmless and malicious software.&lt;/dd&gt;
&lt;/dl&gt;

&lt;p&gt;&lt;b&gt;Adware&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;Third-party WhatsApp messenger mods, detected as &lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;, topped the list of adware programs detected in 2025. Such modifications are given the functionality needed to open links when the messenger is being worked with. These links redirect users to advertised websites. Compared to 2024, &lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;’s share of all adware apps detected on protected devices decreased from 47.45% to 26.90%.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt; modules, which are embedded into Android apps and display notifications containing ads, ranked second, increasing their share from 14.76% to 26.19%. Third place, with 8.88%, was occupied by members of the &lt;b&gt;Adware.Basement&lt;/b&gt; family. Their share remained almost the same, compared to the previous year. Such programs can display ads that lead to malicious websites.&lt;/p&gt;

&lt;p&gt;Also prevalent were such adware families as &lt;a href="https://vms.drweb.com/search/?q=Adware.Airpush&amp;lng=en"&gt;&lt;b&gt;Adware.Airpush&lt;/b&gt;&lt;/a&gt; (their detection rate rose from 4.35% to 5.14%), &lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt; (an increase from 3.29% to 6.21% was observed), &lt;b&gt;Adware.Youmi&lt;/b&gt; (an increase from 1.62% to 2.91% was observed), as well as &lt;a href="https://vms.drweb.com/search/?q=Adware.Leadbolt&amp;lng=en"&gt;&lt;b&gt;Adware.Leadbolt&lt;/b&gt;&lt;/a&gt; (an increase from 2.26% to 2.41% was observed) and &lt;b&gt;Adware.Jiubang&lt;/b&gt; (an increase from 1.70% to 2.38% was observed).&lt;/p&gt;

&lt;p&gt;The ten most widespread adware programs detected on protected Android devices in 2025:&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/11_2025_adware_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/11_2025_adware_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for some modified versions (mods) of the &lt;i&gt;WhatsApp&lt;/i&gt; messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21846&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.39.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Basement.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;These apps display unwanted ads that often lead to malicious and fraudulent websites. They share a common code base with &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; unwanted applications.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An adware module that malicious actors embed into cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display obnoxious ads.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Airpush&amp;lng=en"&gt;&lt;b&gt;Adware.Airpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware modules that can be built into Android apps and display various ads. Depending on the modules’ version and modification, these can be notifications containing ads, pop-up windows or banners. Malicious actors often use these modules to distribute malware by offering their potential victims diverse software for installation. Moreover, such modules collect personal information and send it to a remote server.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Youmi&amp;lng=en"&gt;&lt;b&gt;Adware.Youmi&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for an unwanted adware module that adds advertising shortcuts onto the Android OS home screen.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Jiubang.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Unwanted ad-displaying software for Android devices that displays a banner showing recommended programs when applications are being installed.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Inmobi&amp;lng=en"&gt;&lt;b&gt;Adware.Inmobi&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for some versions of the Inmobi adware SDK. These are capable of making phone calls and adding event entries into an Android device’s calendar.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Threats on Google Play&lt;/h3&gt;

&lt;p&gt;In 2025, Doctor Web’s anti-virus laboratory discovered over 180 malicious, unwanted, and adware apps, which have been installed a combined total of at least 2,165,040 times. Among them were various modifications of the trojans &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4213&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4215&lt;/b&gt;, which concealed their presence on infected devices and displayed ads on top of the system interface and other programs. These trojans were distributed under the guise of image-editing tools, camera apps for taking photos and videos, and some other software.&lt;/p&gt;

&lt;div class="img img-two mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/12_Android.HiddenAds.4215_2025.png" class="preview"&gt;
    &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/12_Android.HiddenAds.4215_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/13_Android.HiddenAds.4213_2025.png" class="preview"&gt;
    &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/13_Android.HiddenAds.4213_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The programs Time Shift Cam and Fusion Collage Editor were adware trojans from the &lt;b&gt;Android.HiddenAds&lt;/b&gt; family&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Cybercriminals distributed the cryptocurrency-stealing trojans &lt;a href="https://vms.drweb.com/search/?q=Android.CoinSteal&amp;lng=en"&gt;&lt;b&gt;Android.CoinSteal&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.202&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.CoinSteal&amp;lng=en"&gt;&lt;b&gt;Android.CoinSteal&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.203&lt;/b&gt;, and &lt;a href="https://vms.drweb.com/search/?q=Android.CoinSteal&amp;lng=en"&gt;&lt;b&gt;Android.CoinSteal&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.206&lt;/b&gt;, disguising them as official software from the Dydx crypto exchange and from the blockchain platforms Raydium and Aerodrome Finance.&lt;/p&gt;

&lt;div class="img img-two mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/14_Android.CoinSteal.203_2025.png" class="preview"&gt;
    &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/14_Android.CoinSteal.203_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/15_Android.CoinSteal.202_2025.png" class="preview"&gt;
    &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/15_Android.CoinSteal.202_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The programs Raydium and Dydx Exchange were, in fact, trojans for stealing cryptocurrency&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;These malicious apps asked users to enter a mnemonic phrase—supposedly for connecting to a crypto wallet. But the information provided was actually sent to the attackers. To further confuse potential victims, the forms for entering mnemonic phrases could be disguised as requests from other crypto platforms.&lt;/p&gt;

&lt;div class="img img-two-v same-height mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/16_seed_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/16_seed_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/17_seed_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/17_seed_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;&lt;b&gt;Android.CoinSteal.206&lt;/b&gt; displays a phishing form, supposedly from the crypto exchange PancakeSwap, that asks users to enter the mnemonic phrase for accessing their crypto wallet&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Throughout the year, our specialists uncovered over 80 malicious &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; programs that subscribe users to paid services. They were disguised as various software, including messengers, photography apps, system tools, image-editing programs, and apps for working with documents.&lt;/p&gt;

&lt;div class="img img-two-v same-height mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/18_Android.Joker.2494_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/18_Android.Joker.2494_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/19_Android.Joker.2496_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/19_Android.Joker.2496_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Examples of the discovered &lt;b&gt;Android.Joker&lt;/b&gt; trojans. &lt;b&gt;Android.Joker.2494&lt;/b&gt; was distributed as the messenger File Text Messages, and &lt;b&gt;Android.Joker.2496&lt;/b&gt;–as the utility Useful Cleaner for optimizing a smartphone’s operation&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Cybercriminals again distributed all sorts of &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs, using them in a number of fraudulent schemes. The programs’ main task is to load target websites. Threat actors passed off some of these trojans as finance-related software. Such apps loaded phishing websites as well as fraudulent sites that were supposedly related to investments and online earnings. Other fake apps from this family were distributed as games and, under certain conditions, could load online casino and bookmaker websites. We discovered over 100 such programs on Google Play.&lt;/p&gt;

&lt;div class="img img-two-v same-height mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/20_Android.FakeApp.1840_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/20_Android.FakeApp.1840_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/21_Android.FakeApp.1863_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/21_Android.FakeApp.1863_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Examples of &lt;b&gt;Android.FakeApp&lt;/b&gt; fake programs. The trojan &lt;b&gt;Android.FakeApp.1863&lt;/b&gt; was hidden in the TPAO app and targeted Turkish users, offering them the opportunity to manage deposits and income. The trojan &lt;b&gt;Android.FakeApp.1840&lt;/b&gt; was distributed as the game Pino Bounce and could load an online casino site&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Doctor Web’s virus analysts also discovered new adware. Dubbed &lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21912&lt;/b&gt;, this program was hidden in the Coin News Promax app with information about cryptocurrencies. &lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21912&lt;/b&gt; displays notifications which, when clicked, load into WebView the link specified by the С2 server.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/22_Adware.Adpush.21912_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/22_Adware.Adpush.21912_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The Coin News Promax app from Google Play was the adware program &lt;b&gt;Adware.Adpush.21912&lt;/b&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;In addition, our specialists found &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.16&lt;/b&gt;, an unwanted app distributed as a program called &lt;i&gt;Zeus Jackpot Mania&lt;/i&gt;. In this app, users, in a game-like style, obtained virtual rewards that allegedly could be converted into real money and withdrawn from the program.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/23_Program.FakeMoney.16_1_Zeus Jackpot Mania_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/23_Program.FakeMoney.16_1_Zeus Jackpot Mania_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The Zeus Jackpot Mania app was the unwanted software &lt;b&gt;Program.FakeMoney.16&lt;/b&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;To “withdraw” the money, users were asked to submit some information to the program, but they did not receive any payouts.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/24_Program.FakeMoney.16_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/24_Program.FakeMoney.16_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;&lt;b&gt;Program.FakeMoney.16&lt;/b&gt; asks the user to provide their full name and information about their bank account&lt;/em&gt;&lt;/p&gt;

&lt;h3&gt;Banking trojans&lt;/h3&gt;

&lt;p&gt;According to the detection statistics provided by Dr.Web Security Space for mobile devices, in 2025, the share of banking trojans, out of the total number of malicious apps registered, was 6.94%, which is slightly more than the 6.29% figure from the year before. During the first three months, banking trojan activity remained at approximately the same level, but at the beginning of the second quarter, it significantly increased. After that, it began to gradually decline, reaching the annual minimum in July. From August onwards, the number of detections began to grow again, peaking in October. At the end of the year, another decline was observed.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/26_banker_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/26_banker_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;In 2025, threat actors continued using a number of popular banking trojan families to carry out their attacks. Among the most active were the malicious apps &lt;b&gt;Android.Banker.Mamont&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot.Coper&amp;lng=en" target="_blank"&gt;Coper&lt;/a&gt;, &lt;b&gt;Android.BankBot.Ermac&lt;/b&gt;, and some others. Moreover, new versions of &lt;a href="https://vms.drweb.com/virus/?i=29204494&amp;lng=en" target="_blank"&gt;NGate&lt;/a&gt; trojans were found. These trojans use NFC technology to steal money. They send data from the NFC chip of infected devices to the attackers, allowing fraudsters to withdraw money from victims’ accounts at ATMs or make purchases using contactless payment without further user involvement. Among the most active were modifications like &lt;b&gt;Android.Banker.NGate.8&lt;/b&gt;, &lt;b&gt;Android.Banker.NGate.17&lt;/b&gt;, and &lt;b&gt;Android.Banker.NGate.5.origin&lt;/b&gt;.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Android.SpyMax&lt;/b&gt;, malicious apps with spyware functionality, continued to be distributed. These trojans are based on leaked source code of the SpyNote RAT trojan. Cybercriminals use them in a variety of scenarios, including as banking trojans. At the same time, compared to 2024, the activity of &lt;b&gt;Android.SpyMax&lt;/b&gt; malware decreased. These trojans accounted for 12.35% of banking trojan detections, compared to 32.04% the year before.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/27_Android.SpyMax_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2026/january/review_mobile/27_Android.SpyMax_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;In 2025, Russian users were most likely to encounter various banking trojans belonging to the extensive Mamont family, as classified by Doctor Web (e.g., &lt;b&gt;Android.Banker.790.origin&lt;/b&gt;, &lt;b&gt;Android.Banker.Mamont.3.origin&lt;/b&gt;, and &lt;b&gt;Android.Banker.Mamont.28.origin&lt;/b&gt;). This family includes different malicious apps that malware creators continue to actively modify and develop. These apps intercept SMS containing one-time codes from credit organizations and steal bank card data and other confidential information.&lt;/p&gt;

&lt;p&gt;Throughout the year, our experts observed the activity of banking trojans targeting users from Uzbekistan and neighboring countries, including Armenia, Azerbaijan, and Kyrgyzstan. Trojans like &lt;b&gt;Android.Banker.951.origin&lt;/b&gt;, &lt;b&gt;Android.Banker.881.origin&lt;/b&gt;, and &lt;b&gt;Android.Banker.963.origin&lt;/b&gt; were most frequently detected on protected devices. They hijack verification codes from SMS coming from banks. Cybercriminals constantly modify such trojans to make it harder for them to be detected. Turkish users were most often attacked by the &lt;b&gt;Android.BankBot.Coper.12.origin&lt;/b&gt;, &lt;b&gt;Android.Banker.5685&lt;/b&gt;, and &lt;b&gt;Android.Banker.864.origin&lt;/b&gt; banking trojans, which are also capable of stealing the contents of SMS.&lt;/p&gt;

&lt;p&gt;At the same time, Iranian residents encountered the trojans &lt;b&gt;Android.BankBot.1190.origin&lt;/b&gt; and &lt;b&gt;Android.BankBot.1191.origin&lt;/b&gt; and modifications of them. These malicious programs steal banking information from SMS, finding data about the victim’s bank cards, accounts, available funds, completed transactions, etc., and then send it to the attackers. They also collect contact information from the phone book and can send SMS on the attackers’ command.&lt;/p&gt;

&lt;p&gt;Users from many Southeast Asian and the Asia-Pacific region countries, including Indonesia and South Korea, were attacked by the &lt;b&gt;Android.BankBot.Remo.1.origin&lt;/b&gt; trojan. This malicious program utilizes the Accessibility Services of the Android OS to steal data from bank software and crypto wallets installed on infected devices. In addition to the Remo trojan, users in South Korea also encountered such trojans as &lt;b&gt;Android.BankBot.15140&lt;/b&gt;, &lt;b&gt;Android.BankBot.Ermac.6.origin&lt;/b&gt;, and GoldDigger (&lt;b&gt;Android.BankBot.GoldDigger.9&lt;/b&gt;, &lt;b&gt;Android.BankBot.GoldDigger.11&lt;/b&gt;).&lt;/p&gt;

&lt;p&gt;The GoldDigger malware was also used to attack Indonesian and Thai users. And the banking trojan &lt;b&gt;Android.BankBot.Gigabud.1.origin&lt;/b&gt; was used against customers of credit organizations in Indonesia and Malaysia. At the same time, threat actors continued to use MoqHao trojans in attacks on Japanese audiences. The most widely used MoqHao modifications included &lt;b&gt;Android.Banker.672.origin&lt;/b&gt;, &lt;b&gt;Android.Banker.5063&lt;/b&gt;, &lt;b&gt;Android.Banker.740.origin&lt;/b&gt;, and a number of others.&lt;/p&gt;

&lt;p&gt;One banking trojans targeting users in India was &lt;b&gt;Android.Banker.6209&lt;/b&gt;. This trojan imitates the appearance of genuine banking software to steal victims’ data, including their names, bank card numbers and CVV security codes. In addition, RewardSteal banking trojans, such as &lt;b&gt;Android.Banker.814.origin&lt;/b&gt;, &lt;b&gt;Android.Banker.913.origin&lt;/b&gt;, and &lt;b&gt;Android.Banker.5132&lt;/b&gt;, continued to be active. To steal banking data, they are camouflaged as software that appears to be backed by large Indian credit organizations, for example, ICICI, SBI, Axis, and PM Kisan.&lt;/p&gt;

&lt;p&gt;Android device owners in Brazil were most frequently attacked by &lt;b&gt;Android.BankBot.1183.origin&lt;/b&gt; malicious apps and some members of the NGate family, like &lt;b&gt;Android.Banker.NGate.8&lt;/b&gt;, &lt;b&gt;Android.Banker.NGate.9&lt;/b&gt;, and &lt;b&gt;Android.Banker.NGate.14&lt;/b&gt;.&lt;/p&gt;

&lt;p&gt;In 2025, malware creators continued utilizing different techniques to protect Android banking trojans from analysis and detection. For instance, various code obfuscation and concealment methods were popular, such as DEX to C (which involves converting executable DEX code into C programming language code). Another widespread solution that was employed involved obfuscating malicious apps with the NP Manager utility.&lt;/p&gt;

&lt;p&gt;Techniques involving manipulating the format of ZIP archives, which are essentially APK files of Android apps, remain popular. These include manipulating the &lt;span class="string"&gt;compression method&lt;/span&gt; and &lt;span class="string"&gt;compressed size&lt;/span&gt; fields in the header structure of the local file inside the APK, and also using incorrect disk data in ECDR and CD records. We covered these techniques in more detail in our &lt;a href="https://news.drweb.com/show/review/?lng=en&amp;i=14970#troj" target="_blank"&gt;previous review&lt;/a&gt;, in the section dedicated to banking trojans. After such manipulations, trojan apps remain fully functional, but many static analysis instruments perceive them as damaged and are unable to process them correctly.&lt;/p&gt;

&lt;p&gt;Malware creators have increased their use of dropper programs to conceal their main payload in order to, for example, bypass the internal protection on Google Play. Cybercriminals are also using AI assistants when writing banking trojan code, which simplifies the malware-development process and leads to the emergence of new families. Moreover, threat actors are increasingly using Telegram bots to control banking trojans and exfiltrate data from infected devices.&lt;/p&gt;

&lt;h3&gt;Prospects and trends&lt;/h3&gt;

&lt;p&gt;In 2025, we observed high activity on the part of ad-displaying trojans, which remain the most common threats targeting the Android OS. Various fake programs used for fraudulent purposes, including phishing and money theft, were also widespread again. In addition, the number of attacks involving banking trojans continued to increase. All of these malicious apps are a source of illegal income for cybercriminals, which is why their popularity remains high. In 2026, they are highly likely to once again be one of the most popular money-making tools for cybercriminals. Meanwhile, malware creators are increasingly using Telegram bots to control banking trojans. This trend is likely to continue.&lt;/p&gt;

&lt;p&gt;The emergence of &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; malware and new versions of the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; trojans in the firmware of smartphones and TV box sets indicates the continued interest of attackers in distributing malware in ways that significantly complicate its detection. It is likely that this trend will continue in the new year and that we will see more cases of malicious programs being pre-installed on smartphones, TV box sets, and other types of Android devices.&lt;/p&gt;

&lt;p&gt;We should also expect that more sophisticated malicious apps, ones capable of performing a wider range of tasks, will emerge. These could be yet other backdoors and various spyware trojans. Moreover, malware creators will likely use official app catalogs, including Google Play, to distribute malware and unwanted software.&lt;/p&gt;

&lt;p&gt;Threat actors will also continue implementing various protection methods for the instruments they create. They will also use AI assistants more often when writing code, which will lead to the emergence of more new families.&lt;/p&gt;

&lt;p&gt;Doctor Web monitors the threat landscape in the mobile segment and promptly responds to emerging challenges. We recommend to Android users that they install Dr.Web Security Space for mobile devices to protect themselves from malicious and other dangerous programs.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/2025%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank"&gt;Indicators of compromise&lt;/a&gt;&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15101&amp;lng=en</guid><title>Doctor Web’s Q4 2025 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=15101&amp;lng=en&amp;c=10</link><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;January 12, 2026&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, the trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;, which display intrusive ads, were again the most widespread Android threats. At the same time, their activity decreased, and they were detected less frequently on protected devices by 43.24% and 18.06%, respectively. These malicious programs were followed by trojans from the &lt;b&gt;Android.Siggen&lt;/b&gt; family, which includes malware whose functionality varies. They were also detected less often—by 27.47%.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;At the same time, noticeable banking trojan activity was observed, with users encountering them 65.52% more frequently. This growth was largely due to members of the &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; family. Such malicious programs intercept SMS with one-time codes for confirming banking transactions and can also imitate the appearance of legitimate bank software and display phishing windows.&lt;/p&gt;

&lt;p&gt;Android apps modified with the CloudInject cloud service (Dr.Web anti-virus detects them as &lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;) were the most widespread unwanted software. CloudInject adds dangerous system permissions to the apps and obfuscated code, while the purpose of that code cannot be controlled. &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt; (fake anti-viruses) and &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt; (apps) were also commonly found on protected devices. The former detect non-existing threats and ask users to purchase the full version to “cure” the infection, while the latter allegedly allow users to make money by completing various tasks.&lt;/p&gt;

&lt;p&gt;The most widespread riskware programs in Q4 were &lt;b&gt;Tool.NPMod&lt;/b&gt; apps, programs modified using the NP Manager utility. This tool obfuscates the code of the modified apps and adds a special module to them that allows digital signature verification to be bypassed once applications are modified. Among the adware detections, members of the &lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt; family retained their lead. These are special software modules that developers integrate into apps to display notifications containing advertisements.&lt;/p&gt;

&lt;p&gt;In October, our specialists &lt;a href="https://news.drweb.com/show/?i=15076&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about the dangerous backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;. Threat actors embedded it into unofficial Telegram X messenger modifications and distributed it through malicious websites and third-party Android app catalogs. This malware steals logins and passwords for Telegram accounts as well as other confidential data. Moreover, with its help, threat actors can practically control the victim’s account and covertly perform various actions in the messenger on their behalf. For example, the attackers can join Telegram channels and leave them, conceal new authorized devices, conceal certain messages, etc. Malicious actors use several control mechanisms to operate &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;. One of them is the Redis database, which has not been seen previously in Android threats. In total, this backdoor infected around 58,000 devices, including about 3,000 different models of smartphones, tablets, TB box sets, and cars with on-board Android-based computers.&lt;/p&gt;

&lt;p&gt;Over the past quarter, Doctor Web’s anti-virus laboratory discovered new malware on Google Play. Among these programs were &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojans, which subscribe victims to paid services, and various &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs, which are used in fraudulent schemes. They had at least 263,000 downloads combined.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;PRINCIPAL TRENDS OF Q4 2025&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;Ad-displaying trojans remain the most widespread Android threats&lt;/li&gt;
        &lt;li&gt;The number of banking trojan attacks increased&lt;/li&gt;
        &lt;li&gt;Malicious actors distributed the dangerous backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;, which was built into Telegram X messenger modifications&lt;/li&gt;
        &lt;li&gt;More malicious programs emerged on Google Play&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h3&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/01_malware_q4_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/01_malware_q4_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7859&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan app that displays obnoxious ads. It is a special software module that developers incorporate into applications.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan app that loads the website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1812&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious &lt;em&gt;WhatsApp&lt;/em&gt; messenger mods that can covertly load various websites in the background.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Android.Packed.57.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for an obfuscator that is used to protect apps, including malicious ones (for example, some &lt;b&gt;Android.SpyMax&lt;/b&gt; banking trojan versions).&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5847&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for a packer for &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; trojans that is designed to protect them from being detected and analyzed. Threat actors most often use the packer together with the malicious Telegram messenger mods in which these trojans are embedded.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/02_unwanted_q_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/02_unwanted_q_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, modders can remotely manage these apps—blocking them, displaying custom dialogs, tracking when other software is being installed or removed from a device, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Program.SnoopPhone.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;An application designed to monitor the activity of Android device owners. It allows intruders to read SMS, collect call information, track device location, and record the surroundings.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/03_riskware_q4_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/03_riskware_q4_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.3&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. A special module is embedded in such apps, and it allows them to bypass digital signature verification once they have been modified.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads specially prepared scripts from the Internet, which can be crafted and added to a shared database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for some potentially dangerous versions of a specialized framework for developing Android software based on the Lua scripting language. The main logic of Lua-based apps resides in corresponding scripts that are encrypted and decrypted by the interpreter upon execution. By default, this framework often requests access to a large number of system permissions in order to operate. As a result, the Lua scripts that it executes can potentially perform various malicious actions in accordance with the acquired permissions.&lt;/dd&gt;
&lt;/dl&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/04_adware_q4_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/04_adware_q4_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21846&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Bastion.1.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for optimization programs that periodically create notifications with misleading messages about allegedly low storage and “system errors” in order to display ads during the “optimization”.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Airpush.7.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware modules that can be built into Android apps and display various ads. Depending on the modules’ version and modification, these can be notifications containing ads, pop-up windows or banners. Malicious actors often use these modules to distribute malware by offering their potential victims diverse software for installation. Moreover, such modules collect personal information and send it to a remote server.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for some modified versions (mods) of the &lt;em&gt;WhatsApp&lt;/em&gt; messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Threats on Google Play&lt;/h3&gt;

&lt;p&gt;Over the course of Q4 2025, Doctor Web’s virus analysts detected over 20 &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; malicious programs on Google Play. These are designed to subscribe users to paid services; Threat actors camouflaged them as various software: messengers, system optimization tools, image-editing apps, and apps that allow users to watch movies.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/05_Android.Joker_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/05_Android.Joker_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Examples of &lt;b&gt;Android.Joker&lt;/b&gt; malicious apps that were detected. &lt;b&gt;Android.Joker.2496&lt;/b&gt; masqueraded as Useful Cleaner, a tool for clearing out “junk” from the phone, and one of the &lt;b&gt;Android.Joker.2495&lt;/b&gt; modifications was passed off as the movie player Reel Drama&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Our experts also discovered several new fake programs from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; family. As before, some of them were distributed as financial apps and were designed to load fraudulent websites. Other fakes were passed off as games. Under certain conditions (for instance, if a user’s IP address met the attackers’ requirements), they could load bookmaker and online casino sites.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/06_Android.FakeApp.1910_1_Chicken_Road_Fun.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_mobile_q4/06_Android.FakeApp.1910_1_Chicken_Road_Fun.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The Chicken Road Fun game was the fake app &lt;b&gt;Android.FakeApp.1910&lt;/b&gt;. It could open an online casino website instead of providing the declared functionality&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q4%202025%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank"&gt;Indicators of compromise&lt;/a&gt;&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15099&amp;lng=en</guid><title>Doctor Web’s Q4 2025 virus activity review</title><link>https://news.drweb.com/show/?i=15099&amp;lng=en&amp;c=10</link><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;January 12 2026&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;newslead&gt;According to statistics collected by the Dr.Web anti-virus, the total number of threats detected in the fourth quarter of 2025 increased by 16.05%, compared to the third quarter. The number of unique threats decreased by 1.13%. Most common were unwanted adware apps, malicious scripts, and various malicious programs, including downloaders and ad-displaying trojans.&lt;/newslead&gt;&lt;/p&gt;

&lt;p&gt;In email traffic, trojan apps—like downloaders, password stealers, and droppers—were most frequently detected. Moreover, exploits, backdoors, and various malicious scripts were also distributed via email.&lt;/p&gt;

&lt;p&gt;Users whose files were affected by encoder trojans had mostly encountered &lt;b&gt;Trojan.Encoder.35534&lt;/b&gt;, &lt;b&gt;Trojan.Encoder.41868&lt;/b&gt;, and &lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.29750&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.29750&lt;/b&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;In October, we &lt;a href="https://news.drweb.com/show/?i=15076&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about the &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; backdoor, which cybercriminals were distributing in modified versions of the Telegram X messenger. This malicious program steals logins and passwords for Telegram accounts as well as other sensitive data. Using this backdoor, threat actors can control the victims’ hacked accounts and also gain full control over the messenger itself, performing various actions on behalf of users.&lt;/p&gt;

&lt;p&gt;In November, our anti-virus laboratory released a &lt;a href="https://news.drweb.com/show/?i=15078&amp;lng=en" target="_blank"&gt;study&lt;/a&gt; of a targeted attack carried out by the Cavalry Werewolf hacker group on a Russian state institution. During the examination, Doctor Web’s experts identified many of the malicious instruments being used by the threat actors, including open-source tools that cybercriminals utilize in their campaigns. Our specialists also studied the features of this hacker group and the actions it typically takes in compromised networks.&lt;/p&gt;

&lt;p&gt;Already in December, we &lt;a href="https://news.drweb.com/show/?i=15090&amp;lng=en" target="_blank"&gt;published&lt;/a&gt; information about the unique trojan dubbed &lt;a href="https://vms.drweb.com/search/?q=Trojan.ChimeraWire&amp;lng=en"&gt;&lt;b&gt;Trojan.ChimeraWire&lt;/b&gt;&lt;/a&gt;, which artificially increases the popularity of websites. To do so, it pretends to be a human so that its actions are not blocked by the anti-bot protection of the sites. The malicious program automatically searches target websites in search engines, opens them, and performs clicks on their webpages in accordance with the parameters received from the malicious actors. &lt;a href="https://vms.drweb.com/search/?q=Trojan.ChimeraWire&amp;lng=en"&gt;&lt;b&gt;Trojan.ChimeraWire&lt;/b&gt;&lt;/a&gt; infects computers with the help of several malicious programs that exploit DLL Search Order Hijacking class vulnerabilities and also utilize anti-debugging techniques to avoid detection.&lt;/p&gt;

&lt;p&gt;Over the course of Q4, Doctor Web’s Internet analysts identified new fraudulent websites that promised potential victims quick and easy money. More phishing sites and fake marketplace Internet resources were also found.&lt;/p&gt;

&lt;p&gt;Our specialists uncovered yet more malicious apps on Google Play. Among them were &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojans, which subscribe Android device owners to paid services, as well as &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious apps, which are used by cybercriminals to implement various fraudulent schemes. At the same time, Dr.Web Security Space for mobile devices detection statistics revealed that Android banking trojans increased their activity.&lt;/p&gt;

&lt;div class="colorful"&gt;
    &lt;h3&gt;Principal trends in Q4 2025&lt;/h3&gt;
    &lt;ul class="list"&gt;
        &lt;li&gt;The number of threats detected on protected devices increased&lt;/li&gt;
        &lt;li&gt;The number of unique threats used in attacks decreased&lt;/li&gt;
        &lt;li&gt;More users requested help to decrypt files affected by encoder trojans&lt;/li&gt;
        &lt;li&gt;Banking trojans targeting Android device owners were more active&lt;/li&gt;
        &lt;li&gt;Threat actors distributed the &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; backdoor, which hacks the Telegram accounts of Android users&lt;/li&gt;
        &lt;li&gt;New malicious apps emerged on Google Play&lt;/li&gt;
    &lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;According to Doctor Web’s statistics service&lt;/h3&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/01_stat_q4_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/01_stat_q4_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common threats in Q4 2025:&lt;/p&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Siggen31.34463&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A trojan written in the Go programming language and designed to download various miner trojans and adware into infected systems. This malware is a DLL file located at &lt;span class="string"&gt;%appdata%\utorrent\lib.dll&lt;/span&gt;. To launch, it exploits a DLL Search Order Hijacking vulnerability in the uTorrent torrent client.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Downware.20091&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;VBS.KeySender.7&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious script that, in an infinite loop, searches for windows containing the text &lt;span class="string"&gt;mode extensions&lt;/span&gt;, &lt;span class="string"&gt;разработчика&lt;/span&gt;, and &lt;span class="string"&gt;розробника&lt;/span&gt; and sends them an Escape key press event, forcibly closing them.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.BPlug.4268&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for a malicious component of the WinSafe browser extension. This component is a JavaScript file that displays intrusive ads in browsers.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Siggen.33379&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A fake Adblock Plus browser ad blocker that is installed on the system by other malware to display advertisements.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Statistics for malware discovered in email traffic&lt;/h3&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/02_mail_traffic_q4_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/02_mail_traffic_q4_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common threats in email traffic in Q4 2025:&lt;/p&gt;

&lt;dl&gt;
    &lt;dt&gt;&lt;b&gt;W97M.DownLoader.2938&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Exploit.CVE-2017-11882.123&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Exploit.CVE-2018-0798.4&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Exploits designed to take advantage of Microsoft Office software vulnerabilities and allow an attacker to run arbitrary code.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1413&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for a packed version of the &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malicious app, written in the AutoIt scripting language. This trojan is distributed as part of a group of several malicious applications, including a miner, a backdoor, and a self-propagating module. &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; performs various malicious actions that make it difficult for the main payload to be detected.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;JS.Phishing.791&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious JavaScript script that generates a phishing web page.&lt;/dd&gt;
&lt;/dl&gt;

&lt;h3&gt;Encryption ransomware&lt;/h3&gt;

&lt;p&gt;In Q4 2025, the number of requests made to decrypt files affected by encoder trojans increased by 1.15%, compared to Q3 2025.&lt;/p&gt;

&lt;p&gt;The dynamics of the decryption requests received by Doctor Web’s technical support service:&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/03_encoder_requests_q4_2025_en.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/03_encoder_requests_q4_2025_en.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;The most common encoders of Q4 2025:&lt;/p&gt;

&lt;ul class="list"&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 24.90% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.41868&lt;/b&gt; — 4.21% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.29750&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.29750&lt;/b&gt;&lt;/a&gt; — 3.42% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.26996&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.26996&lt;/b&gt;&lt;/a&gt; — 2.68% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.30356 &lt;/b&gt; — 0.38% of user requests&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Network fraud&lt;/h3&gt;

&lt;p&gt;Over the course of Q4 2025, Doctor Web’s Internet analysts observed the emergence of new fake marketplace websites. Fraudsters, allegedly on behalf of online trading platforms, offer potential victims the opportunity to play a carousel-type game (similar to roulette) with the chance of winning a prize. After several attempts, the user “gets lucky”, but to receive the prize, they are supposedly required to pay first for the shipping, then insurance, some taxes, etc. In some cases, the victim is told that the item in question is allegedly unavailable and is offered the chance to exchange it for money. If the user agrees, they are again asked to make some more payments in the form of insurance, some account activation, etc. &lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/04_fake_market_q4_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/04_fake_market_q4_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;Example of a fake marketplace website offering a “prize drawing”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;More Internet resources on which scammers sell non-existent theater tickets were added to our unwanted and malicious websites database. Such sites offer victims the chance to attend popular theatrical performances, often at attractive prices. However, after victims pay, they do not get the tickets and have essentially given their money away to the fraudsters.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/05_fake_bilet_q4_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/05_fake_bilet_q4_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;One of the fraudulent sites that sells non-existent theater tickets&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Other sites that imitate the websites of private cinemas and offer users a chance to buy movie tickets have also been detected. Victims do not receive any tickets after paying for them on such sites.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/06_fake_cinema_q4_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/06_fake_cinema_q4_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;The fake website of a private cinema&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Our specialists detected several phishing web resources with some of them being fake sites of the Steam platform. Malicious actors used them to obtain user account data by asking potential victims to provide a login and password for authentication.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/07_fake_steam_login_q4_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/07_fake_steam_login_q4_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A phishing website that imitates the real Steam Internet portal and asks potential victim to log into their account&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;In addition, scammers again lured potential victims into non-existent investment projects. One of the detected sites invited Russian-speaking users living in America to invest $250 in a project called &lt;em&gt;Federal Invest&lt;/em&gt; with the chance to “make up to 90,000 dollars in 3 months”. This project was allegedly created with the participation of Donald Trump.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/08_fake_invest_rus_amer_q4_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/08_fake_invest_rus_amer_q4_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fraudulent site offering the chance to join a “profitable investment project”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Another website reported that Uzbek users can achieve an income of at least 15,000,000 Uzbek soums already within the first month of joining the advertised project, which is allegedly related to a large holding company.&lt;/p&gt;

&lt;div class="img mb-3"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/09_fake_usm_q4_2025.png" data-fancybox&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/december/review_common_q4/09_fake_usm_q4_2025.1.png" alt="#drweb"&gt;
    &lt;/a&gt;
&lt;/div&gt;
&lt;p class="text-center"&gt;&lt;em&gt;A fraudulent website promising residents of Uzbekistan some large profits by joining the “investment project”&lt;/em&gt;&lt;/p&gt;

&lt;div class="notrecommend"&gt;
    &lt;a href="http://antifraud.drweb.com/dangerous_urls/"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;
&lt;/div&gt;

&lt;h3&gt;Malicious and unwanted programs for mobile devices&lt;/h3&gt;

&lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q4 2025, the ad-displaying trojans &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; remained the most common Android threats, despite a decline in their activity. Malicious programs that belong to the &lt;b&gt;Android.Siggen&lt;/b&gt; family and have various functionality rose to third place. Over the course of last three months, banking trojan activity increased, with the &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; family showing the greatest growth.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt; apps, modified via the CloudInject cloud service, were the most common unwanted software. Among the potentially dangerous programs, or riskware, the most active were &lt;b&gt;Tool.NPMod&lt;/b&gt; apps, which had been modified using the NP Manager utility. The most commonly detected adware programs were &lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt; modules that developers embed into Android apps.&lt;/p&gt;

&lt;p&gt;In October, Doctor Web released a &lt;a href="https://news.drweb.com/show/?i=15076&amp;lng=en" target="_blank"&gt;report&lt;/a&gt; on &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt;, a dangerous backdoor that threat actors embedded into Telegram X messenger modifications. This malware steals confidential information and allows the attackers to control both the victim's account and the messenger itself by changing its operating logic.&lt;/p&gt;

&lt;p&gt;During the fourth quarter, our virus analysts discovered new threats on Google Play, including &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojans, which subscribe users to paid services, and &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious apps, which are used for fraudulent purposes.&lt;/p&gt;

&lt;p&gt;The following Q4 2025 events involving mobile malware are the most noteworthy:&lt;/p&gt;

&lt;ul class="list"&gt;
    &lt;li&gt;Adware trojans remained the most common Android threats.&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojan activity increased.&lt;/li&gt;
    &lt;li&gt;The dangerous backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.Baohuo.1.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.Baohuo.1.origin&lt;/b&gt;&lt;/a&gt; was found in a third-party Telegram X messenger mods.&lt;/li&gt;
    &lt;li&gt;New malicious programs emerged on Google Play.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;To find out more about the security-threat landscape for mobile devices in Q4 2025, read our &lt;a href="https://news.drweb.com/show/?i=15101&amp;lng=en" target="_blank"&gt;special overview&lt;/a&gt;.&lt;/p&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15061&amp;lng=en</guid><title>Doctor Web’s Q3 2025 virus activity review</title><link>https://news.drweb.com/show/?i=15061&amp;lng=en&amp;c=10</link><pubDate>Wed, 01 Oct 2025 06:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;October 1, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section&gt;
    &lt;p&gt;&lt;strong&gt;&lt;newslead&gt;According to statistics collected by the Dr.Web anti-virus, the total number of threats detected in the third quarter of 2025 decreased by 4.23%, compared to the second quarter. The number of unique threats increased by 2.17%. Among the most commonly detected threats were unwanted adware software, ad-displaying trojans, and malicious scripts. Email traffic was dominated by malicious scripts, backdoors, and various trojans, including downloaders, droppers, and password stealers.&lt;/newslead&gt;&lt;/strong&gt;&lt;/p&gt;
    &lt;p&gt;Users whose files were affected by encoder trojans had mostly encountered &lt;b&gt;Trojan.Encoder.35534&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt;, and &lt;b&gt;Trojan.Encoder.35067&lt;/b&gt;.&lt;/p&gt;
    &lt;p&gt;In July, Doctor Web’s experts &lt;a href="https://news.drweb.com/show/?i=15036&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about the &lt;a href="https://vms.drweb.com/search/?q=Trojan.Scavenger&amp;lng=en"&gt;&lt;b&gt;Trojan.Scavenger&lt;/b&gt;&lt;/a&gt; malware family whose trojans are designed to steal cryptocurrency and passwords. Threat actors distributed these trojans under the guise of mods, cheats, and patches for games. This malware was launched using legitimate apps, including through the exploitation of the DLL Search Order Hijacking vulnerabilities in them.&lt;/p&gt;
    &lt;p&gt;In August, our malware analysts &lt;a href="https://news.drweb.com/show/?i=15047&amp;lng=en" target="_blank"&gt;warned&lt;/a&gt; about the spread of &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt;, a multifunctional backdoor for mobile devices that was targeting representatives of Russian business. Cybercriminals remotely controlled this malware and used it to steel confidential data and spy on victims.&lt;/p&gt;
    &lt;p&gt;That same month, Doctor Web's anti-virus laboratory &lt;a href="https://news.drweb.com/show/?i=15046&amp;lng=en" target="_blank"&gt;released a study&lt;/a&gt; of a targeted attack committed against a Russian engineering enterprise by the Scaly Wolf hacker group. The threat actors used a variety of malicious instruments, one of the main ones being the Updatar modular backdoor. With its help, the attackers tried to obtain confidential data from infected computers.&lt;/p&gt;
    &lt;p&gt;In Q3 2025, our Internet analysts detected more fake Telegram messenger websites and a number of fraudulent finance-themed online resources. In addition, over the past three months, our specialists have recorded the emergence of dozens of malicious and unwanted apps on Google Play. Among these were &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojans, which subscribe users to paid services, and &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs.&lt;/p&gt;
    &lt;div class="colorful"&gt;
        &lt;h3&gt;Principal trends in Q3 2025&lt;/h3&gt;
        &lt;ul&gt;
            &lt;li&gt;The number of threats detected on protected devices decreased&lt;/li&gt;
            &lt;li&gt;The number of unique threats attacking users were detected in increased numbers&lt;/li&gt;
            &lt;li&gt;More fake Telegram messenger and fraudulent finance-themed websites emerged&lt;/li&gt;
            &lt;li&gt;Password- and cryptocurrency-stealing &lt;a href="https://vms.drweb.com/search/?q=Trojan.Scavenger&amp;lng=en"&gt;&lt;b&gt;Trojan.Scavenger&lt;/b&gt;&lt;/a&gt; malware was spotted in the wild&lt;/li&gt;
            &lt;li&gt;The backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; was used to spy on Russian business representatives and steal confidential data&lt;/li&gt;
            &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; ad-displaying trojans became the most widespread threat for Android devices&lt;/li&gt;
            &lt;li&gt;The activity of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans decreased for the second quarter in a row&lt;/li&gt;
            &lt;li&gt;Many threats were detected on Google Play&lt;/li&gt;
        &lt;/ul&gt;
    &lt;/div&gt;
&lt;/section&gt;

&lt;section&gt;
    &lt;h3&gt;According to Doctor Web’s statistics service&lt;/h3&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/01_stat_q3_2025_en.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/01_stat_q3_2025_en.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;The most common threats in Q3 2025:&lt;/p&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;b&gt;VBS.KeySender.7&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A malicious script that, in an infinite loop, searches for windows containing the text &lt;span class="string"&gt;mode extensions&lt;/span&gt;, &lt;span class="string"&gt;разработчика&lt;/span&gt;, and &lt;span class="string"&gt;розробника&lt;/span&gt; and sends them an Escape key press event, forcibly closing them.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Adware.Downware.20091&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.Siggen31.34463&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan written in the Go programming language and designed to download various miner trojans and adware into infected systems. This malware is a DLL file located at &lt;span class="string"&gt;%appdata%\utorrent\lib.dll&lt;/span&gt;. To launch, it exploits a DLL Search Order Hijacking vulnerability in the uTorrent torrent client.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Adware.Ubar.20&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A torrent client designed to install unwanted programs on a user’s device.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
        &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;h3&gt;Statistics for malware discovered in email traffic&lt;/h3&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/02_mail_traffic_q2_2025_en.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/02_mail_traffic_q2_2025_en.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;b&gt;W97M.DownLoader.2938&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Exploit.CVE-2017-11882.123&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Exploit.CVE-2018-0798.4&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Exploits designed to take advantage of Microsoft Office software vulnerabilities and allow an attacker to run arbitrary code.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;JS.Phishing.745&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A malicious JavaScript script that generates a phishing web page.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;JS.Muldrop.371&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A malicious JavaScript script that installs a payload into the system.&lt;/dd&gt;
    &lt;/dl&gt;
&lt;/section&gt;

&lt;section&gt;
    &lt;h3&gt;Encryption ransomware&lt;/h3&gt;
    &lt;p&gt;In Q3 2025, the number of requests made to decrypt files affected by encoder trojans increased by 3.02%, compared to Q2 2025.&lt;/p&gt;
    &lt;p&gt;The dynamics of the decryption requests received by Doctor Web’s technical support service:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/03_encoder_requests_q3_2025_en.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/03_encoder_requests_q3_2025_en.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;The most common encoders of Q3 2025:&lt;/p&gt;
    &lt;ul&gt;
        &lt;li&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 26.99% of user requests&lt;/li&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt; — 3.07% of user requests&lt;/li&gt;
        &lt;li&gt;&lt;b&gt;Trojan.Encoder.35067&lt;/b&gt; — 2.76% of user requests&lt;/li&gt;
        &lt;li&gt;&lt;b&gt;Trojan.Encoder.41542&lt;/b&gt; — 2.15% of user requests&lt;/li&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.29750&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.29750&lt;/b&gt;&lt;/a&gt; — 1.84% of user requests&lt;/li&gt;
    &lt;/ul&gt;
&lt;/section&gt;

&lt;section&gt;
    &lt;h3&gt;Network fraud&lt;/h3&gt;
    &lt;p&gt;In Q3 2025, Doctor Web’s Internet analysts continued to detect new fake Telegram messenger websites, including those that fraudsters used to try to gain access to user accounts:&lt;/p&gt;
    &lt;div class="flex fxCenter" style="margin-bottom: 12px;"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/04_tg_fake_1.png" class="preview"&gt;
                &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/04_tg_fake_1.1.png" alt="#drweb" style="max-width: 350px;"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/04_tg_fake_2.png" class="preview"&gt;
                &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/04_tg_fake_2.1.png" alt="#drweb" style="max-width: 350px;"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p&gt;In addition, finance-themed fraudulent sites continued to emerge. One of them lured users to an “investment platform of the future” called Apple Trade AI, which supposedly had been created by the Apple Corporation. Cybercriminals promised potential victims the opportunity to make more than $4,000 a month. To “access” the platform, they were required to register by providing personal information.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/05_fraud_appletradeai.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/05_fraud_appletradeai.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;Other Internet resources offered visitors a chance to join a “new investment platform from Meta” and “create a source of constant income, starting from $4,000 a month”. To access the “platform”, users were asked to take a survey and then register.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/06_fraud_inv_1.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/06_fraud_inv_1.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;Our experts also discovered more variants of fake investing platforms that allegedly allowed users to make money with the help of trading bots in &lt;i&gt;WhatsApp&lt;/i&gt;.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/07_fraud_whatsappbusiness.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/07_fraud_whatsappbusiness.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;To “work” with the promised services, potential victims had to provide personal data:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/08_fraud_whatsappbusiness.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/08_fraud_whatsappbusiness.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;A number of fraudulent websites were designed for audiences in specific countries. Some of them were targeting CIS-based users, to whom fraudsters offered the chance to “open a closed investment market” and access some exclusive investments through the INSIDER X financial service. To do so, visitors had to “leave a request” by providing personal data.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/09_fraud_insiderx.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/09_fraud_insiderx.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;In one of the schemes designed for Russian users, cybercriminals asked users to take a survey in order to gain access to an “investment platform” that was supposedly related to large oil and gas companies and the state-backed Gosuslugi &lt;i&gt;(Госуслуги)&lt;/i&gt; portal:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/10_fraud_gazgosusl.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/10_fraud_gazgosusl.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;Scammers passed off some other sites as legitimate Russian bank services and told users they could register in order to “earn at least 50,000 rubles a week”:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/11_fraud_finance.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/11_fraud_finance.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;Once again, users from some other countries encountered similar fake websites. On one of them, fraudsters offered users from Kyrgyzstan the opportunity to become part of a people's program and invest in what they claimed was the country’s largest company:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/12_fraud_gaz.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/12_fraud_gaz.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;Another site was allegedly tied to a Georgian bank and allowed users to join its “investment platform”:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/13_fraud_bankopros.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/13_fraud_bankopros.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;The scammers passed off a similar fake website as belonging to one of the Kazakhstan banks and promised users an income starting from 600,000 tenge per month:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/14_fraud_bank.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/14_fraud_bank.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;On another site, malicious actors, allegedly on behalf of a Turkish oil and gas company, offered potential victims the opportunity to join an investment platform and make “up to 9,000 Turkish lira a day”:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/15_fraud_bankoffer.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/15_fraud_bankoffer.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;At the same time, fraudsters continued exploiting the topic of all kinds of government payments and compensations. On one of the unwanted sites targeting Kazakhstani users, visitors allegedly could check whether financial compensation was available to them and get up to 5,000,000 tenge:&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 32px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/16_fraud_compensation.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_common_q3/16_fraud_compensation.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;a href="http://antifraud.drweb.com/dangerous_urls/" target="_blank"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;
&lt;/section&gt;

&lt;section&gt;
    &lt;h3&gt;Malicious and unwanted programs for mobile devices&lt;/h3&gt;
    &lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q3 2025, users most often encountered &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; ad-displaying trojans. At the same time, the previously leading &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; trojans dropped to second place, significantly reducing their activity. The third most common threat was &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs.&lt;/p&gt;
    &lt;p&gt;Compared to the second quarter, the number of &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; banking trojan detections increased, while the banking trojans &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Android.SpyMax&lt;/b&gt; were, to the contrary, detected less often.&lt;/p&gt;
    &lt;p&gt;In August, Doctor Web’s experts &lt;a href="https://news.drweb.com/show/?i=15047&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; users about the &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; multifunctional backdoor that threat actors had used to spy on representatives of Russian business and steal confidential data from them.&lt;/p&gt;
    &lt;p&gt;Over the course of the last three months, more than 70 malicious and unwanted apps were discovered on Google Play. Among them were &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojans, which subscribe users to paid services, &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs, and &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.16&lt;/b&gt;—a piece of software that allegedly allowed users to convert virtual rewards into real money.&lt;/p&gt;
    &lt;p&gt;The following Q3 2025 events involving mobile malware are the most noteworthy:&lt;/p&gt;
    &lt;ul&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; adware trojans were more active.&lt;/li&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojan activity decreased.&lt;/li&gt;
        &lt;li&gt;Users encountered &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; banking trojans more often.&lt;/li&gt;
        &lt;li&gt;The number of &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Android.SpyMax&lt;/b&gt; banking trojan attacks decreased.&lt;/li&gt;
        &lt;li&gt;Malicious actors used a multifunctional backdoor &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; to spy on Russian business representatives.&lt;/li&gt;
        &lt;li&gt;Many threats were distributed on Google Play.&lt;/li&gt;
    &lt;/ul&gt;
    &lt;p&gt;To find out more about the security-threat landscape for mobile devices in Q3 2025, read our &lt;a href="https://news.drweb.com/show/?i=15060&amp;lng=en" target="_blank"&gt;special overview&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15060&amp;lng=en</guid><title>Doctor Web’s Q3 2025 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=15060&amp;lng=en&amp;c=10</link><pubDate>Wed, 01 Oct 2025 03:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;October 1, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section&gt;
    &lt;p&gt;&lt;strong&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; ad-displaying trojans were the most widespread threats of Q3 2025. They were detected on protected devices 18.19% more often than during the previous observation period.&lt;/newslead&gt;&lt;/strong&gt;&lt;/p&gt;
    &lt;p&gt;The adware trojans &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;, whose activity decreased for the second quarter in a row, fell to second place. In the past 3 months, users encountered them 71.85% less often. These malicious apps conceal their icons, making the trojans harder to detect and remove, and then display ads, including full-screen videos.&lt;/p&gt;
    &lt;p&gt;Third place was again occupied by the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans that cybercriminals use in various fraudulent schemes; the number of times they were detected decreased by 7.49%. Instead of providing the declared functionality, these malicious apps often load various websites, including fraudulent and malicious ones, as well as bookmaker and online casino websites.&lt;/p&gt;
    &lt;p&gt;Despite a 38.88% decline in activity, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; trojans remain the most widespread banking malware. Threat actors use them to gain illegal access to banking accounts and steal money. These trojans can display phishing windows to hijack logins and passwords, imitate the appearance of real banking software, intercept SMS to obtain one-time codes, etc.&lt;/p&gt;
    &lt;p&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; trojans were followed by the &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; trojans, which were detected 18.91% more often than in Q2. Such trojans also try to gain access to users’ online banking accounts by intercepting confirmation codes. At the same time, these malicious apps can execute various commands coming from cybercriminals. Some of them also allow infected devices to be controlled remotely.&lt;/p&gt;
    &lt;p&gt;Rounding out the top three, &lt;b&gt;Android.SpyMax&lt;/b&gt; banking trojans were detected 17.25% less often than in the previous quarter. These malicious apps are based on the source code of the spyware trojan SpyNote and provide a wide range of functions, including the ability to remotely control affected devices.&lt;/p&gt;
    &lt;p&gt;In August, we &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=15047" target="_blank"&gt;informed&lt;/a&gt; users about a malware distribution campaign involving the &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt; multi-functional backdoor. Cybercriminals use this piece of malware to steal confidential data and spy on Android device users. Threat actors sent messages to potential victims via various messengers, offering an “anti-virus” that can be installed from the attached APK file. Doctor Web’s anti-virus laboratory discovered the first versions of this backdoor back in January 2025 and has continued to monitor its development ever since. Our experts believe that this backdoor is used in targeted attacks and is not intended for mass distribution. The main target for cybercriminals is representatives of Russian businesses.&lt;/p&gt;
    &lt;p&gt;Over the course of Q3, a large number of malicious programs were distributed on Google Play for a combined total of over 1,459,000 installations. Among them were dozens of &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; trojans that subscribe victims to paid services and &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious fake programs. In addition, our malware analysts discovered yet another app that supposedly allowed virtual rewards to be converted into real money.&lt;/p&gt;
    &lt;div class="colorful"&gt;
        &lt;h3&gt;Principal trends of Q3 2025&lt;/h3&gt;
        &lt;ul&gt;
            &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; ad-displaying trojans became the most widespread threats&lt;/li&gt;
            &lt;li&gt;The activity of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans continued to decline&lt;/li&gt;
            &lt;li&gt;The number of &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; banking trojan attacks increased&lt;/li&gt;
            &lt;li&gt;Banking trojans &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Android.SpyMax&lt;/b&gt; were less active&lt;/li&gt;
            &lt;li&gt;Cybercriminals used a multi-functional backdoor, &lt;a href="https://vms.drweb.com/search/?q=Android.Backdoor.916.origin&amp;lng=en"&gt;&lt;b&gt;Android.Backdoor.916.origin&lt;/b&gt;&lt;/a&gt;, to attack representatives of Russian businesses&lt;/li&gt;
            &lt;li&gt;Many malicious apps were found on Google Play&lt;/li&gt;
        &lt;/ul&gt;
    &lt;/div&gt;
&lt;/section&gt;

&lt;section&gt;
    &lt;h3&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h3&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/01_malware_q3_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/01_malware_q3_2025_en.1.png" alt="Malware_Stat_Q3_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7859&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that displays obnoxious ads. It is a special software module that developers incorporate into applications.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that loads the website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1812&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for malicious &lt;i&gt;WhatsApp&lt;/i&gt; messenger mods that can covertly load various websites in the background.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.673.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5847&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a packer for &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; trojans that is designed to protect them from being detected and analyzed. Threat actors most often use the packer together with malicious Telegram messenger mods in which these trojans are embedded.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/02_unwanted_q3_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/02_unwanted_q3_2025_en.1.png" alt="Unwanted_Stat_Q3_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, modders can remotely manage these apps—blocking them, displaying custom dialogs, tracking when other software is being installed or removed from a device, etc.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a program that allows users to be monitored via their Android devices. Malicious actors can utilize it to track a target device’s location, take photos and video with the camera, eavesdrop via the microphone, record audio, etc.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/03_riskware_q3_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/03_riskware_q3_2025_en.1.png" alt="Riskware_Stat_Q3_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.3&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.4&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. A special module is embedded in such apps, and it allows them to bypass digital signature verification once they have been modified.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads specially prepared scripts from the Internet, which can be crafted and added to a shared database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some potentially dangerous versions of a specialized framework for developing Android software based on the Lua scripting language. The main logic of Lua-based apps resides in corresponding scripts that are encrypted and decrypted by the interpreter upon execution. By default, this framework often requests access to a large number of system permissions in order to operate. As a result, the Lua scripts that it executes can potentially perform various malicious actions in accordance with the acquired permissions.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/04_adware_q2_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/04_adware_q2_2025_en.1.png" alt="Adware_Stat_Q3_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21846&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some modified versions (mods) of the &lt;i&gt;WhatsApp&lt;/i&gt; messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Youmi&amp;lng=en"&gt;&lt;b&gt;Adware.Youmi&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for an unwanted adware module that adds advertizing shortcuts onto the Android OS home screen.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Adware.Basement.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;These are apps that display unwanted ads which often lead to malicious and fraudulent websites. They share a common code base with the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; unwanted applications.&lt;/dd&gt;
    &lt;/dl&gt;
&lt;/section&gt;

&lt;section&gt;
    &lt;h3&gt;Threats on Google Play&lt;/h3&gt;
    &lt;p&gt;In Q3 2025, Doctor Web's anti-virus laboratory detected over 50 trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; family which subscribe users to paid services. They were distributed under the guise of different software, including messengers, various system tools, image-editing apps, camera apps, programs for working with documents, etc.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/05_Android.Joker.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/05_Android.Joker.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p style="text-align: center;"&gt;&lt;em&gt;One trojan was hidden in the system-optimizing app Clean Boost (&lt;b&gt;Android.Joker.2412&lt;/b&gt;), and another — in the app Convert Text to PDF (&lt;b&gt;Android.Joker.2422&lt;/b&gt;) for creating PDF documents&lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;Moreover, our specialists discovered more fake apps from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; family being used in fraudulent schemes. As before, cybercriminals passed off some of them as financial apps, like reference books and teaching aids and software for accessing investing services. Other &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans were distributed as games and under certain conditions could load bookmaker and online casino websites instead of operating as promised.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/06_Android.FakeApp.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/06_Android.FakeApp.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p style="text-align: center;"&gt;&lt;em&gt;Examples of &lt;b&gt;Android.FakeApp&lt;/b&gt; trojans disguised as financial apps. &lt;b&gt;Android.FakeApp.1889&lt;/b&gt; offered users the chance to test their financial literacy and &lt;b&gt;Android.FakeApp.1890&lt;/b&gt; the opportunity to develop financial intellection&lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;Our experts also discovered &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.16&lt;/b&gt;—an unwanted app, distributed as software called &lt;i&gt;Zeus Jackpot Mania&lt;/i&gt;. In this program, users could get virtual rewards that they could supposedly convert into real money and withdraw it.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/09_Program.FakeMoney.16_1_Zeus Jackpot Mania.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/09_Program.FakeMoney.16_1_Zeus Jackpot Mania.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p style="text-align: center;"&gt;&lt;em&gt;&lt;b&gt;Program.FakeMoney.16&lt;/b&gt; on Google Play&lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;To “withdraw” the money, victims had to give this app some of their data. However, ultimately, they did not receive any payments.&lt;/p&gt;
    &lt;div class="column_grid_review column_grid_review--o" style="margin-bottom: 12px;"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/10_Program.FakeMoney.16.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/october/review_mobile_q3/10_Program.FakeMoney.16.1.png" alt="#drweb"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p style="text-align: center;"&gt;&lt;em&gt;&lt;b&gt;Program.FakeMoney.16&lt;/b&gt; asks users to provide their full name and information about their bank account&lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.&lt;/p&gt;
    &lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q3%202025%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank" rel="noopener noreferrer"&gt;Indicators of compromise&lt;/a&gt;
&lt;/section&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15027&amp;lng=en</guid><title>Doctor Web’s Q2 2025 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=15027&amp;lng=en&amp;c=10</link><pubDate>Tue, 01 Jul 2025 06:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;July 1, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
    &lt;p&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, adware trojans from various families remained the most common malware. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; trojan family were again the most active, despite the fact that users encountered them 8.62% less often. These were followed by &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; adware trojans; the number of attacks involving them increased by 11.17%. &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious programs, used in various fraudulent schemes, ranked third; they were detected on protected devices 25.17% less frequently.&lt;/newslead&gt;&lt;/p&gt;
    &lt;p&gt;
        The activity of &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans increased by 73.15%, compared to the previous quarter. 
        At the same time, some other banking trojan families were detected less often, e.g., &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; (by 37.19%) and &lt;b&gt;Android.SpyMax&lt;/b&gt; (by 19.14%).
    &lt;/p&gt;
    &lt;p&gt;
        In April, our virus analysts &lt;a href="https://news.drweb.com/show/?i=15002&amp;lng=en" target="_blank"&gt;informed&lt;/a&gt; 
        the public about the discovery of a large-scale campaign to steal cryptocurrency from Android smartphone users. 
        During this campaign, malicious actors hid &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; in a modified version of the WhatsApp 
        messenger and implanted it into the firmware of some budget Android smartphone models. This trojan hijacks messages 
        sent and received in the messenger, searches the Tron and Ethereum crypto wallet addresses in them, and replaces 
        legitimate addresses with ones belonging to the scammers. At the same time, the trojan conceals this substitution, 
        and users of infected devices see the “correct” wallets in their messages. Moreover, &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; 
        sends all images in the &lt;i&gt;jpg&lt;/i&gt;, &lt;i&gt;png&lt;/i&gt;, and &lt;i&gt;jpeg&lt;/i&gt; formats to a remote server to search mnemonic phrases 
        for their victims’ crypto wallets.
    &lt;/p&gt;
    &lt;p&gt;
        Also in April, we &lt;a href="https://news.drweb.com/show/?i=15006&amp;lng=en" target="_blank"&gt;reported&lt;/a&gt; on a spyware trojan targeting Russian military personnel. 
        The &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; malicious program was hidden in a modified version of Alpine Quest mapping software. It was distributed via a fake Telegram 
        channel of an app created by the threat actors as well as via one of the Russian Android app catalogs. 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; sent various confidential data to the attackers, including user accounts, their mobile phone number, contacts from the phone book, 
        and information about the infected device’s geolocation and the files stored in its memory. When commanded by malicious actors, the trojan could steal specified files. 
        The malware creators were particularly interested in confidential documents sent via popular messengers as well as in Alpine Quest’s location log file.
    &lt;/p&gt;
    &lt;p&gt;
        At the same time, during this most recent observation period, Doctor Web’s virus laboratory detected more threats on Google Play. 
        Among them were various trojans and unwanted ad-displaying software.
    &lt;/p&gt;
    &lt;div class="colorful"&gt;
        &lt;h3&gt;Principal trends of Q2 2025&lt;/h3&gt;
        &lt;ul&gt;
            &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans intensified their activity&lt;/li&gt;
            &lt;li&gt;Adware trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; family also heightened their activity&lt;/li&gt;
            &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans were less commonly detected on protected devices, compared to the previous quarter&lt;/li&gt;
            &lt;li&gt;Decreased numbers of &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Android.SpyMax&lt;/b&gt; banking trojan family attacks were noted&lt;/li&gt;
            &lt;li&gt;A trojan designed to steal cryptocurrency was found in the firmware of several budget Android smartphone models&lt;/li&gt;
            &lt;li&gt;Malicious actors distributed a trojan that spied on Russian military personnel&lt;/li&gt;
            &lt;li&gt;More threats emerged on Google Play&lt;/li&gt;
        &lt;/ul&gt;
    &lt;/div&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
    &lt;h3&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h3&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/01_malware_q2_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/01_malware_q2_2025_en.png" alt="Malware_Stat_Q2_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4214&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4213&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Trojan apps designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7859&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that displays obnoxious ads. It is a special software module that developers incorporate into applications.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that loads a website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/02_unwanted_q2_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/02_unwanted_q2_2025_en.png" alt="Unwanted_Stat_Q2_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, modders can remotely manage these apps—blocking them, displaying custom dialogs, tracking when other software is being installed or removed from a device, etc.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;    
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a program that allows users to be monitored via their Android devices. Malicious actors can utilize it to track a target device’s location, take photos and video with the camera, eavesdrop via the microphone, record audio, etc.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for various modifications of an application that is designed to record videos and take photos in the background, using built-in Android device cameras. It can operate covertly by allowing notifications about ongoing recordings to be disabled. It also allows an app’s icon and name to be replaced with fake ones. This functionality makes this software potentially dangerous.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/03_riskware_q2_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/03_riskware_q2_2025_en.png" alt="Riskware_Stat_Q2_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.3&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. A special module is embedded in such apps, and it allows them to bypass digital signature verification once they have been modified.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some potentially dangerous versions of a specialized framework for developing Android software based on the Lua scripting language. The main logic of Lua-based apps resides in the corresponding scripts that are encrypted and decrypted by the interpreter upon execution. By default, this framework often requests access to a large number of system permissions in order to operate. As a result, the Lua scripts that it executes can potentially perform various malicious actions in accordance with the acquired permissions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A riskware platform that allows applications to launch APK files without installing them. It creates a virtual runtime environment in the context of the apps in which they are integrated. The APK files launched with the help of this platform can operate as if they are part of such programs and can also obtain the same permissions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A packer tool designed to protect Android applications from unauthorized modifications and reverse engineering. This tool is not malicious in itself, but it can be used to protect both harmless and malicious software.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/04_adware_q2_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/04_adware_q2_2025_en.png" alt="Adware_Stat_Q2_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some modified versions (mods) of the WhatsApp messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Adware.Basement.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;These are apps that display unwanted ads which often lead to malicious and fraudulent websites. They share a common code base with the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; unwanted applications.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;An adware module that malicious actors embed into the cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display obnoxious ads.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Adware.Jiubang.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Unwanted ad-displaying software for Android devices that displays a banner showing recommended programs when applications are being installed.&lt;/dd&gt;
    &lt;/dl&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="gplay"&gt;
    &lt;h3&gt;Threats on Google Play&lt;/h3&gt;
    &lt;p&gt;
        Over the course of the second quarter of 2025, Doctor Web’s virus analysts discovered several dozen threats on Google Play, 
        including various fake programs from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; family. These trojans were again actively being distributed 
        under the guise of finance-related programs and, instead of the promised functionality, could load fraudulent websites.
    &lt;/p&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/05_Android.FakeApp.1863.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/05_Android.FakeApp.1863.1.png" alt="Android.FakeApp_Q2_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/06_Android.FakeApp.1859.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/06_Android.FakeApp.1859.1.png" alt="Android.FakeApp_Q2_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        &lt;b&gt;Android.FakeApp.1863&lt;/b&gt; and &lt;b&gt;Android.FakeApp.1859&lt;/b&gt; are examples of the trojans that were discovered. 
        The former was hidden in the “TPAO” app and targeted Turkish users who were told that the app could help them 
        “easily control their deposits and incomes”. The latter was disguised as a “financial assistant” (“Quantum MindPro”) 
        and was geared toward a French-speaking audience.
    &lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;
        Games remain another popular disguise for such fake programs. Under certain conditions, they load online casino and bookmaker websites instead of providing gaming functionality.
    &lt;/p&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/07_Android.FakeApp.1840.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/07_Android.FakeApp.1840.1.png" alt="Android.FakeApp_Q2_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        &lt;b&gt;Android.FakeApp.1840&lt;/b&gt; (“Pino Bounce”) is one of the fake games that could load an online casino site.
    &lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;
        In addition, our specialists detected the unwanted ad-displaying software &lt;b&gt;Adware.Adpush.21912&lt;/b&gt;. 
        It was hidden in the &lt;i&gt;“Coin News Promax”&lt;/i&gt; app, which contains informational materials about cryptocurrencies. 
        &lt;b&gt;Adware.Adpush.21912&lt;/b&gt; displays notifications that, when clicked, load into WebView the link specified by the С2 server.
    &lt;/p&gt;
     &lt;div class="flex fxCenter"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/08_Adware.Adpush.21912.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_mobile_q2/08_Adware.Adpush.21912.1.png" alt="Adware.Adpush_Q2_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p&gt;
        To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.
    &lt;/p&gt;
&lt;/section&gt;
&lt;br /&gt;
&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q2%202025%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank" rel="noopener noreferrer"&gt;Indicators of compromise&lt;/a&gt;</description></item><item><guid>https://news.drweb.com/show/?i=15026&amp;lng=en</guid><title>Doctor Web’s Q2 2025 virus activity review</title><link>https://news.drweb.com/show/?i=15026&amp;lng=en&amp;c=10</link><pubDate>Tue, 01 Jul 2025 03:00:00 GMT</pubDate><description>&lt;p&gt;&lt;b&gt;July 1, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
  &lt;p&gt;&lt;newslead&gt;According to statistics collected by the Dr.Web anti-virus, the total number of threats detected in the second quarter of 2025 decreased by 7.38%, compared to the first quarter. At the same time, the number of unique threats decreased by 23.10%. Unwanted adware apps, backdoors, ad-displaying trojans, and malicious scripts were among the threats most commonly detected on protected devices. In email traffic, most frequently detected were trojan downloaders, various malicious scripts, and trojan droppers.&lt;/newslead&gt;&lt;/p&gt;
  &lt;p&gt;
    Users whose files were affected by encoder trojans had mostly encountered &lt;b&gt;Trojan.Encoder.35534&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt;, and &lt;b&gt;Trojan.Encoder.29750&lt;/b&gt;.
  &lt;/p&gt;
  &lt;p&gt;
    In April, Doctor Web’s virus analysts reported on a trojan found in the firmware of a number of Android smartphone models. 
    Cybercriminals used this malware to steal cryptocurrency from their victims. In addition, our specialists discovered a trojan 
    that malicious actors embedded into a version of a popular mapping program; it was used to spy on Russian military personnel.
  &lt;/p&gt;
  &lt;p&gt;
    Over the course of the second quarter, our Internet analysts uncovered many new fraudulent websites. 
    Among them were websites of non-existent educational platforms that supposedly allowed potential victims 
    to undergo online training and improve their qualifications. There were also more investment-themed websites promising quick and easy money.
  &lt;/p&gt;
  &lt;p&gt;
    The detection statistics on mobile devices showed a decrease in activity of the part of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; 
    ad-displaying trojans. However, this malware family remains the most widespread Android threat. At the same time, our 
    virus laboratory detected many new threats on Google Play.
  &lt;/p&gt;
  &lt;div class="colorful"&gt;
    &lt;h3&gt;Principal trends in Q2 2025&lt;/h3&gt;
    &lt;ul&gt;
      &lt;li&gt;The number of threats detected on protected devices decreased&lt;/li&gt;
      &lt;li&gt;Unique threats used in attacks were detected in decreased numbers&lt;/li&gt;
      &lt;li&gt;Many fraudulent websites, allegedly related to the education sector and finances, emerged&lt;/li&gt;
      &lt;li&gt;A spyware trojan attack targeting Russian military personnel was detected; the attack exploited popular mapping software for Android devices&lt;/li&gt;
      &lt;li&gt;A trojan designed to steal cryptocurrency was found in the firmware of a variety of Android smartphones&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans remain among the most widespread Android threats&lt;/li&gt;
      &lt;li&gt;More malicious and unwanted programs were detected on Google Play&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/div&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
  &lt;h3&gt;According to Doctor Web’s statistics service&lt;/h3&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/01_stat_q2_2025_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/01_stat_q2_2025_en.png" alt="stat_2025_Q2"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;The most common threats in Q2 2025:&lt;/p&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;VBS.KeySender.6&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious script that, in an infinite loop, searches for windows containing the text &lt;span class="string"&gt;mode extensions&lt;/span&gt;, &lt;span class="string"&gt;разработчика&lt;/span&gt;, and &lt;span class="string"&gt;розробника&lt;/span&gt; and sends them an Escape key press event, forcibly closing them.&lt;/dd&gt; 
    &lt;dt&gt;&lt;b&gt;Adware.Downware.20091&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.BPlug.4242&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.BPlug.3814&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious components of the WinSafe browser extension. These components are JavaScript files that display intrusive ads in browsers.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Siggen30.53926&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name of an Electron framework host process modified by threat actors. It mimics a Steam application component (Steam Client WebHelper) and loads a JavaScript backdoor.&lt;/dd&gt;
  &lt;/dl&gt;
  &lt;h3 class="alignCenter"&gt;Statistics for malware discovered in email traffic&lt;/h3&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/02_mail_traffic_q2_2025_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/02_mail_traffic_q2_2025_en.png" alt="mail_traffic_2025_Q2"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
    &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;JS.Inject&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A family of malicious JavaScripts that inject a malicious script into the HTML code of webpages.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Win32.HLLW.Rendoc.3&amp;lng=en"&gt;&lt;b&gt;Win32.HLLW.Rendoc.3&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
    &lt;dd&gt;A network worm that spreads via removeable storage media and other channels.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;W97M.DownLoader.2938&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;PDF.Phisher.867&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;PDF documents used in phishing newsletters.&lt;/dd&gt;
  &lt;/dl&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="encruptor"&gt;
  &lt;h3&gt;Encryption ransomware&lt;/h3&gt;
  &lt;p&gt;
    In Q2 2025, the number of requests made to decrypt files affected by encoder trojans decreased by 14.65%, compared to Q1 2025.
  &lt;/p&gt;
  &lt;p&gt;
    The dynamics of the decryption requests received by Doctor Web’s technical support service:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/03_encoder_requests_q2_2025_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/03_encoder_requests_q2_2025_en.png" alt="encoder_stat_2025_Q2"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;The most common encoders of Q2 2025:&lt;/p&gt;
  &lt;ul&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 24.41% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt; — 4.41% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.29750 &lt;/b&gt; — 2.71% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.35067&lt;/b&gt; — 2.71% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.41868 &lt;/b&gt; — 2.71% of user requests&lt;/li&gt;
  &lt;/ul&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="netfraud"&gt;
  &lt;h3&gt;Network fraud&lt;/h3&gt;
  &lt;p&gt;
    Over the course of the second quarter, Doctor Web’s Internet analysts detected many fraudulent websites 
    supposedly related to the education sector. Online resources offering training in various professions became widespread. 
    For example, the &lt;i&gt;SMM Академия&lt;/i&gt; (“SMM Academy”) and &lt;i&gt;LearnIT KZ&lt;/i&gt; platforms, designed for Kazakhstani users, 
    supposedly allowed them to “master the SMM manager profession in 3 months” and “become a data analyst”.
  &lt;/p&gt;
  &lt;div class="img img-two"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/04_q2_2025_fraud.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/04_q2_2025_fraud.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/05_q2_2025_fraud.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/05_q2_2025_fraud.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    On other websites, potential victims were allegedly able to access various courses. Among them were courses for learning English 
    and for gaining capital management skills—from the &lt;i&gt;EnglishPro&lt;/i&gt; and &lt;i&gt;FinCourse&lt;/i&gt; “platforms”, respectively:
  &lt;/p&gt;
  &lt;div class="img img-two"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/06_q2_2025_fraud.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/06_q2_2025_fraud.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/07_q2_2025_fraud.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/07_q2_2025_fraud.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    And the fraudulent website of a certain service called &lt;i&gt;Финансовое Образование&lt;/i&gt; (“Financial Education”) could supposedly 
    help users improve their financial literacy. It offered visitors the chance to “master their finances and guarantee their future”:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/08_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/08_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    To “access” their advertised services, such websites ask users to register an account by providing personal data, 
    like their name, mobile phone number, email address, etc. Such data accumulates in the criminals’ hands and can 
    later be used in various fraudulent schemes.
  &lt;/p&gt;
  &lt;p&gt;
    At the same time, new fraudulent websites appeared for pseudo-investment projects that cybercriminals often presented 
    as allegedly being related to well-known companies and services. For instance, one offered users the opportunity to become 
    participants in an innovative project based on AI (artificial intelligence) technologies. This “project” was passed off as 
    a service from the Audi automobile concern and supposedly allowed cryptocurrencies to be traded automatically and a guaranteed 
    high income to be received. For “accessing” the service, a starting sum of €250 was required.
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/09_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/09_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Another “investment project” was allegedly related to the &lt;i&gt;TikTok&lt;/i&gt; social network. Visitors to the fraudulent website were 
    asked to complete a short survey and then provide personal information for registering and accessing the promised service:
  &lt;/p&gt;
  &lt;div class="img img-two"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/10_q2_2025_fraud_1.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/10_q2_2025_fraud_1.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/10_q2_2025_fraud_2.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/10_q2_2025_fraud_2.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Moreover, other fraudulent websites were discovered that were camouflaged as official online resources for the &lt;i&gt;WhatsApp&lt;/i&gt; messenger. 
    One of them offered visitors the opportunity to receive digital coins, each of which “brings the owner €15 a day”. The user supposedly 
    received 160 of these coins, but to begin “earning money on them”, they were asked to register an account by providing personal data. 
    In reality, the potential victim did not get any digital assets, and their data ended up in the hands of the scammers.
  &lt;/p&gt;
  &lt;div class="img img-two"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/11_q2_2025_fraud_1.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/11_q2_2025_fraud_1.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/11_q2_2025_fraud_2.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/11_q2_2025_fraud_2.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Another fake &lt;i&gt;WhatsApp&lt;/i&gt; website supposedly granted access to yet another trading bot, based on some so-called unique developments. 
    Users were asked to “run the &lt;i&gt;WhatsApp Bot&lt;/i&gt; and make money automatically”. For this, they were traditionally required to register 
    by indicating their personal data, which was then transferred to the threat actors.
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/12_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/12_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Fraudsters also targeted users from specific countries. For example, Russian citizens could encounter websites offering them the opportunity 
    to “make their dreams come true” with the help of this or that investment service. Malicious actors utilized the same template to design such 
    websites, only changing the appearance and the names of the non-existent projects.
  &lt;/p&gt;
  &lt;div class="img img-two"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/13_q2_2025_fraud_1.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/13_q2_2025_fraud_1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/13_q2_2025_fraud_2.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/13_q2_2025_fraud_2.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    It is noteworthy that websites based on the same template were also created for residents of other countries, for example, Uzbekistan:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/14_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/14_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    One fraudulent website that was discovered lured Russian-speaking users living in Europe. On this website, 
    cybercriminals promised potential victims a passive income of up to €1000 per week “with the help of innovative, 
    new-generation financial solutions” from some platform called &lt;i&gt;LevelUPTrade&lt;/i&gt;:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/15_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/15_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    French users could become victims of malicious actors offering the chance to access the non-existent 
    &lt;i&gt;TraderAI&lt;/i&gt; automated trading software. With its help, potential victims allegedly had the opportunity to earn a hefty sum, starting from €3500:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/16_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/16_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    For Mexican citizens, scammers prepared an “intellectual trading system” called &lt;i&gt;QuantumIA&lt;/i&gt;. This is one of many variants of 
    the well-known pseudo-trading system known as &lt;i&gt;Quantum System&lt;/i&gt; or &lt;i&gt;QuantumAI&lt;/i&gt;, which supposedly allows automatic trading to take 
    place in financial markets using quantum computing and artificial intelligence technologies.
  &lt;/p&gt;
  &lt;div class="img img-two"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/17_q2_2025_fraud_1.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/17_q2_2025_fraud_1.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/17_q2_2025_fraud_2.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/17_q2_2025_fraud_2.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    On another website, fraudsters, allegedly on behalf of a large bank, offered Mexican users some investment services. 
    Potential victims were promised that they could make 16,000 Mexican pesos within a short period of time after registering. 
    For this, they were asked to provide their personal data.
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/18_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/18_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    German users risked falling victim to the fake trading platform &lt;i&gt;Lucrosa Infinity&lt;/i&gt;. Its image has been exploited 
    in one form or another by cybercriminals for several years. On one fraudulent website, threat actors offered users 
    the opportunity to “start investing and open the door to financial independence”.
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/19_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/19_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Cybercriminals also offered Canadian users the opportunity to use “unique” services that allegedly provide high income through investments 
    and cryptocurrency trading. Among the uncovered fraudulent websites, for example, were those advertising “platforms” like &lt;i&gt;BitcoinFusionPro&lt;/i&gt; 
    and &lt;i&gt;BitcoinReaction&lt;/i&gt;. These supposedly allowed clients to make at least 1,000 Canadian dollars per day by investing “only” 350 dollars:
  &lt;/p&gt;
  &lt;div class="img img-two"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/20_q2_2025_fraud.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/20_q2_2025_fraud.2.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/21_q2_2025_fraud.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/21_q2_2025_fraud.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Users from Poland also encountered similar websites. On one of them, scammers promised their potential victims earnings from $950 to $2,200 
    a day with “the most advanced cryptocurrency management software in the world”:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/22_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/22_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Another website offered them €250 to invest and then earn €700 daily:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/23_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/23_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    One fraudulent website promised Polish users “the opportunity to work from home and make decent money” thanks to the automated system &lt;i&gt;Click Money&lt;/i&gt;. 
    With its help, people without trading experience could allegedly earn up to 64,000,000 Polish zlotys annually:
  &lt;/p&gt;
  &lt;div class="img"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/24_q2_2025_fraud.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/july/review_common_q2/24_q2_2025_fraud.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;div class="notrecommend"&gt;
    &lt;a href="http://antifraud.drweb.com/dangerous_urls/" target="_blank"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;
  &lt;/div&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="formobile"&gt;
    &lt;h3&gt;Malicious and unwanted programs for mobile devices&lt;/h3&gt;
    &lt;p&gt;
        According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q2 2025, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojans were most commonly detected on protected devices. 
        Compared to the previous quarter, users encountered them somewhat less frequently. Next came adware 
        trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; family and 
        &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious fake programs; the activity of the former increased, while that of the latter decreased.
    &lt;/p&gt;
    &lt;p&gt;
        Mixed dynamics were also observed with banking trojans. For example, more attacks by representatives of the 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; family were recorded. At the same time, trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Android.SpyMax&lt;/b&gt; 
        families were detected less often on protected devices.
    &lt;/p&gt;
    &lt;p&gt;
        In the second quarter, Doctor Web’s specialists 
        &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=15002" target="_blank"&gt;discovered&lt;/a&gt; the &lt;a href="https://vms.drweb.com/search/?q=Android.Clipper.31&amp;lng=en"&gt;&lt;b&gt;Android.Clipper.31&lt;/b&gt;&lt;/a&gt; 
        trojan in the firmware of a number of Android smartphone models. This malicious app was hidden in one of the &lt;i&gt;WhatsApp&lt;/i&gt; 
        messenger versions modified by attackers and was used to steal cryptocurrency from the owners of infected devices. 
        Moreover, our virus analysts &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=15006" target="_blank"&gt;uncovered&lt;/a&gt; 
        the &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.1292.origin&amp;lng=en"&gt;&lt;b&gt;Android.Spy.1292.origin&lt;/b&gt;&lt;/a&gt; malicious program. Cybercriminals embedded it into one version of Alpine Quest mapping 
        software and used it to spy on Russian military personnel.
    &lt;/p&gt;
    &lt;p&gt;
        Over the course of the last 3 months, dozens of threats have been detected on Google Play. 
        Among them were malicious fake apps from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; 
        family and new unwanted ad-displaying software &lt;b&gt;Adware.Adpush.21912&lt;/b&gt;.
    &lt;/p&gt;
    &lt;p&gt;
        The following Q2 2025 events involving mobile malware are the most noteworthy:
    &lt;/p&gt;
    &lt;ul&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojans were less active.&lt;/li&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; adware trojan activity increased.&lt;/li&gt;
        &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans were detected more often on protected devices, compared to the first quarter.&lt;/li&gt;
        &lt;li&gt;The number of &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Android.SpyMax&lt;/b&gt; banking trojan attacks decreased.&lt;/li&gt;
        &lt;li&gt;A trojan designed to steal cryptocurrency was found in the firmware of several Android smartphone models.&lt;/li&gt;
        &lt;li&gt;A spyware trojan targeting Russian military personnel was discovered.&lt;/li&gt;
        &lt;li&gt;New threats emerged on Google Play.&lt;/li&gt;
    &lt;/ul&gt;
    &lt;p&gt;
      To find out more about the security-threat landscape for mobile devices in Q2 2025, read our &lt;a href="" target="_blank"&gt;special overview&lt;/a&gt;.
    &lt;/p&gt;
&lt;/section&gt;</description></item><item><guid>https://news.drweb.com/show/?i=14992&amp;lng=en</guid><title>Doctor Web’s Q1 2025 virus activity review</title><link>https://news.drweb.com/show/?i=14992&amp;lng=en&amp;c=10</link><pubDate>Thu, 27 Mar 2025 00:00:00 GMT</pubDate><description>



&lt;p&gt;&lt;b&gt;March 27, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
  &lt;p&gt;&lt;newslead&gt;According to statistics collected by the Dr.Web anti-virus, the total number of threats detected in the first quarter of 2025 increased by 7.23%, compared to the fourth quarter of 2024. At the same time, the number of unique threats decreased by almost a third—27.59%. This suggests that, while increasing the intensity of their attacks, threat actors were using the same malicious and unwanted applications in them more often. Malicious scripts with different functionality, ad-displaying trojans, and adware apps were the most widespread threats.&lt;/newslead&gt;&lt;/p&gt;
  &lt;p&gt;
    In email traffic, trojan droppers and downloaders, adware software, malicious scripts, and trojans designed to run various threats on attacked computers were most frequently detected.
  &lt;/p&gt;
  &lt;p&gt;
    Users whose files were affected by encoder trojans had mostly encountered 
    &lt;b&gt;Trojan.Encoder.35534&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt;, and &lt;b&gt;Trojan.Encoder.35067&lt;/b&gt;.
  &lt;/p&gt;
  &lt;p&gt;
    In January, Doctor Web’s virus laboratory 
    &lt;a href="https://news.drweb.com/show/?i=14976&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;uncovered&lt;/a&gt; 
    an active Monero cryptocurrency mining campaign using many different trojans. To conceal some of them, threat actors utilized steganography, 
    a technique that allows some data to be hidden within other data—for example, inside images.
  &lt;/p&gt;
  &lt;p&gt;
    At the same time, over the course of the first quarter, our Internet analysts detected an increase in the number of fraudulent websites aimed at stealing Telegram messenger user accounts. 
  &lt;/p&gt;
  &lt;p&gt;
    In the mobile threats department, Doctor Web’s specialists observed increased activity on the part of adware trojans and some 
    banking trojans used to target the Android OS. In addition, they uncovered dozens of new malicious apps on Google Play.
  &lt;/p&gt;
  &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
    &lt;h4 class="white alignCenter"&gt;Principal trends in Q1 2025&lt;/h4&gt;
    &lt;ul&gt;
      &lt;li&gt;Threats were detected on protected devices in increasing numbers.&lt;/li&gt;
      &lt;li&gt;The quantity of unique threats used in attacks decreased.&lt;/li&gt;
      &lt;li&gt;Phishing sites designed to steal Telegram accounts became more prevalent.&lt;/li&gt;
      &lt;li&gt;Several widespread ad-displaying and banking trojan families, used to target the Android operating system, heightened their activity.&lt;/li&gt;
      &lt;li&gt;New malware emerged on Google Play.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/div&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
  &lt;h2 class="alignCenter"&gt;According to Doctor Web’s statistics service&lt;/h2&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/01_stat_q1_2025_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/01_stat_q1_2025_en.png" alt="stat_2025_Q1"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;The most common threats in Q1 2025:&lt;/p&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;VBS.KeySender.6&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious script that, in an infinite loop, searches for windows containing the text &lt;span class="string"&gt;mode extensions&lt;/span&gt;, &lt;span class="string"&gt;разработчика&lt;/span&gt;, and &lt;span class="string"&gt;розробника&lt;/span&gt; and sends them an Escape key press event, forcibly closing them.&lt;/dd&gt; 
    &lt;dt&gt;&lt;b&gt;Adware.Downware.20091&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.BPlug.4242&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name for malicious components of the WinSafe browser extension. These components are JavaScript files that display intrusive ads in browsers.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
    &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Siggen30.53926&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;The detection name of an Electron framework host process modified by threat actors. It mimics a Steam application component (Steam Client WebHelper) and loads a JavaScript backdoor.&lt;/dd&gt;
  &lt;/dl&gt;
  &lt;h3 class="alignCenter"&gt;Statistics for malware discovered in email traffic&lt;/h3&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/02_mail_traffic_q1_2025_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/02_mail_traffic_q1_2025_en.png" alt="mail_traffic_2025_Q1"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
    &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;JS.Inject&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A family of malicious JavaScripts that inject a malicious script into the HTML code of webpages.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.AVKill.63950&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;This is a dropper that installs the &lt;b&gt;JS.BackDoor.42&lt;/b&gt; backdoor on computers running the Windows operating system.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Inject5.13806&lt;/b&gt;&lt;/dt&gt;
    &lt;dd&gt;A malicious program for Windows-based computers that was created using the AutoIt scripting language. It launches several system processes and injects the &lt;b&gt;Trojan.Fbng&lt;/b&gt; spyware trojan into them. The attackers can use the latter as banking malware and for other purposes.&lt;/dd&gt;
  &lt;/dl&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="encruptor"&gt;
  &lt;h2 class="alignCenter"&gt;Encryption ransomware&lt;/h2&gt;
  &lt;p&gt;
    In Q1 2025, the number of requests made to decrypt files affected by encoder trojans decreased by 9.34%, compared to Q4 2024.
  &lt;/p&gt;
  &lt;p&gt;
    The dynamics of the decryption requests received by Doctor Web’s technical support service:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/03_encoder_requests_q1_2025_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/03_encoder_requests_q1_2025_en.png" alt="encoder_stat_2025_Q1"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;The most common encoders of Q1 2025:&lt;/p&gt;
  &lt;ul&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 11.89% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt; — 5.95% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder. 35067&lt;/b&gt; — 3.57% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.38200&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.38200&lt;/b&gt;&lt;/a&gt; — 2.38% of user requests&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Trojan.Encoder.37369&lt;/b&gt; — 1.98% of user requests&lt;/li&gt;
  &lt;/ul&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="netfraud"&gt;
  &lt;h2 class="alignCenter"&gt;Network fraud&lt;/h2&gt;
  &lt;p&gt;
    In Q1 2025, Doctor Web’s Internet analysts observed the emergence of many new phishing websites designed 
    to steal Telegram messenger user accounts. Among the most common variants were fake login pages and support 
    pages that informed users about alleged problems due to some violation of the terms of service. 
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/04_scam_telegram_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/04_scam_telegram_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/05_scam_telegram_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/05_scam_telegram_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Fake sites of online stores were widespread once again. On these, cybercriminals asked potential victims to log in to their accounts.
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/06_scam_onlinestore_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/06_scam_onlinestore_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
    A phishing authorization form on a fake website of one Russian online store
  &lt;/em&gt;&lt;/p&gt;
  &lt;p&gt;
    Our specialists continued detecting fraudulent sites with all sorts of “great offers”, such as quick or easy ways to make money; 
    others were about receiving certain gifts, participating in promotions, etc. One of the schemes, for instance, targeted residents 
    of Great Britain, offering them the chance to obtain “limited edition” transportation cards, which were supposedly dedicated to the 
    anniversaries of various carriers and would allow them to use public transport services free of charge for a long period of time.
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/07_scam_transportcard_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/07_scam_transportcard_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/08_scam_transportcard_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/08_scam_transportcard_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
    Fraudulent sites offering the chance to obtain “special” First Essex and Oyster transportation cards that allow public transport services to be used for free
  &lt;/em&gt;&lt;/p&gt;
  &lt;p&gt;
    Users had to answer several questions and then play a game by opening virtual gift boxes (the “winning” box in such scenarios is hardcoded). 
    After “winning”, users had to provide personal information and pay £2 to “receive” the promised card. As a result, the victims’ personal 
    information and money ended up in the hands of threat actors.
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/09_transport_gift_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/09_transport_gift_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/10_transport_gift_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/10_transport_gift_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
    A potential victim has allegedly obtained a card successfully from one of the game boxes, and in order to receive it, they must provide personal data and also pay £2
  &lt;/em&gt;&lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/11_transportcard_pay_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/11_transportcard_pay_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
    A form for entering bank card details to pay for a non-existent promotional transportation card
  &lt;/em&gt;&lt;/p&gt;
  &lt;p&gt;
    Fraudsters continue luring potential victims with all sorts of trading platforms that have “unique” algorithms, including 
    ones that are supposedly based on artificial intelligence (AI) technologies. At the same time, cybercriminals exploit the 
    names of famous people and hide behind real companies and services, attributing to themselves a connection with them. One 
    popular scenario is based on claims that users can make money with the help of certain specialized services from Telegram, 
    WhatsApp, and other companies.
  &lt;/p&gt;
  &lt;p&gt;
    Some of these fraudulent sites were advertising various AI platforms, such as Telegram AI and WHATSAPP AI, which allegedly 
    could help users make at least €14,000 per month, thanks to an “automated trading system”:
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/12_scam_telegramai_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/12_scam_telegramai_q1_2025.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/13_scam_whatsappai_q1_2025.PNG" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/13_scam_whatsappai_q1_2025.PNG" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Other variants exploited the theme of trading bots, which are commonly passed off as instruments created by the messengers’ owners themselves. 
    One website, for instance, promised that “Pavel Durov’s bot” Telegram.AI would allow users to earn €2,500+ monthly; and another one offered the 
    option to use the WhatsApp Bot, supposedly created by Mark Zuckerberg, to make up to €500 per day.
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/14_scam_telegrambot_q1_2025.PNG" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/14_scam_telegrambot_q1_2025.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/15_scam_whatsapbot_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/15_scam_whatsapbot_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Another scam website offered users the option to register on a “Telegram platform” that allegedly runs directly from a smartphone browser, 
    automatically trades shares of global companies, and earns €10,000 per month:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/16_scam_telegram_platform_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/16_scam_telegram_platform_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    One website promised “every Europe resident” an income starting at €5,000 per month with the help of certain AI-based algorithms from the WhatsApp Company:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/17_scam_whatsapp_platform_q1_2025__new.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/17_scam_whatsapp_platform_q1_2025__new.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Scam platform “The wealth formula” (“Formule Bohatstvi” in Czech), with its fake AI-based trading system, is a popular variation of this fraudulent scheme. 
    It supposedly makes trades in a split second by analyzing huge amounts of data. Different sites of this non-existent system invite visitors to watch an 
    informational video and register an account for consultations in the “anti-crisis solutions office”. The fraudsters are mainly targeting Europeans—Czech 
    users in particular— who are promised an income of €1,000 per day “for life”. To access the system, potential victims are required to make a minimum deposit of €250.
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/18_scam_formule_bohatstvi_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/18_scam_formule_bohatstvi_q1_2025.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/19_scam_formule_bohatstvi_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/19_scam_formule_bohatstvi_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Other similar scenarios, such as generating income using various specialized software, also remain popular. 
    One such website invited Czech users to make thousands of crowns per day with “the world’s most intelligent cryptographic software”:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/20_scam_cz_money_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/20_scam_cz_money_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Another scam Internet portal promised earnings of over 4.7 million crowns monthly using certain trading software known as «10K EVERY DAY APP»:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/21_scam_10kapp_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/21_scam_10kapp_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    At the same time, users continued encountering fake investment-themed websites targeting residents of different countries. 
    For example, for an audience from Kazakhstan, fraudsters prepared yet another platform for earning passive income through oil and gas trading:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/22_scam_kaz_passive_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/22_scam_kaz_passive_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Many other sites offered the opportunity to “earn as much as possible” by trading shares of companies in Kazakhstan, Russia, China, and other countries:
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/23_scam_kaz_more_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/23_scam_kaz_more_q1_2025.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/24_scam_kaz_more_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/24_scam_kaz_more_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Russian and Kyrgyz residents also encountered similar websites; on these, users allegedly could make money by trading oil and gas:
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/25_scam_kyrgyzgaz_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/25_scam_kyrgyzgaz_q1_2025.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/26_scam_russiagaz_q1_2025.PNG" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/26_scam_russiagaz_q1_2025.PNG" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p&gt;
    And one scam Internet resource offered Romanian users the chance to join the BRUA pipeline project, promising 3,000 lei per week as passive income:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/27_scam_romania_brua_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/27_scam_romania_brua_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Sites that promise government support to the population in the form of benefits, social payments, etc., remain a lure for potential victims. 
    Threat actors, for instance, tried to bait Russian users with more fake &lt;em&gt;Gosuslugi&lt;/em&gt; web portals. One asked them to provide personal 
    data—supposedly to participate in an oil and gas company payment program and also to receive bonuses from the government:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/28_scam_fakegosuslugi_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/28_scam_fakegosuslugi_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Another scam site promised every Kazakhstan resident assistance in the form of money payments. It was allegedly organized on behalf of a large bank to “avoid problems and disasters”:
  &lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/29_scam_kaz_fakepayments_q1_2025.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/29_scam_kaz_fakepayments_q1_2025.png" alt="Net Fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p&gt;
    Fake investing service websites, including those supposedly belonging to Russian credit organizations, are still a problem. 
    Many of them mimic real bank websites in order to confuse potential victims as much as possible.
  &lt;/p&gt;
  &lt;div class="flex fxCenter"&gt;
    &lt;div class="margRM"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/30_scam_fakebank_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/30_scam_fakebank_q1_2025.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/31_scam_fakebank_q1_2025.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_common_q1/31_scam_fakebank_q1_2025.1.png" alt="Net Fraud" style="max-width: 350px;"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
    Examples of fake Russian bank websites offering access to “investing services”
  &lt;/em&gt;&lt;/p&gt;
  &lt;p&gt;&lt;a href="http://antifraud.drweb.com/dangerous_urls/" target="_blank"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;&lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="formobile"&gt;
    &lt;h2 class="alignCenter"&gt;Malicious and unwanted programs for mobile devices&lt;/h2&gt;
    &lt;p&gt;
      According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q1 2025, 
      &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; 
      ad-displaying trojans, along with &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious fake programs, were the Android 
      threats most commonly encountered; their activity increased, compared to the last quarter of 2024. In addition, users progressively encountered 
      &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans. In contrast, &lt;b&gt;Android.SpyMax&lt;/b&gt; 
      spyware trojans, whose attacks increased in number almost every month in 2024, were detected less frequently.
    &lt;/p&gt;
    &lt;p&gt;
      Our specialists once again discovered many threats on Google Play. Among them were trojans used in various fraudulent schemes, 
      cryptocurrency-stealing malware, and adware trojans.
    &lt;/p&gt;
    &lt;p&gt;The following Q1 2025 events involving mobile malware are the most noteworthy:&lt;/p&gt;
    &lt;ul&gt;
      &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; adware trojan activity increased.&lt;/li&gt;
      &lt;li&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banking trojans were more active.&lt;/li&gt;
      &lt;li&gt;The number of &lt;b&gt;Android.SpyMax&lt;/b&gt; spyware trojans attacks declined.&lt;/li&gt;
      &lt;li&gt;New threats were discovered on Google Play.&lt;/li&gt;
    &lt;/ul&gt;
    &lt;p&gt;
      To find out more about the security-threat landscape for mobile devices in Q1 2025, read our &lt;a href="https://news.drweb.com/show/review/?i=14991&amp;lng=en" target="_blank"&gt;special overview&lt;/a&gt;.
    &lt;/p&gt;
&lt;/section&gt;

</description></item><item><guid>https://news.drweb.com/show/?i=14991&amp;lng=en</guid><title>Doctor Web’s Q1 2025 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=14991&amp;lng=en&amp;c=10</link><pubDate>Thu, 27 Mar 2025 00:00:00 GMT</pubDate><description>



&lt;p&gt;&lt;b&gt;March 27, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
    &lt;p&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, ad-displaying &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; trojans remained the most common Android malware. Moreover, they were detected on protected devices more than twice as often as in the fourth quarter of last year. Second place once again went to &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malware, which cybercriminals use in various fraudulent schemes—their activity increased by almost 8%. Adware trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; family ranked third; the number of their detections almost quintupled.&lt;/newslead&gt;&lt;/p&gt;
    &lt;p&gt;
        Similar dynamics were observed among many banking trojans. For instance, an increase was recorded in the number of attacks involving 
        &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; trojan family members—by 20.68% and 151.71%, respectively. At the same time, &lt;b&gt;Android.SpyMax&lt;/b&gt; 
        trojans, whose activity grew throughout almost all of 2024, were detected 41.94% less frequently than in the previous quarter.
    &lt;/p&gt;
    &lt;p&gt;
        Over the past 3 months, Doctor Web’s specialists discovered dozens of new threats on Google Play. Our virus laboratory’s findings in 
        this catalog included cryptocurrency-stealing malware and other trojans that display intrusive ads, along with the traditionally large 
        number of &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans.
    &lt;/p&gt;
    &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
        &lt;h4 class="white alignCenter"&gt;PRINCIPAL TRENDS OF Q1 2025&lt;/h4&gt;
        &lt;ul&gt;
            &lt;li&gt;Increased activity on the part of adware trojans&lt;/li&gt;
            &lt;li&gt;Increased numbers of &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; banker malware attacks &lt;/li&gt;
            &lt;li&gt;Decreased activity on the part of &lt;b&gt;Android.SpyMax&lt;/b&gt; spyware trojans&lt;/li&gt;
            &lt;li&gt;The emergence of many new threats on Google Play&lt;/li&gt;
        &lt;/ul&gt;
    &lt;/div&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
    &lt;h2 class="alignCenter"&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h2&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/01_malware_q1_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/01_malware_q1_2025_en.png" alt="Malware_Stat_Q1_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.655.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4214&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Trojan apps designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that loads a website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7859&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that displays obnoxious ads. It is a special software module that developers incorporate into applications.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/02_unwanted_q1_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/02_unwanted_q1_2025_en.png" alt="Unwanted_Stat_Q1_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, users can remotely manage these apps. They can block them, display custom dialogs, and track when other software is being installed or removed from a device, etc.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a program that allows users to be monitored via their Android devices. Malicious actors can utilize it to track a target device’s location, take photos and video with the camera, eavesdrop via the microphone, record audio, etc.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/03_riskware_q1_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/03_riskware_q1_2025_en.png" alt="Riskware_Stat_Q1_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. A special module is embedded in such apps, and it allows them to bypass digital signature verification once they have been modified.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some potentially dangerous versions of a specialized framework for developing Android software based on the Lua scripting language. The main logic of Lua-based apps resides in the corresponding scripts that are encrypted and decrypted by the interpreter upon execution. By default, this framework often requests access to a large number of system permissions in order to operate. As a result, the Lua scripts that it executes can potentially perform various malicious actions in accordance with the acquired permissions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A riskware platform that allows applications to launch APK files without installing them. It creates a virtual runtime environment in the context of the apps in which they are integrated. The APK files launched with the help of this platform can operate as if they are part of such programs and can also obtain the same permissions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads specially prepared scripts from the Internet, which can be crafted and added to the common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A packer tool designed to protect Android applications from unauthorized modifications and reverse engineering. This tool is not malicious in itself, but it can be used to protect both harmless and malicious software.&lt;/dd&gt;
    &lt;/dl&gt;
    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/04_adware_q1_2025_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/04_adware_q1_2025_en.png" alt="Adware_Stat_Q1_2025"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some modified versions (mods) of the WhatsApp messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Adware.Basement.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;These are apps that display unwanted ads which often lead to malicious and fraudulent websites. They share a common code base with the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; unwanted applications.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21846&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;An adware module that malicious actors embed into the cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display obnoxious ads.&lt;/dd&gt;
    &lt;/dl&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="gplay"&gt;
    &lt;h2 class="alignCenter"&gt;Threats on Google Play&lt;/h2&gt;
    &lt;p&gt;
        In Q1 2025, Doctor Web’s virus laboratory detected several dozen malicious programs. Among them were various modifications of the trojans 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4213&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4215&lt;/b&gt;, which conceal their presence on infected devices and 
        start displaying ads on top of other apps’ windows and the operating system UI. They masqueraded as software for taking photos and videos 
        with different effects, image-editing programs, an image collection app, and a women’s health diary.
    &lt;/p&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/05_Android.HiddenAds.4213_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/05_Android.HiddenAds.4213_q1_2025.png" alt="Android.HiddenAds_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/06_Android.HiddenAds.4215_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/06_Android.HiddenAds.4215_q1_2025.png" alt="Android.HiddenAds_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        The &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans concealed in the apps “Time Shift Cam” and “Fusion Collage Editor”
    &lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;
        Our specialists also discovered &lt;a href="https://vms.drweb.com/search/?q=Android.CoinSteal&amp;lng=en"&gt;&lt;b&gt;Android.CoinSteal&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.202&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.CoinSteal&amp;lng=en"&gt;&lt;b&gt;Android.CoinSteal&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.203&lt;/b&gt;, and 
        &lt;a href="https://vms.drweb.com/search/?q=Android.CoinSteal&amp;lng=en"&gt;&lt;b&gt;Android.CoinSteal&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.206&lt;/b&gt;, malicious programs designed to steal cryptocurrency that are distributed under the guise 
        of official software from the Raydium and Aerodrome Finance blockchain platforms and the Dydx cryptocurrency exchange.
    &lt;/p&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/07_Android.CoinSteal.202_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/07_Android.CoinSteal.202_q1_2025.png" alt="Android.CoinSteal_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/08_Android.CoinSteal.203_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/08_Android.CoinSteal.203_q1_2025.png" alt="Android.CoinSteal_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        The “Raydium” and “Dydx Exchange” programs are trojans that steal cryptocurrency
    &lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;
        When launched, these malicious apps ask potential victims to enter a mnemonic phrase (the seed phrase)—supposedly to connect their crypto wallet. 
        But, in reality, the data that users provide is sent to threat actors. To further mislead users, forms for entering mnemonic phrases can be disguised 
        as requests from other crypto platforms. As shown in the example below, &lt;a href="https://vms.drweb.com/search/?q=Android.CoinSteal&amp;lng=en"&gt;&lt;b&gt;Android.CoinSteal&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.206&lt;/b&gt; 
        displayed a phishing form allegedly on behalf of the crypto exchange PancakeSwap.
    &lt;/p&gt;
    &lt;div class=" flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/09_seed_q1_2025.png" class="preview"&gt;
              &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/09_seed_q1_2025.1.png" alt="PancakeSwap"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/10_seed_q1_2025.png" class="preview"&gt;
              &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/10_seed_q1_2025.1.png" alt="PancakeSwap"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p&gt;
        At the same time, &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs were once again being distributed via Google Play. 
        Fraudsters passed off many of them as finance-related software, including teaching aids, instruments for accessing 
        investing services, and personal finance software. They loaded various phishing websites, including those used by threat actors to collect personal information.
    &lt;/p&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/11_Android.FakeApp.1803_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/11_Android.FakeApp.1803_q1_2025.png" alt="Android.FakeApp_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/12_Android.FakeApp.1777_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/12_Android.FakeApp.1777_q1_2025.png" alt="Android.FakeApp_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojan apps distributed under the guise of financial software: «Умные Деньги» (“Smart Money”) is &lt;b&gt;Android.FakeApp.1803&lt;/b&gt;, 
        and “Economic Union” is &lt;b&gt;Android.FakeApp.1777&lt;/b&gt;
    &lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;
        Under certain conditions, other &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans loaded bookmaker and online casino sites. Such malware variants were distributed as different games and other software, 
        like a speed-typing trainer and a drawing tutorial. Among them were new modifications of the 
        &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1669&lt;/b&gt; trojan.
    &lt;/p&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/13_Android.FakeApp.1669_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/13_Android.FakeApp.1669_q1_2025.png" alt="Android.FakeApp_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/14_Android.FakeApp.1669_q1_2025.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/april/review_mobile_q1/14_Android.FakeApp.1669_q1_2025.png" alt="Android.FakeApp_Q1_2025" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of malicious fake apps that, instead of providing the declared functionality, could load online casino and bookmaker websites
    &lt;/em&gt;&lt;/p&gt;
    &lt;p&gt;
        To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.
    &lt;/p&gt;
&lt;/section&gt;

&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q1%202025%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank" rel="noopener noreferrer"&gt;Indicators of compromise&lt;/a&gt;

&lt;style&gt;
    .custom-color-link a {
        color: #73b320;
    }
&lt;/style&gt;

</description></item><item><guid>https://news.drweb.com/show/?i=14965&amp;lng=en</guid><title>Doctor Web’s annual virus activity review for 2024</title><link>https://news.drweb.com/show/?i=14965&amp;lng=en&amp;c=10</link><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><description>


&lt;p&gt;&lt;b&gt;January 30, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
    &lt;p&gt;&lt;newslead&gt;In 2024, malicious programs created with the AutoIt scripting language and distributed as part of other malicious apps to make the latter more difficult to detect were once again among the most widespread threats. In addition, adware trojans and all kinds of malicious scripts were highly active. In email traffic, malicious scripts were also most commonly detected. Furthermore, threat actors used spam emails to distribute various trojans, phishing documents, and exploits that allow arbitrary code to be executed.&lt;/newslead&gt;&lt;/p&gt;
    &lt;p&gt;
        Ad-displaying trojans, spyware trojans, and unwanted adware apps were the threats most commonly 
        detected on mobile devices. Throughout the year, increasing activity on the part of mobile banking 
        trojans was observed. In addition, our virus laboratory discovered hundreds of malicious and unwanted 
        programs on Google Play.
    &lt;/p&gt;
    &lt;p&gt;
        Doctor Web’s Internet analysts noted high activity on the part of online fraudsters, whose arsenal included both old and new schemes for deceiving users.
    &lt;/p&gt;
    &lt;p&gt;
        Compared to 2023, the number of user requests to decrypt files affected by encoder trojans decreased. 
        At the same time, our specialists observed many information security incidents and events. 
        Over the course of the year, Doctor Web investigated several targeted attacks, uncovered another infection 
        impacting Android TV box sets, and repelled an attack on its own infrastructure.
    &lt;/p&gt;
    
    &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
        &lt;h4 class="white alignCenter"&gt;Principal trends of the year&lt;/h4&gt;
        &lt;ul&gt;
          &lt;li&gt;Trojans created with the AutoIt scripting language remained highly active.&lt;/li&gt;
          &lt;li&gt;Malicious scripts were among the most widespread threats.&lt;/li&gt;
          &lt;li&gt;Malicious scripts and various trojans were among the threats most commonly detected in email traffic.&lt;/li&gt;
          &lt;li&gt;New targeted attacks were detected.&lt;/li&gt;
          &lt;li&gt;Threat actors exploited eBPF technology more often to conceal their malicious activity.&lt;/li&gt;
          &lt;li&gt;The number of requests to decrypt files affected by encoder trojans decreased.&lt;/li&gt;
          &lt;li&gt;Internet fraudsters were highly active.&lt;/li&gt;
          &lt;li&gt;Cybercriminals used mobile banking trojans more frequently.&lt;/li&gt;
          &lt;li&gt;Many new threats were discovered on Google Play.&lt;/li&gt;
        &lt;/ul&gt;
    &lt;/div&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
    &lt;h2 class="alignCenter"&gt;The most notable events of 2024&lt;/h2&gt;
    &lt;p&gt;
        In January, Doctor Web’s specialists &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=14792" target="_blank" rel="noopener noreferrer"&gt;informed&lt;/a&gt; 
        customers about the mining trojan &lt;a href="https://vms.drweb.com/search/?q=Trojan.BtcMine.3767&amp;lng=en"&gt;&lt;b&gt;Trojan.BtcMine.3767&lt;/b&gt;&lt;/a&gt;, which was concealed in pirated programs that were being 
        distributed via a specially created Telegram channel and a number of websites. This malware infected tens of thousands of 
        Windows computers. To anchor itself in an attacked system, it created a scheduler task for its own autorun and added itself 
        to the Windows Defender anti-virus exceptions. Next, it injected a component directly responsible for cryptocurrency mining into 
        &lt;span class="string"&gt;explorer.exe&lt;/span&gt; (Windows Explorer). 
        &lt;a href="https://vms.drweb.com/search/?q=Trojan.BtcMine.3767&amp;lng=en"&gt;&lt;b&gt;Trojan.BtcMine.3767&lt;/b&gt;&lt;/a&gt; also allowed a number of other malicious actions to be performed, e.g., fileless rootkits can be installed, 
        access to websites can be blocked, and Windows updates can be disabled.
    &lt;/p&gt;
    &lt;p&gt;
        In March, our company &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=14823" target="_blank" rel="noopener noreferrer"&gt;published research&lt;/a&gt; 
        on a targeted attack against a Russian enterprise in the mechanical-engineering sector. An investigation into the incident revealed a multi-stage 
        infection vector and the use of several malicious programs by the attackers. Among these programs, of greatest interest was the &lt;a href="https://vms.drweb.com/search/?q=JS.BackDoor.60&amp;lng=en"&gt;&lt;b&gt;JS.BackDoor.60&lt;/b&gt;&lt;/a&gt; 
        backdoor, through which the main interaction between the attackers and the infected computer took place. This trojan uses its own JavaScript framework and 
        consists of a main body and additional modules. It allows files to be stolen from infected machines, keystrokes to be hijacked, and screenshots to be taken. 
        It can download its own updates and expand its functionality by downloading new modules.
    &lt;/p&gt;
    &lt;p&gt;
        In May, Doctor Web’s virus analysts &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=14860" target="_blank" rel="noopener noreferrer"&gt;discovered&lt;/a&gt; 
        the trojan clicker &lt;a href="https://vms.drweb.com/search/?q=Android.Click.414.origin&amp;lng=en"&gt;&lt;b&gt;Android.Click.414.origin&lt;/b&gt;&lt;/a&gt; in Love Spouse, an app used to control adult toys, and also in the QRunning app, used to track 
        physical activity. Both were distributed through Google Play. &lt;a href="https://vms.drweb.com/search/?q=Android.Click.414.origin&amp;lng=en"&gt;&lt;b&gt;Android.Click.414.origin&lt;/b&gt;&lt;/a&gt; was disguised as a component for collecting debugging 
        information and was embedded into several new versions of the target apps. Later, the developer of the Love Spouse program updated the app, and the 
        trojan was no longer present in it. There was no reaction from the developer of the second program. &lt;a href="https://vms.drweb.com/search/?q=Android.Click.414.origin&amp;lng=en"&gt;&lt;b&gt;Android.Click.414.origin&lt;/b&gt;&lt;/a&gt; 
        had modular architecture and could perform various malicious tasks with the help of its components. It could collect information about an infected device, 
        covertly load webpages, display ads, perform clicks, and interact with the contents of loaded pages.
    &lt;/p&gt;
    &lt;p&gt;
        In July, we &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=14877" target="_blank" rel="noopener noreferrer"&gt;informed&lt;/a&gt; users about the emergence of a Linux version 
        of the well-known remote access trojan TgRat, which is used for targeted attacks on computers. Dubbed &lt;a href="https://vms.drweb.com/search/?q=Linux.BackDoor.TgRat.2&amp;lng=en"&gt;&lt;b&gt;Linux.BackDoor.TgRat.2&lt;/b&gt;&lt;/a&gt;, the new variant of this 
        malware was discovered during an investigation into an information security incident that a hosting provider contacted us about. Dr.Web anti-virus detected a suspicious 
        file on the server of one of their clients; it turned out to be the backdoor dropper that actually installed the trojan. Threat actors controlled 
        &lt;a href="https://vms.drweb.com/search/?q=Linux.BackDoor.TgRat.2&amp;lng=en"&gt;&lt;b&gt;Linux.BackDoor.TgRat.2&lt;/b&gt;&lt;/a&gt; through a private Telegram group, using the Telegram bot connected to it. 
        Through the messenger, they could download files from a compromised system, take screenshots, remotely execute commands, or upload files to a computer via chat attachments.
    &lt;/p&gt;
    &lt;p&gt;
        In early September, we published an &lt;a href="https://news.drweb.com/show/?i=14899&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;article&lt;/a&gt; 
        on our website, detailing the case of a failed spear-phishing attack on a major Russian enterprise in the rail freight industry. Several months 
        earlier, the company’s information security team had detected a suspicious email with a file attached to it. Our virus analysts’ examination of 
        it showed that it was a Windows shortcut disguised as a PDF document, and that it had hardcoded parameters for launching the PowerShell command 
        interpreter. Opening this shortcut would lead to a multi-stage infection of the target system, with several malicious programs designed for cyber 
        espionage. One of them was &lt;a href="https://vms.drweb.com/search/?q=Trojan.Siggen27.11306&amp;lng=en"&gt;&lt;b&gt;Trojan.Siggen27.11306&lt;/b&gt;&lt;/a&gt;, which exploited the 
        &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6473" target="_blank" rel="noopener noreferrer"&gt;CVE-2024-6473&lt;/a&gt; vulnerability in 
        Yandex Browser to intercept the DLL search order (DLL Search Order Hijacking). The trojan placed a malicious DLL library into the browser installation 
        directory; this file had the same name as the system component &lt;span class="string"&gt;Wldp.dll&lt;/span&gt; responsible for securely launching applications. 
        Since the malicious file was located in the browser directory, it received higher priority to be loaded when the program was launched, thanks to the 
        browser vulnerability. The library also obtained all the permissions of the browser. This vulnerability was later fixed.
    &lt;/p&gt;
    &lt;p&gt;
        A little later, our specialists &lt;a href="https://news.drweb.com/show/?i=14900&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;reported&lt;/a&gt; 
        on another attack on Android-based TV box sets. In this campaign, the malicious program &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; 
        was used. It infected nearly 1.3 million devices belonging to users in 197 countries. This was a modular backdoor that placed its components 
        into the system storage area and, upon receiving the attackers’ commands, could covertly download and run other programs.
    &lt;/p&gt;
    &lt;p&gt;
        Moreover, in September, we detected a &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=14904" target="_blank" rel="noopener noreferrer"&gt;targeted attack&lt;/a&gt; 
        on our company’s resources. Doctor Web’s specialists promptly stopped the attempt to damage our infrastructure, 
        &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=14907" target="_blank" rel="noopener noreferrer"&gt;successfully repelling the attack&lt;/a&gt;. 
        At the same time, none of our users were harmed.
    &lt;/p&gt;
    &lt;p&gt;
        In October, Doctor Web’s virus analysts &lt;a href="https://news.drweb.com/show/?i=14918&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;reported&lt;/a&gt;
        on the discovery of a number of new malicious programs for Linux. They were uncovered thanks to a study of attacks on devices that had the Redis 
        database management system installed on them. This system is increasingly becoming the target of cybercriminals wanting to exploit the various 
        vulnerabilities in it. Among the threats detected were backdoors, droppers, and a new modification of a rootkit that installs the Skidmap mining 
        trojan on compromised devices. This miner has been active since 2019, and its primary targets are large servers and cloud environments.
    &lt;/p&gt;
    &lt;p&gt;
        Also in October, our virus laboratory uncovered a &lt;a href="https://news.drweb.com/show/?i=14920&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;large-scale campaign&lt;/a&gt;
        aimed at distributing malware for cryptocurrency mining and theft. Over 28,000 users, most of whom were from Russia, suffered from the actions of the attackers. The trojans 
        were hiding in pirated software that was being distributed via fraudulent websites created on the GitHub platform. In addition, the malware creators placed links for downloading 
        malicious programs under videos posted on the YouTube platform.
    &lt;/p&gt;
    &lt;p&gt;
        In November, our experts &lt;a href="https://news.drweb.com/show/?i=14935&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;discovered&lt;/a&gt;
        a number of new variants of the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; trojan, whose task is to load websites. Unlike the malware most similar to it, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; receives target website addresses from the TXT records of malicious DNS servers. For this, it uses the modified 
        code of the open-source library dnsjava. At the same time, the trojan exhibits malicious activity only when connected to the Internet through 
        certain providers. In other cases, it operates as harmless software.
    &lt;/p&gt;
    &lt;p&gt;
        At the end of 2024, while investigating a request from one of our clients, Doctor Web’s virus laboratory specialists detected an ongoing
        &lt;a href="https://news.drweb.com/show/?lng=en&amp;i=14955" target="_blank" rel="noopener noreferrer"&gt;hacker campaign&lt;/a&gt;
        primarily targeting users from Southeast Asia. During the attacks, cybercriminals used a range of malicious programs as well as methods 
        and techniques that are only increasing in popularity among virus writers. One of them involves exploiting eBPF (extended Berkeley Packet 
        Filter) technology, which was created to provide enhanced control over the network subsystem of the Linux operating system and its processes. 
        This technology was used to conceal malicious network activity and processes, collect confidential information, and bypass firewalls and 
        intrusion detection systems. Another technique involved storing the trojan configuration not on the C&amp;C server, but on public platforms such 
        as GitHub and blogs. The third feature of the attacks was the use of post-exploitation frameworks in tandem with malicious apps. Although such 
        tools are not malicious and are used in security audits of digital systems, their functionality and the presence of vulnerability databases 
        can expand the capabilities of attackers.
    &lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="virobst"&gt;
    &lt;h2 class="alignCenter"&gt;The malware landscape&lt;/h2&gt;
    &lt;p&gt;
        According to the statistics collected by Dr.Web anti-virus, the total number of threats detected in 2024 increased by 26.20%, compared to 2023. 
        The number of unique threats increased by 51.22%. Among the most common malicious programs were trojans created in the AutoIt scripting language. 
        They are distributed as part of other malware and are designed to make the latter more difficult to detect. Moreover, users encountered various malicious scripts and adware trojans.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/01_stat_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/01_stat_2024_en.png" alt="stat_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
        &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of Russian cities.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1224&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1131&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1124&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1222&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for packed versions of the &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malicious app that are written in the AutoIt scripting language. This trojan is distributed as part of a group of several malicious applications, including a miner, a backdoor, and a self-propagating module. &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; performs various malicious actions that make it difficult for the main payload to be detected.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.StartPage1.62722&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A malicious program that can modify the home page in the browser settings.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.BPlug.3814&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for malicious components of the WinSafe browser extension. These components are JavaScript files that display intrusive ads in browsers.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;VBS.KeySender.6&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A malicious script that, in an infinite loop, searches for windows containing the text &lt;span class="string"&gt;mode extensions&lt;/span&gt;, &lt;span class="string"&gt;разработчика&lt;/span&gt; and &lt;span class="string"&gt;розробника&lt;/span&gt; and sends them an Escape key press event, forcibly closing them.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;BAT.AVKill.37&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A component of the &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malicious program. This script launches other malware components, sets them to autorun via Windows Task Scheduler, and also adds them to Windows Defender’s anti-virus exceptions.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.Unsecure.7&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan that blocks the launch of anti-viruses and other software through AppLocker policies in the Windows operating system.&lt;/dd&gt;
    &lt;/dl&gt;

    &lt;p&gt;
        As for email threats, the most widespread were various malicious scripts and all kinds of trojans, including backdoors, 
        malware downloaders and droppers, trojans with spyware functionality, malicious cryptocurrency miners, and others. 
        Threat actors also distributed phishing documents, often fake login forms mimicking those on popular websites. 
        Additionally, users encountered worms and malicious apps that exploit vulnerabilities in Microsoft Office documents.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/02_email_traffic_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/02_email_traffic_2024_en.png" alt="mail_traffic_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
        &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of Russian cities.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;JS.Inject&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A family of malicious JavaScripts that inject a malicious script into the HTML code of webpages.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;LNK.Starter.56&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a shortcut that is crafted in a specific way. This shortcut is distributed through removable media, like USB flash drives. To mislead users and conceal its activities, it has a default icon of a disk. When launched, it executes malicious VBS scripts from a hidden directory located on the same drive as the shortcut itself.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Win32.HLLW.Rendoc.3&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A network worm that spreads via removable storage media and other channels.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Exploit.CVE-2018-0798.4&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;An exploit designed to take advantage of Microsoft Office software vulnerabilities so that an attacker can run arbitrary code.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1122&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a packed version of the &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malicious app that is written in the AutoIt scripting language. This trojan is distributed as part of a group of several malicious applications, including a miner, a backdoor, and a self-propagating module. &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; performs various malicious actions that make it difficult for the main payload to be detected.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.SpyBot.699&amp;lng=en"&gt;&lt;b&gt;Trojan.SpyBot.699&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
        &lt;dd&gt;A multi-module banking trojan. It allows cybercriminals to download and launch various applications on infected devices and run arbitrary code.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;VBS.BtcMine.13&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;VBS.BtcMine.12&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A VBS script designed to covertly mine cryptocurrencies.&lt;/dd&gt;
    &lt;/dl&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="encruptor"&gt;
    &lt;h2 class="alignCenter"&gt;Encryption ransomware&lt;/h2&gt;
    &lt;p&gt;
        Compared with 2023, in 2024, Doctor Web’s technical support service registered 33.05% fewer user requests to decrypt 
        files affected by encryption trojans. The dynamics of when those requests were registered is shown in the graph below:
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/03_encoder_requests_14_2024_en.1.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/03_encoder_requests_14_2024_en.1.png" alt="encoders_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;The most common encoders of 2024:&lt;/p&gt;
    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; (13.13% of user requests)&lt;/dt&gt;
        &lt;dd&gt;An encoder trojan also known as Mimic. It uses the everything.dll library from the legitimate software Everything, which is designed to instantly locate files on Windows computers.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.3953&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.3953&lt;/b&gt;&lt;/a&gt; (12.10% of user requests)&lt;/dt&gt;
        &lt;dd&gt;An encoder trojan that has several versions and modifications. It uses the AES-256 algorithm in CBS mode to encrypt files.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.26996&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.26996&lt;/b&gt;&lt;/a&gt; (7.44% of user requests)&lt;/dt&gt;
        &lt;dd&gt;A trojan encoder known as STOP Ransomware. It attempts to obtain a private key from a server. If unsuccessful, it uses the hardcoded one. It uses Salsa20 stream cipher to encrypt files.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35067&lt;/b&gt; (2.21% of user requests)&lt;/dt&gt;
        &lt;dd&gt;An encoder trojan also known as Macop (&lt;b&gt;Trojan.Encoder.30572&lt;/b&gt; is one of its other variants). It has a small size, about 30-40 Kbytes. This is partially due to the fact that the trojan does not carry third-party cryptographic libraries and uses exclusively CryptoAPI functions for encryption and key generation. It uses the AES-256 algorithm to encrypt files, and the keys themselves are encrypted with RSA-1024.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Trojan.Encoder.37369&lt;/b&gt; (2.10% of user requests)&lt;/dt&gt;
        &lt;dd&gt;One of many modifications of #Cylance ransomware. To encrypt files, it uses the ChaCha12 algorithm with the Curve25519 (X25519) elliptic curve key exchange scheme.&lt;/dd&gt;
    &lt;/dl&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="netfraud"&gt;
    &lt;h2 class="alignCenter"&gt;Network fraud&lt;/h2&gt;
    &lt;p&gt;
        Over the course of 2024, Doctor Web’s Internet analysts observed high activity on the part of cyber fraudsters 
        using both traditional and new scenarios to deceive users. In the Russian segment of the Internet, the most 
        widespread schemes were again those using fraudulent sites of multiple formats. Some of them were fake sites 
        of online stores and social networks with promotions and prize draws allegedly sponsored by them. Potential 
        victims always “win” on such websites, but to get their nonexistent prize, they are asked to pay a “commission”.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/04_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/04_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fraudulent site, allegedly related to a Russian online store, offers the visitor the chance to participate in a nonexistent prize draw&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/05_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/05_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fake social network website offers the chance to “try your luck” and win large cash prizes or other gifts&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        One of the current variants of such a scheme is not new: using fake websites of retailers and household appliance and electronics stores to offer 
        users the opportunity to buy goods at a discount. On such sites, potential victims are typically asked to pay for their “orders” with a bank card. 
        But last year, fraudsters started resorting to the Faster Payment System.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/06_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/06_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fake website of a household appliance and electronics store promises potential victims big discounts&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/07_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/07_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fraudulent site offers visitors the option to use the Faster Payment System as one way to pay for their “order”&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        The scheme involving “free” lottery tickets also remained popular. Lottery draws, allegedly performed online, always end in “winnings” for potential victims. 
        To get their prize, users also have to pay a “commission”.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/08_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/08_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;This user has supposedly won 314,904 rubles in the lottery, and to “get” their prize, they need to pay a “commission”&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Scammers also kept fake finance-themed websites in their arsenal. Popular were such topics as receiving some payments from the government or private companies, 
        investing in the oil and gas sector, financial literacy training, trading stocks with the help of “unique” automated systems or “verified” strategies that 
        supposedly guarantee income, and others. Threat actors engaged in strategies that included exploiting the names of media personalities to attract users’ attention. 
        Examples of such sites are shown below.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/09_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/09_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fraudulent site offers visitors the chance to “make up to 10,000 euros per month on the unique WhatsApp platform”&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/10_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/10_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;Russian singer Shaman “shared a secret platform for success” that allegedly can generate an income of $14,000 per month&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/11_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/11_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;The fake site of an oil and gas company offers access to an investment service and promises income starting at 150,000 rubles&lt;/em&gt;&lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
          &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/14_fraud_2024.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/14_fraud_2024.1.png" alt="netfraud_2024"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/13_fraud_2024.png" class="preview"&gt;
            &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/13_fraud_2024.1.png" alt="netfraud_2024"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;Fraudulent sites that imitate real bank investing services&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Meanwhile, our specialists detected new schemes. For example, scammers, allegedly on behalf of large companies, 
        offered users a reward for participating in service-quality surveys. Such fakes included fictitious websites of 
        credit organizations. On these, users were asked to provide sensitive personal information that could include their 
        full name, the mobile phone number linked with their bank account, and their bank card number.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/15_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/15_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fake bank website offers a reward of 6,000 rubles for participating in a survey on “improving service quality”&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        At the same time, such fakes also affected users in other countries. For instance, the site shown below assured European users that they will get dividends 
        for investing in promising sectors of the economy:
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/16_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/16_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        And this site advertised a “new investing platform from Google” that could allegedly help users make money, starting at €1000:
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/17_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/17_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        Another fraudulent Internet resource offered Slovak users the opportunity to “make more than $192,460 per month” with the help of some investing service:
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/18_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/18_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        Users from Azerbaijan allegedly could also significantly improve their financial situation, making from 1000 manat per month. 
        All they had to do was participate in a short survey and get access to the service, which was supposedly related to an Azerbaijani oil and gas company:
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/19_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/19_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        At the end of the year, fraudsters held to tradition and began adapting these fake websites to the New Year holiday theme. 
        The next fake Internet resource of a crypto exchange, for example, promised Russian users New Year payments:
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/20_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/20_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        Another site offered users holiday payments supposedly on behalf of an investing company:
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/21_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/21_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        And this fraudulent Internet resource promised users from Kazakhstan large payments in honor of Independence Day as part of a “New Year offer”: 
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/22_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/22_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        Throughout the year, our Internet analysts detected other phishing sites as well. Among them were fake websites of online education services. 
        One, for instance, simulated the appearance of a genuine site and offered programming courses. To “receive a consultation”, users were asked to provide their personal data.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/23_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/23_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fake website that was disguised as a real online resource of an online education service&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Additionally, attempts to steal Telegram user accounts continued. For this, fraudsters used phishing websites camouflaged as various online voting platforms. 
        Among these, sites asking visitors to “vote in children’s drawing competitions” were widespread again. Potential victims are asked to provide their mobile phone 
        number to receive a one-time code. However, when they enter this code on such a website, users are giving scammers access to their accounts.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/24_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/24_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A phishing website for “voting” in an online children’s drawing competition&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        On other similar sites, potential victims were offered a “free” subscription to a Telegram Premium service. 
        Users are asked to log into their account, but the confidential data that they enter there is sent to the 
        cybercriminals who then hijack their accounts. It is noteworthy that the links to these sites are distributed 
        in a variety of ways, including through the messenger itself. And the real address of the target site in such 
        messages often does not match the one that users see.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/25_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/25_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A phishing message in Telegram, in which, in order to “activate” a Telegram Premium subscription, users are asked to follow the given link. The text of this link does not in fact match the target URL&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/26_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/26_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;The phishing site loaded after the link in the fraudulent message is followed&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/27_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/27_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;After the user clicks the button on the previous page, the website displays an authorization form that looks like the genuine one&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        To distribute links to fraudulent sites, cybercriminals use email spam, among other avenues. Over the course of last year, our Internet analysts detected many different spam campaigns. 
        They observed the active distribution of phishing emails targeting Japanese users. For example, scammers, allegedly on behalf of some bank, informed potential victims about some purchase 
        and suggested that they view the details of the “payment” by following the provided link. In reality, this link led to a phishing Internet resource.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/28_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/28_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A phishing email, supposedly sent on behalf of a bank and offering Japanese users the option to view the details of a payment&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        In another popular scenario, threat actors, supposedly on behalf of credit organizations, were sending fake notifications containing information about a month’s 
        worth of bank card expenses. At the same time, the links to phishing sites were often concealed and seemed harmless in the email texts.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/29_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/29_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;In the texts of spam emails, users saw the links to real bank web addresses, but when clicked, these addresses led to a fraudulent Internet resource&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        One spam campaign targeted European users. For example, users in Belgium encountered phishing emails that claimed their bank accounts had been “blocked”. 
        To get them “unblocked”, they were asked to follow a link which, in fact, led to the fraudsters’ website.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/30_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/30_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;An unwanted letter threatens a potential victim with a “blocked” bank account&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        We also detected other spam campaigns, for example, those aimed at an English-speaking audience. In one such campaign, 
        potential victims received messages asking them to confirm receipt of a large money transfer. However, the link in these 
        messages led to a phishing online bank authorization form, which resembled the one on the genuine bank’s website.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/31_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/31_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A spam email saying that the user supposedly needs to confirm receipt of $1,218.16 US&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Russian users most often encountered spam letters that helped fraudsters lure potential victims to the phishing websites 
        we covered earlier in this review. Common topics for these unwanted messages were prizes and discounts from online stores, 
        free lottery tickets, and access to investment services. Examples of them are shown in the screenshots below.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/32_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/32_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A letter, allegedly from an online store, offering the chance to participate in a “prize draw”&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/33_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/33_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A letter, allegedly from a credit organization, offering the chance to “become a successful investor”&lt;/em&gt;&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_common/34_fraud_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_common/34_fraud_2024.png" alt="netfraud_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A letter, allegedly sent on behalf of an electronics store, offering a promo code that the recipient can activate to get a discount on goods&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="formobile"&gt;
    &lt;h2 class="alignCenter"&gt;Mobile devices&lt;/h2&gt;
    &lt;p&gt;
        According to detection statistics collected by Dr.Web Security Space for mobile devices, in 2024, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; trojans were once again the most common Android malicious programs. They accounted for more than a third of malware detections. 
        Such trojans conceal their presence on infected devices and display ads. Among the most active members of this family were &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3956&lt;/b&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3851&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.655.origin&lt;/b&gt;, 
        and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3994&lt;/b&gt;. At the same time, users encountered &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt; trojan variants capable of running automatically after installation. 
        Other widespread malicious programs were &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans, used in a variety of fraudulent schemes, and &lt;a href="https://vms.drweb.com/search/?q=Android.Spy&amp;lng=en"&gt;&lt;b&gt;Android.Spy&lt;/b&gt;&lt;/a&gt; spyware trojans.
    &lt;/p&gt;
    &lt;p&gt;
        The most active unwanted programs were members of the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;, and &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt; families. 
        The first ones offer users the opportunity to get virtual rewards by completing various tasks and then withdraw those rewards as real money. 
        However, users never receive any payments. The second ones are programs modified through a specialized cloud service. When modified, an uncontrolled 
        code and a number of dangerous permissions are added to them. The third ones are programs that imitate anti-virus software, detect nonexistent threats 
        and offer users the option to buy the full version to fix the “problems” that had allegedly been found.
    &lt;/p&gt;
    &lt;p&gt;
        &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt; utilities, which allow Android apps to run without being installed, were once again the most commonly detected potentially dangerous software. 
        They accounted for more than a third of the detections of this type of threat. Also widespread were apps modified with the NP Manager tool (these are detected as 
        &lt;b&gt;Tool.NPMod&lt;/b&gt;). A special module is embedded into such modified programs, which allows them to bypass the digital signature verification process once they have been modified. 
        Apps protected with the 
        &lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; software packer were also detected quite often, as was the &lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; framework. 
        The latter allows installed Android programs to be modified and potentially dangerous Lua scripts to be executed.
    &lt;/p&gt;
    &lt;p&gt;
        The most widespread adware software was the new family &lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;, which accounted for almost half of all detections. 
        These are specially modified versions of the WhatsApp messenger, whose functions have been injected with a specific code for loading advertising links. 
        Members of the &lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt; family ranked second, while another new family, 
        &lt;b&gt;Adware.Basement&lt;/b&gt;, occupied third place.
    &lt;/p&gt;
    &lt;p&gt;
        In 2024, Android banking trojans were slightly more active than in 2023. At the same time, our specialists observed an increase in the popularity 
        of some techniques used to protect malware from analysis and detection. This was commonly seen in banking trojans. Such techniques included undertaking various 
        manipulations with the ZIP file format (as Android APK files are based on this format) and the configuration file &lt;span class="string"&gt;AndroidManifest.xml&lt;/span&gt; of Android apps.
    &lt;/p&gt;
    &lt;p&gt;
        The widespread distribution of the &lt;b&gt;Android.SpyMax&lt;/b&gt; malicious program is worth a separate mention. Cybercriminals actively used this spyware trojan as a banking trojan, 
        particularly against Russian users (46.23% of detections), and also against Brazilian (35.46% of detections) and Turkish (5.80% of detections) Android device owners.
    &lt;/p&gt;
    &lt;p&gt;
        Throughout the year, Doctor Web’s virus analysts detected over 200 different threats on Google Play. Among them were trojans that subscribe users to paid services, 
        spyware trojans, and fraudulent and adware apps. Combined, they have been downloaded at least 26.7 million times. Moreover, our specialists detected another attack on 
        Android TV box sets: the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor has infected almost 1.3 million user devices in 197 countries. This trojan placed its components into the system 
        storage area and, when commanded, could covertly download third-party apps from the Internet and install them.
    &lt;/p&gt;
    &lt;p&gt;
        To find out more about the security-threat landscape for mobile devices in 2024, read our &lt;a href="https://news.drweb.com/show/review/?i=14970&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;special overview&lt;/a&gt;.
    &lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="future"&gt;
    &lt;h2 class="alignCenter"&gt;Prospects and possible trends&lt;/h2&gt;
    &lt;p&gt;
        The events of the past year have once again demonstrated the diversity of the modern cyber-threat landscape. Malicious actors are interested in both large targets, 
        like private corporate and government sector, and ordinary users. The functionality of many of the malicious programs used in the targeted attacks we investigated 
        indicates that virus writers are constantly searching for new opportunities to improve their methods of conducting malicious campaigns and developing their tools. 
        Over time, new techniques inevitably transfer to more widespread threats. In this regard, in 2025, we may witness the emergence of more trojans that use eBPF technology 
        to conceal their malicious activity. Moreover, we should also expect new targeted attacks, including those that utilize exploits.
    &lt;/p&gt;
    &lt;p&gt;
        One of the main goals of cybercriminals is to make money illegally, so 2025 may see an increase in the activity of banking and ad-displaying trojans. 
        In addition, users may be threatened by more malware with spyware functionality.
    &lt;/p&gt;
    &lt;p&gt;
        At the same time, not only Windows computer users will be the target, but also users of other operating systems, such as Linux and macOS. 
        The distribution of mobile threats will continue. Android device owners should above all be wary of the emergence of new spyware and banking 
        trojans as well as malicious and unwanted ad-displaying apps. New attempts to infect Android TVs, Android TV box sets, and other Android-based 
        devices are also to be expected. Moreover, chances are high that new threats will emerge on Google Play.
    &lt;/p&gt;

    &lt;!--AVP_BANNER start--&gt;
  &lt;div class="reviews-banners"&gt;
    &lt;a class="avp" href="https://www.drweb.com/pravda/issues/?lng=en" target="_blank"&gt;
        &lt;div class="avp__box avp__box--img"&gt;
            &lt;picture&gt;
                &lt;source srcset="https://st.drweb.com/static/new-www/review_banners/avp/avp-banner_885.png" media="(min-width: 885px)" /&gt;
                &lt;source srcset="https://st.drweb.com/static/new-www/review_banners/avp/avp-banner_768.png" media="(min-width: 768px)" /&gt;
                &lt;source srcset="https://st.drweb.com/static/new-www/review_banners/avp/avp-banner_480.png" media="(min-width: 480px)" /&gt;
                &lt;img class="avp__img" src="https://st.drweb.com/static/new-www/review_banners/avp/avp-banner_320.png" alt="The Anti-virus Times." /&gt;
            &lt;/picture&gt;
        &lt;/div&gt;
        &lt;div class="avp__box avp__box--content"&gt;
            &lt;div class="avp__box avp__box--text"&gt;
                &lt;h2 class="avp__title"&gt;The Anti-virus Times&lt;/h2&gt;
                &lt;h3 class="avp__subtitle"&gt;Infinite horizons&lt;/h3&gt;
            &lt;/div&gt;
            &lt;div class="avp__box avp__box--btn"&gt;
                &lt;button class="avp__btn"&gt;read&lt;/button&gt;
            &lt;/div&gt;
        &lt;/div&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;!--AVP_BANNER end--&gt;

&lt;/section&gt;

</description></item><item><guid>https://news.drweb.com/show/?i=14970&amp;lng=en</guid><title>Doctor Web’s review of virus activity on mobile devices in 2024</title><link>https://news.drweb.com/show/?i=14970&amp;lng=en&amp;c=10</link><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><description>


&lt;p&gt;&lt;b&gt;January 30, 2025&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
    &lt;p&gt;&lt;newslead&gt;In 2024, ad-displaying trojans were once again the most widespread Android threats. Fraudulent software, ransom trojans, clickers, and banking trojans were more active than in the previous year. Among the latter, compared to 2023, the most common were simple banking trojans that steal only online bank account access data and SMS confirmation codes.&lt;/newslead&gt;&lt;/p&gt;
    &lt;p&gt;
        Among the most active unwanted software programs were apps offering users the opportunity to complete various tasks in exchange 
        for virtual rewards, which can supposedly be converted into real money. The most commonly detected riskware apps were tools that 
        allow Android programs to launch without being installed. And the most active adware programs were specially modified WhatsApp 
        messenger versions whose functions had been injected with code for loading adware URLs.
    &lt;/p&gt;
    &lt;p&gt;
        Over the course of last year, Doctor Web's malware analysts discovered hundreds of new threats on Google Play, with over 26.7 million 
        cumulative downloads. Among these were malicious programs, including a spyware trojan, and unwanted and adware apps.
    &lt;/p&gt;
    &lt;p&gt;
        Our experts also uncovered a new attack on Android-based TV box sets. Around 1.3 million devices were affected by a backdoor 
        that infected the system storage and, when commanded by attackers, could download and install third-party software.
    &lt;/p&gt;
    &lt;p&gt;
        In addition, Doctor Web’s virus analysts noted the growing popularity of a number of techniques aimed at making Android 
        malware more complicated to analyze and more difficult for antiviruses to detect. These techniques included various 
        manipulations with the ZIP archive format (the APK files of Android apps are based on the ZIP format), manipulations with 
        the apps’ configuration file 
        &lt;span class="string"&gt;AndroidManifest.xml&lt;/span&gt;,
        and others. These methods were most often found to be used in banking trojans.
    &lt;/p&gt;

    &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
        &lt;h4 class="white alignCenter"&gt;PRINCIPAL TRENDS IN 2024&lt;/h4&gt;
        &lt;ul&gt;
            &lt;li&gt;Ad-displaying malware remained the most widespread threat;&lt;/li&gt;
            &lt;li&gt;An increase in banking trojan activity;&lt;/li&gt;
            &lt;li&gt;
                Cybercriminals increasingly used simple &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt; 
                banking trojans, which steal only login data for online bank accounts and also verification codes from SMS;
            &lt;/li&gt;
            &lt;li&gt;
                Threat actors increasingly resorted to manipulating the format of APK apps and their structural components 
                to avoid being detected by anti-viruses and to make it more difficult for their malware to be analyzed;
            &lt;/li&gt;
            &lt;li&gt;An increase in the number of &lt;a href="https://vms.drweb.com/search/?q=Android.Locker&amp;lng=en"&gt;&lt;b&gt;Android.Locker&lt;/b&gt;&lt;/a&gt; ransomware trojans and &lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt; trojan clickers;&lt;/li&gt;
            &lt;li&gt;The emergence of many new threats on Google Play.&lt;/li&gt;
        &lt;/ul&gt;
    &lt;/div&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="events"&gt;
    &lt;h2 class="alignCenter"&gt;The most notable events of 2024&lt;/h2&gt;
    &lt;p&gt;
        Last May, Doctor Web’s experts 
        &lt;a href="https://news.drweb.com/show/?i=14860&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;informed&lt;/a&gt;
        users about the &lt;a href="https://vms.drweb.com/search/?q=Android.Click.414.origin&amp;lng=en"&gt;&lt;b&gt;Android.Click.414.origin&lt;/b&gt;&lt;/a&gt; trojan clicker, which was found in an app used to control sex toys 
        and in software for tracking physical activity. Both programs were distributed through Google Play and had more than 
        1.5 million installs combined. 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Click.414.origin&amp;lng=en"&gt;&lt;b&gt;Android.Click.414.origin&lt;/b&gt;&lt;/a&gt; had a modular structure and used its components to execute certain tasks. 
        For example, the trojan covertly loaded advertising websites and performed various actions on them. It could 
        scroll webpages, enter text into forms, mute audio on webpages, and take screenshots of webpages to analyze 
        their contents and click on desired areas. In addition, &lt;a href="https://vms.drweb.com/search/?q=Android.Click.414.origin&amp;lng=en"&gt;&lt;b&gt;Android.Click.414.origin&lt;/b&gt;&lt;/a&gt; 
        sent detailed information about infected devices to its C&amp;C server. At the same time, the clicker did not 
        specifically attack certain users, and it did not start on devices where the interface language was set to Chinese.
    &lt;/p&gt;

    &lt;div class=" flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/01_Android.Click.414.origin_2024_1.png" class="preview"&gt;
              &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/01_Android.Click.414.origin_2024_1.1.png" alt="Android.Click_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/01_Android.Click.414.origin_2024_2.png" class="preview"&gt;
              &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/01_Android.Click.414.origin_2024_2.1.png" alt="Android.Click_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;Some versions of the Love Spouse and QRunning programs had the &lt;b&gt;Android.Click.414.origin&lt;/b&gt; trojan hidden in them&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        In September, our specialists revealed the details of their 
        &lt;a href="https://news.drweb.com/show/?i=14900&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;analysis&lt;/a&gt;
        regarding cases of Android TV box sets being infected with the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor. 
        This modular malware affected nearly 1.3 million devices belonging to users in 197 countries. 
        It placed its components into the system storage area and could covertly download and install 
        third-party software when commanded by threat actors.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/02_Android.Vo1d_map_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/02_Android.Vo1d_map_en.png" alt="Android.Void_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;Countries found to have the highest number of TV boxes infected with the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor&lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Already in November, our virus analysts used &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; as an example 
        &lt;a href="https://news.drweb.com/show/?i=14935&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;to show&lt;/a&gt;
        how threat actors use the DNS protocol to covertly connect malware to C&amp;C servers. 
        &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; is a rather primitive trojan whose only task is to load target websites. 
        It differs from most of the threats similar to it in that it receives the addresses of target sites from the 
        TXT record of a malicious DNS server. For this, it uses the modified code of an open source dnsjava library. 
        At the same time, &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; 
        manifests its malicious nature only when connected to the Internet through certain providers; in other cases it operates as harmless software.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/03_Android.FakeApp.1669_c2_response.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/03_Android.FakeApp.1669_c2_response.png" alt="DNS_Trojan_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;An example of a target domain’s TXT record. It was sent by the DNS server upon request via the Linux ‘dig’ tool while one of the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; modifications was undergoing analysis&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
    &lt;h2 class="alignCenter"&gt;Statistics&lt;/h2&gt;
    &lt;p&gt;
        According to detection statistics collected by Dr.Web Security Space for mobile devices, malicious programs were the threats most 
        commonly detected in 2024.They accounted for 74.67% of all registered detections. Adware programs, with a share of 10.96%, ranked 
        second. Riskware apps, which accounted for 10.55% of all detections, ranked third. The fourth most common threats were unwanted apps, 
        which users encountered in 3.82% of cases.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/04_threat_share_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/04_threat_share_2024_en.png" alt="Android_Danger_Stat_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    
    &lt;h3&gt;Malicious programs&lt;/h3&gt;
    &lt;p&gt;
        Once again the malicious Android apps most commonly encountered were ad-displaying trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family. 
        Over the course of last year, their share of the total number of malware programs detected by the Dr.Web anti-virus increased by 0.34 pp. to 31.95% of all detections.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/05_Android.HiddenAds_dynamics_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/05_Android.HiddenAds_dynamics_2024_en.png" alt="Android.Hidden.Ads_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        In this malware family, the most active member was &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3956&lt;/b&gt;
        (15.10% of the detections for the entire family and 4.84% of all malware detected). This is one of many variants of 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1994&lt;/b&gt; malware that users have been encountering for several years now. This particular version, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3956&lt;/b&gt;, emerged in 2023 along with other modifications. We 
        &lt;a href="https://news.drweb.com/show/review/?i=14846&amp;lng=en#stat" target="_blank" rel="noopener noreferrer"&gt;predicted&lt;/a&gt;
        that it could take a leading position in the family, which is what eventually happened. In 2024, its new variants also became widespread: 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3980&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3989&lt;/b&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3994&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.655.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt;, and some others.
    &lt;/p&gt;
    &lt;p&gt;
        At the same time, our experts also noticed activity on the part of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt; subfamily. 
        Unlike most other &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; malware, members of this group have the ability to autorun and have some other
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;features&lt;/a&gt;. 
        Modifications like &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4.origin&lt;/b&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7.origin&lt;/b&gt;, and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; 
        were the ones most commonly detected on devices protected by Dr.Web anti-virus.
    &lt;/p&gt;
    &lt;p&gt;
        The second most widespread malicious programs were trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; 
        family, which cybercriminals use in various fraudulent schemes. Last year, they accounted for 
        18.28% of all malware detections, which is 16.45 pp. higher than the year before. Typically, 
        such trojans load unwanted websites designed for phishing attacks and online fraud.
    &lt;/p&gt;
    &lt;p&gt;
        &lt;a href="https://vms.drweb.com/search/?q=Android.Spy&amp;lng=en"&gt;&lt;b&gt;Android.Spy&lt;/b&gt;&lt;/a&gt; trojans, which have spyware functionality, ranked third with a share of 11.52%; 
        their share decreased by 16.7 pp., compared to 2023. As in the year before, the most common member of 
        this family was &lt;a href="https://vms.drweb.com/search/?q=Android.Spy.5106&amp;lng=en"&gt;&lt;b&gt;Android.Spy.5106&lt;/b&gt;&lt;/a&gt;. 
        It accounted for 5.95% of all detected malware.
    &lt;/p&gt;
    &lt;p&gt;
        In 2024, we observed a mixed trend in the distribution of malware that is designed to download and install other apps and capable 
        of executing arbitrary code. Compared to the previous year, the share of &lt;a href="https://vms.drweb.com/search/?q=Android.DownLoader&amp;lng=en"&gt;&lt;b&gt;Android.DownLoader&lt;/b&gt;&lt;/a&gt; downloader trojans decreased by 0.49 pp. 
        to 1.69%; the share of &lt;a href="https://vms.drweb.com/search/?q=Android.Mobifun&amp;lng=en"&gt;&lt;b&gt;Android.Mobifun&lt;/b&gt;&lt;/a&gt; trojans decreased by 0.15 pp. to 0.10%; and the share of &lt;a href="https://vms.drweb.com/search/?q=Android.Xiny&amp;lng=en"&gt;&lt;b&gt;Android.Xiny&lt;/b&gt;&lt;/a&gt; trojans decreased by 0.14 pp. to 0.13%. 
        At the same time, &lt;a href="https://vms.drweb.com/search/?q=Android.Triada&amp;lng=en"&gt;&lt;b&gt;Android.Triada&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.RemoteCode&amp;lng=en"&gt;&lt;b&gt;Android.RemoteCode&lt;/b&gt;&lt;/a&gt; trojans were detected more often. The number of detection cases for the former 
        increased by 0.6 pp. to 2.74%, and for the latter by 0.95 pp. to 3.78%.
    &lt;/p&gt;
    &lt;p&gt;
        The share of &lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt; malware protected by software packers decreased from 7.98% to 5.49%, nearly returning to the 2022 figure. 
        The number of attacks involving &lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt; adware trojans also decreased—from 10.06% to 5.38%. At the same time, the number of &lt;a href="https://vms.drweb.com/search/?q=Android.Locker&amp;lng=en"&gt;&lt;b&gt;Android.Locker&lt;/b&gt;&lt;/a&gt; 
        ransomware and &lt;a href="https://vms.drweb.com/search/?q=Android.Proxy&amp;lng=en"&gt;&lt;b&gt;Android.Proxy&lt;/b&gt;&lt;/a&gt; trojan detections increased slightly—from 1.15% to 1.60% and from 0.57% to 0.81%, respectively. 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Proxy&amp;lng=en"&gt;&lt;b&gt;Android.Proxy&lt;/b&gt;&lt;/a&gt; trojans allow threat actors using infected Android devices to redirect their network traffic through them. In addition, the activity of 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Click&amp;lng=en"&gt;&lt;b&gt;Android.Click&lt;/b&gt;&lt;/a&gt; malicious programs increased significantly, from 0.82% to 3.56%. These trojans can open advertising websites and perform clicks on webpages.
    &lt;/p&gt;
    &lt;p&gt;The ten most commonly detected malicious programs in 2024:&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/06_top_malware_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/06_top_malware_2024_en.png" alt="Most_Common_Malware_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that loads a website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Spy.5106&amp;lng=en"&gt;&lt;b&gt;Android.Spy.5106&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a trojan that presents itself as modified versions of unofficial WhatsApp messenger mods. This malicious program can steal the contents of notifications and offer users other apps from unknown sources for installation. And when such a modified messenger is used, it can also display dialog boxes containing remotely configurable content.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3956&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3851&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.655.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3994&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Trojan apps designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click.1751&amp;lng=en"&gt;&lt;b&gt;Android.Click.1751&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
        &lt;dd&gt;This trojan is built into third-party WhatsApp messenger mods and camouflaged as Google library classes. While the host application is being used, &lt;a href="https://vms.drweb.com/search/?q=Android.Click.1751&amp;lng=en"&gt;&lt;b&gt;Android.Click.1751&lt;/b&gt;&lt;/a&gt; connects to one of the C&amp;C servers and receives two URLs from it. One of them is intended for Russian-speaking users, and the other is for everyone else. The trojan then displays a dialog box whose contents it has also received from a remote server. When a user clicks on the confirmation button, malware loads the corresponding link in the browser.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds.Aegis&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds.Aegis&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that conceals its presence on Android devices and displays intrusive ads. It has a number of characteristics that differentiate it from other members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family. For example, this trojan can run automatically after its installation. Moreover, it implements a mechanism that allows its service to remain constantly running. And, in some cases, it can also use hidden Android operating system functions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7815&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A trojan app that displays obnoxious ads. It is a special software module that developers incorporate into applications.&lt;/dd&gt;
    &lt;/dl&gt;

    &lt;h3&gt;Unwanted software&lt;/h3&gt;
    &lt;p&gt;
        The unwanted program most commonly detected in 2024 was &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;. It accounted for more than half (52.10%) of the total number 
        of unwanted software detected on protected devices. It belongs to a class of apps that offer users a chance to make money by completing various tasks but ultimately 
        do not provide any real rewards.
    &lt;/p&gt;
    &lt;p&gt;
        Programs that Dr.Web anti-virus detects as &lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; ranked second, with a share of 19.21% (up 9.75 pp. from the previous year). 
        Such apps are modified through the CloudInject cloud service. When modified, they have dangerous permissions and an obfuscated code added to them, and the purpose 
        of that code cannot be controlled.
    &lt;/p&gt;
    &lt;p&gt;
        &lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt; program activity declined for the second year in a row. With a share of 10.07%, which is down 9.35 pp. 
        from 2023, these programs became the third most widespread unwanted software. They imitate anti-virus software, detect nonexistent threats, and 
        ask users to buy full versions to “fix” the issues that have allegedly been found.
    &lt;/p&gt;
    &lt;p&gt;
        Over the course of last year, users encountered a variety of programs for monitoring and controlling activity. Such software can be used to collect data, 
        both with the consent of device owners and without their knowledge. In the latter case, these actually turn into spying tools. The following monitoring 
        programs were most often detected on devices protected by Dr.Web anti-virus: 
        &lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; (2.40% of cases), &lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; (2.03% of cases), 
        &lt;a href="https://vms.drweb.com/search/?q=Program.wSpy&amp;lng=en"&gt;&lt;b&gt;Program.wSpy&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt; (0.98% of cases), &lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt; (0.90% of cases), 
        &lt;a href="https://vms.drweb.com/search/?q=Program.Reptilicus&amp;lng=en"&gt;&lt;b&gt;Program.Reptilicus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.8.origin&lt;/b&gt; (0.64% of cases), &lt;a href="https://vms.drweb.com/search/?q=Program.wSpy&amp;lng=en"&gt;&lt;b&gt;Program.wSpy&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; (0.39% of cases), and &lt;a href="https://vms.drweb.com/search/?q=Program.MonitorMinor&amp;lng=en"&gt;&lt;b&gt;Program.MonitorMinor&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; (0.38% of cases).
    &lt;/p&gt;
    &lt;p&gt;
        Additionally, &lt;a href="https://vms.drweb.com/search/?q=Program.Opensite&amp;lng=en"&gt;&lt;b&gt;Program.Opensite&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt; Android programs, with a share of 0.60% of all the unwanted software detected, were also spotted. 
        These programs are designed to load target websites and display ads.
    &lt;/p&gt;
    &lt;p&gt;The ten unwanted programs most commonly detected in 2024:&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/07_top_unwanted_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/07_top_unwanted_2024_en.png" alt="Most_Common_Unwanted_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, users can remotely manage these apps. They can block them, display custom dialogs, and track when other software is being installed or removed from a device, etc.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for a program that allows users to be monitored via their Android devices. Malicious actors can utilize it to track a target device’s location, use the camera to record video and take photos, eavesdrop via the microphone, record audio, etc.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for various modifications of an application that is designed to record videos and take photos in the background, using built-in Android device cameras. It can operate covertly by allowing notifications about ongoing recordings to be disabled. It also allows an app’s icon and name to be replaced with fake ones. This functionality makes this software potentially dangerous.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.wSpy&amp;lng=en"&gt;&lt;b&gt;Program.wSpy&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;This is a commercial spyware app designed to covertly monitor Android device user activity. It allows intruders to read SMS and chats in popular messaging software, listen to the surroundings, track device location and browser history, gain access to the phonebook and contacts, photos and videos, and take screenshots and pictures through a device’s built-in camera. In addition, it has keylogger functionality.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.Reptilicus&amp;lng=en"&gt;&lt;b&gt;Program.Reptilicus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.8.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;An application that allows Android device users to be monitored. It can track device location, collect information from SMS and social media messages, intercept phone calls and record the surroundings, take screenshots, act as a keylogger, copy files from a target device and perform other actions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.Opensite&amp;lng=en"&gt;&lt;b&gt;Program.Opensite&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for single-type Android programs whose function is to load target websites and display ads. Such apps often masquerade as other software. For instance, there exist modifications that are distributed under the guise of YouTube player. They load a genuine YouTube website and display advertisement banners, using the advertising SDKs connected to them.&lt;/dd&gt;
    &lt;/dl&gt;

    &lt;h3&gt;Riskware&lt;/h3&gt;
    &lt;p&gt;
        In 2024, &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt; utilities, which allow Android programs to launch without being installed, retained their leading 
        positions in terms of riskware software detection numbers. In total, they accounted for more than a third of all apps of this type identified 
        on protected devices. Modifications like &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.17.origin&lt;/b&gt; (16.17%), &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14.origin&lt;/b&gt; (9.80%), 
        &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7.origin&lt;/b&gt; (3.25%), and &lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.6.origin&lt;/b&gt; (2.99%) were most often detected.
    &lt;/p&gt;
    &lt;p&gt;
        Other common riskware apps were programs modified using the NP Manager utility. This tool embeds a special module into the target software, which allows the digital 
        signature verification process to be bypassed once the apps have been modified. Dr.Web anti-virus detects such programs as different variants of the &lt;b&gt;Tool.NPMod&lt;/b&gt; family. 
        Of these, &lt;b&gt;Tool.NPMod.1&lt;/b&gt; variants were most commonly detected. Over the course of 2024, they significantly strengthened their position, accounting for 16.49% of all riskware 
        detections, up 11.68 pp. from 2023. At the same time, the share of programs modified using the NP Manager tool and detected with another virus record, 
        &lt;b&gt;Tool.NPMod.2&lt;/b&gt;, was 7.92%. As a result, members of this family were responsible for almost a quarter of potentially dangerous software detections.
    &lt;/p&gt;
    &lt;p&gt;
        Programs protected by the &lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; packer were also among the leaders. They were detected in 13.17% of cases, up 12.38 pp. 
        from the year before. Moreover, the number of &lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt; detections increased from 3.10% to 3.93%. This is a framework that 
        makes it possible to modify Android apps and run Lua scripts that can potentially be malicious.
    &lt;/p&gt;
    &lt;p&gt;
        At the same time, one 2023 leader, the &lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt; family of utilities, was, on the contrary, less active—down from 14.02% to 8.16%. 
        These tools allow Android programs to be modified and scripts downloaded from the Internet to be added to them. Also less frequently encountered were 
        programs protected by the obfuscating utility &lt;a href="https://vms.drweb.com/search/?q=Tool.Obfuscapk&amp;lng=en"&gt;&lt;b&gt;Tool.Obfuscapk&lt;/b&gt;&lt;/a&gt; (down from 3.22% to 1.05%) and by the packer &lt;a href="https://vms.drweb.com/search/?q=Tool.ApkProtector&amp;lng=en"&gt;&lt;b&gt;Tool.ApkProtector&lt;/b&gt;&lt;/a&gt; 
        (down from 10.14% to 3.39%).
    &lt;/p&gt;
    &lt;p&gt;The ten most widespread riskware apps detected on protected Android devices in 2024:&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/08_top_riskware_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/08_top_riskware_2024_en.png" alt="Most_Common_Riskware_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;b&gt;Tool.NPMod.2&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. A special module is embedded in such apps, and it allows them to bypass digital signature verification once they have been modified.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.17.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.6.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Riskware platforms that allow applications to launch APK files without installing them. They create a virtual runtime environment in the context of the apps in which they are integrated. The APK files, launched with the help of these platforms, can operate as if they are part of such programs and can also obtain the same permissions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A packer tool designed to protect Android applications from unauthorized modification and reverse engineering. This tool is not malicious in itself, but it can be used to protect both harmless and malicious software.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads from the Internet specially prepared scripts, which can be crafted and added to the common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some potentially dangerous versions of a specialized framework for developing Android software in the Lua scripting language. The main logic of Lua-based apps resides in the corresponding scripts that are encrypted and decrypted by the interpreter upon execution. By default, this framework often requests access to a large number of system permissions in order to operate. As a result, the Lua scripts that it executes can potentially perform various malicious actions in accordance with the acquired permissions.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for Android programs whose code is encoded and obfuscated by the NP Manager tool.&lt;/dd&gt;
    &lt;/dl&gt;

    &lt;h3&gt;Adware&lt;/h3&gt;
    &lt;p&gt;
        The most common adware in 2024 was the new &lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt; family, which accounted for 47.45% of detections. 
        The previous year’s leaders, members of the &lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt; family, dropped to second place with a share of 14.76% 
        (a 21.06 pp. decrease in the number of detections). Third place, with a share of 8.68%, was occupied by another new adware family, &lt;b&gt;Adware.Basement&lt;/b&gt;.
    &lt;/p&gt;
    &lt;p&gt;
        Also commonly encountered were families like &lt;a href="https://vms.drweb.com/search/?q=Adware.Airpush&amp;lng=en"&gt;&lt;b&gt;Adware.Airpush&lt;/b&gt;&lt;/a&gt; (their share decreased from 8.59% to 4.35%), &lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt; (down from 4.41% to 3.29%), 
        &lt;a href="https://vms.drweb.com/search/?q=Adware.Leadbolt&amp;lng=en"&gt;&lt;b&gt;Adware.Leadbolt&lt;/b&gt;&lt;/a&gt; (down from 4.37% to 2.26%), and &lt;a href="https://vms.drweb.com/search/?q=Adware.ShareInstall&amp;lng=en"&gt;&lt;b&gt;Adware.ShareInstall&lt;/b&gt;&lt;/a&gt; (down from 5.04% to 1.71%). Unwanted ad-displaying &lt;a href="https://vms.drweb.com/search/?q=Adware.MagicPush&amp;lng=en"&gt;&lt;b&gt;Adware.MagicPush&lt;/b&gt;&lt;/a&gt; 
        programs, which ranked second in 2023, significantly curtailed their activity and did not even make it into the top 10; they moved straight to eleventh place with a share 
        of 1.19% (a 8.39 pp. decrease).
    &lt;/p&gt;
    &lt;p&gt;The ten most widespread adware apps detected on protected Android devices in 2024:&lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/09_top_adware_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/09_top_adware_2024_en.png" alt="Most_Common_Adware_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;dl class="dlList"&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some modified versions (mods) of the WhatsApp messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
        &lt;dt&gt;&lt;b&gt;Adware.Basement.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;These are apps that display unwanted ads which often lead to malicious and fraudulent websites. They share a common code base with the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; unwanted applications.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;An adware module that malicious actors embed into cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display obnoxious ads.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21846&lt;/b&gt;&lt;/dt&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.39.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Airpush&amp;lng=en"&gt;&lt;b&gt;Adware.Airpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;Adware modules that can be built into Android apps and display various ads. Depending on the modules’ version and modification, these can be notifications containing ads, pop-up windows or banners. Malicious actors often use these modules to distribute malware by offering their potential victims diverse software for installation. Moreover, such modules collect personal information and send it to a remote server.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ShareInstall&amp;lng=en"&gt;&lt;b&gt;Adware.ShareInstall&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;An adware module that can be built into Android applications. It displays notifications containing ads on the Android OS lock screen.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Youmi&amp;lng=en"&gt;&lt;b&gt;Adware.Youmi&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for an unwanted adware module that adds advertizing shortcuts onto the Android OS home screen.&lt;/dd&gt;
        &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Inmobi&amp;lng=en"&gt;&lt;b&gt;Adware.Inmobi&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
        &lt;dd&gt;The detection name for some versions of the Inmobi adware SDK. These are capable of making phone calls and adding event entries into an Android device’s calendar.&lt;/dd&gt;
    &lt;/dl&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="gplay"&gt;
    &lt;h2 class="alignCenter"&gt;Threats on Google Play&lt;/h2&gt;
    &lt;p&gt;
        In 2024, Doctor Web’s virus analysts discovered over 200 threats with more than 26.7 million combined downloads. 
        In addition to &lt;a href="https://vms.drweb.com/search/?q=Android.Click.414.origin&amp;lng=en"&gt;&lt;b&gt;Android.Click.414.origin&lt;/b&gt;&lt;/a&gt;, these included many other threats, such as ad-displaying &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; 
        trojans. They were distributed under the guise of all kinds of software: image-editing programs, QR code scanners, image collection apps, 
        and even an “anti-theft” alarm for protecting smartphones from falling into the wrong hands. Such trojans conceal their icons after 
        installation and proceed to display aggressive ads that overlap the interface of the operating system and other programs and prevent the 
        device from being used normally.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/10_Android.HiddenAds.4013_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/10_Android.HiddenAds.4013_2024.png" alt="Android.HiddenAds_2024" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
              &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/11_Android.HiddenAds.4034_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/11_Android.HiddenAds.4034_2024.png" alt="Android.HiddenAds_2024" style="max-width: 350px;"&gt;
              &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/12_Android.HiddenAds.4025_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/12_Android.HiddenAds.4025_2024.png" alt="Android.HiddenAds_2024" style="max-width: 350px;"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/13_Android.HiddenAds.656.origin_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/13_Android.HiddenAds.656.origin_2024.png" alt="Android.HiddenAds_2024" style="max-width: 350px;"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of adware trojans discovered on Google Play in 2024. &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4013&lt;/b&gt; was hiding in the photo editor “Cool Fix Photo Enhancer”, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4034&lt;/b&gt; was in the  “Cool Darkness Wallpaper” image-collection app, &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.4025&lt;/b&gt; was in the QR scanning program “QR Code Assistant”, and 
        &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.656.origin&lt;/b&gt; was in the “anti-theft” alarm program “Warning Sound GBD”
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Our experts also discovered various trojans that threat actors were protecting with a complicated software packer.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/14_Android.Packed.57156_2024.0.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/14_Android.Packed.57156_2024.1.png" alt="Android.Packed_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/15_Android.Packed.57159_2024.0.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/15_Android.Packed.57159_2024.1.png" alt="Android.Packed_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        The “Lie Detector Fun Prank” program was the &lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57156&lt;/b&gt; 
        trojan, and the “Speaker Dust and Water Cleaner” app was the &lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57159&lt;/b&gt; trojan; both were protected with a software packer
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Other malware we found were members of the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; family, which are used in various fraudulent schemes. The main task of most of 
        these trojans is to open a target URL, while some of them, under certain conditions, can also operate as the software they are disguised as. Many of 
        them were distributed as different apps, including financial programs, like teaching aids and reference books, profit calculators, apps for accessing 
        trading, and instruments for home bookkeeping. Others were disguised as notepads and diaries, software for participating in quiz games, surveys, etc. 
        They also loaded fraudulent investment sites.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/16_Android.FakeApp.1674_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/16_Android.FakeApp.1674_2024.1.png" alt="Android.FakeApp_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/17_Android.FakeApp.1708_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/17_Android.FakeApp.1708_2024.1.png" alt="Android.FakeApp_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; 
        trojans that opened links to fraudulent websites: &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1681&lt;/b&gt; (disguised as the “SenseStrategy” app), &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1708&lt;/b&gt; 
        (disguised as the “QuntFinanzas” app)
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Some &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs were distributed as a variety of games. Many of them could actually provide the declared functionality, 
        but their main task was to load online casino and bookmaker sites.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/18_Android.FakeApp.1622_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/18_Android.FakeApp.1622_2024.1.png" alt="Android.FakeApp_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/19_Android.FakeApp.1630_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/19_Android.FakeApp.1630_2024.1.png" alt="Android.FakeApp_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans that were disguised as games and loaded bookmaker and online casino websites: 
        &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1622&lt;/b&gt; (“3D Card Merge Game”) and &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1630&lt;/b&gt; (“Crazy Lucky Candy”)
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Some trojans from this family were once again camouflaged as job-search programs. Such scam apps load fake vacancy listings and offer 
        users the opportunity to create a resume by providing personal information. In other cases, the trojans can ask potential victims to 
        contact “the employer” via a messenger. In reality, they will actually be writing to the scammers, who will try to lure them into one 
        or another fraudulent scheme.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/20_Android.FakeApp.1627_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/20_Android.FakeApp.1627_2024.1.png" alt="Android.FakeApp_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/21_Android.FakeApp.1703_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/21_Android.FakeApp.1703_2024.1.png" alt="Android.FakeApp_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans that scammers passed off as job-search apps: &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1627&lt;/b&gt; (the “Aimer” app) and  
        &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1703&lt;/b&gt; (the “FreeEarn” app)
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        In addition, more trojans that subscribe users to paid services were uncovered on Google Play. 
        One of them was &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.22&lt;/b&gt;, which was being distributed as the “InstaPhoto Editor” photo-editing program.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/22_Android.Subscription.22_2024.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/22_Android.Subscription.22_2024.png" alt="Android.Subscriptin_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        The &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.22&lt;/b&gt; trojan is designed to subscribe users to paid services
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        Other such trojans were members of the related &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Harly&amp;lng=en"&gt;&lt;b&gt;Android.Harly&lt;/b&gt;&lt;/a&gt; families, which have a modular architecture. 
        The former can download additional components from the Internet, while the latter are distinguished by the fact that they typically store the modules 
        they need in encrypted form in their file resources.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/23_Android.Joker.2280_2024.png" class="preview"&gt;
                 &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/23_Android.Joker.2280_2024.1.png" alt="Android.Joker_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/24_Android.Harly.82_2024.png" class="preview"&gt;
                 &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/24_Android.Harly.82_2024.1.png" alt="Android.Harly_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;

    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of apps that subscribed victims to paid services. The &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.2280&lt;/b&gt; 
        was hiding in the horoscope program “My Horoscope”, and the &lt;a href="https://vms.drweb.com/search/?q=Android.Harly&amp;lng=en"&gt;&lt;b&gt;Android.Harly&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.87&lt;/b&gt; was hiding in the game “BlockBuster”
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        In addition to malware, Doctor Web’s specialists discovered new unwanted software on Google Play, which included different 
        modifications of &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14&lt;/b&gt;. 
        These belong to a family of programs that offer users virtual rewards for completing various tasks (often this involves watching ads). 
        The rewards can allegedly be converted into real money or prizes, but to withdraw their “earned” reward, users must collect a certain sum. 
        However, even if they succeed in doing so, they will not get any real payments.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/25_Program.FakeMoney.11_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/25_Program.FakeMoney.11_2024.1.png" alt="Program.FakeMoney_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/26_Program.FakeMoney.14_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/26_Program.FakeMoney.14_2024.1.png" alt="Program.FakeMoney_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        One of the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; 
        variants was distributed as the game “Copper Boom”, and &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14&lt;/b&gt; was disguised as the game “Merge Party”
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        In addition, throughout the year, our malware analysts discovered new adware programs. Among them were apps and games with the 
        built-in adware module &lt;a href="https://vms.drweb.com/search/?q=Adware.StrawAd&amp;lng=en"&gt;&lt;b&gt;Adware.StrawAd&lt;/b&gt;&lt;/a&gt;, which is capable of displaying ads from various advertising service providers.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/27_Adware.StrawAd.1_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/27_Adware.StrawAd.1_2024.1.png" alt="Adware.StrawAd_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/28_Adware.StrawAd.3_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/28_Adware.StrawAd.3_2024.1.png" alt="Adware.StrawAd_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/29_Adware.StrawAd.6_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/29_Adware.StrawAd.6_2024.1.png" alt="Adware.StrawAd_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/30_Adware.StrawAd.9_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/30_Adware.StrawAd.9_2024.1.png" alt="Adware.StrawAd_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of games containing the adware module &lt;a href="https://vms.drweb.com/search/?q=Adware.StrawAd&amp;lng=en"&gt;&lt;b&gt;Adware.StrawAd&lt;/b&gt;&lt;/a&gt;: 
        “Crazy Sandwich Runner” (&lt;a href="https://vms.drweb.com/search/?q=Adware.StrawAd&amp;lng=en"&gt;&lt;b&gt;Adware.StrawAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;), 
        “Poppy Punch Playtime” (&lt;a href="https://vms.drweb.com/search/?q=Adware.StrawAd&amp;lng=en"&gt;&lt;b&gt;Adware.StrawAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3&lt;/b&gt;), 
        “Finger Heart Matching”  (&lt;a href="https://vms.drweb.com/search/?q=Adware.StrawAd&amp;lng=en"&gt;&lt;b&gt;Adware.StrawAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.6&lt;/b&gt;), 
        and “Toimon Battle Playground” (&lt;a href="https://vms.drweb.com/search/?q=Adware.StrawAd&amp;lng=en"&gt;&lt;b&gt;Adware.StrawAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.9&lt;/b&gt;)
    &lt;/em&gt;&lt;/p&gt;

    &lt;p&gt;
        &lt;b&gt;Adware.Basement&lt;/b&gt; adware programs were also distributed via Google Play. 
        Ads from these often lead to malicious and fraudulent websites. It is noteworthy that this family shares a code base with the unwanted &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; apps.
    &lt;/p&gt;

    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/31_Adware.Basement.1_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/31_Adware.Basement.1_2024.1.png" alt="Adware.Basement_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/32_Adware.Basement.1_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/32_Adware.Basement.1_2024.1.png" alt="Adware.Basement_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
        &lt;div class="margRM"&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/33_Adware.Basement.1_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/33_Adware.Basement.1_2024.1.png" alt="Adware.Basement_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
            &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/34_Adware.Basement.2_2024.png" class="preview"&gt;
                  &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/34_Adware.Basement.2_2024.1.png" alt="Adware.Basement_2024"&gt;
            &lt;/a&gt;
        &lt;/div&gt;
    &lt;/div&gt;
    &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;
        Examples of &lt;b&gt;Adware.Basement&lt;/b&gt; 
        unwanted adware programs: “Lie Detector: Lie Prank Test”, “TapAlarm:Don't touch my phone”, and “Magic Voice Changer” are examples for &lt;b&gt;Adware.Basement.1&lt;/b&gt;; 
        and “Auto Clicker:Tap Auto” for &lt;b&gt;Adware.Basement.2&lt;/b&gt;
    &lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="troj"&gt;
    &lt;h2 class="alignCenter"&gt;Banking trojans&lt;/h2&gt;
    &lt;p&gt;
        According to detection statistics provided by Dr.Web Security Space for mobile devices, in 2024, banking trojans represented 6.29% of the total number 
        of registered malicious apps, which is up 2.71 pp. from the previous year. Starting in January, their activity steadily declined, but from mid-spring 
        onwards, the number of attacks started to increase again. Their activity remained virtually unchanged during the third quarter, after which they continued 
        to be more active, reaching an annual maximum in November.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/35.1_banker_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/35.1_banker_2024_en.png" alt="Banker_Stat_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        In 2024, well-known banking trojan families became widespread again. 
        Among them were the malicious programs &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot.Coper&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;Coper&lt;/a&gt;, 
        Hydra (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1048.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.563.origin&lt;/b&gt;), 
        Ermac (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1015.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.15017&lt;/b&gt;), 
        Alien (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.745.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1078.origin&lt;/b&gt;), 
        Anubis (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.670.origin&lt;/b&gt;). 
        In addition, attacks using the following were observed: Cerberus (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11404&lt;/b&gt;), 
        GodFather (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.GodFather.3&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.GodFather.14.origin&lt;/b&gt;), and Zanubis (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.Zanubis.7.origin&lt;/b&gt;).
    &lt;/p&gt;
    &lt;p&gt;
        Over the course of 2024, malicious actors actively distributed &lt;b&gt;Android.SpyMax&lt;/b&gt; spyware trojans, which have rich malicious functionality. 
        They are also widely used as banking trojans. This family originally included the multifunctional RAT trojan SpyNote (RAT — Remote Administration 
        Trojan or Remote Access Trojan). However, after its source code was leaked, many new modifications based on this code started to emerge, including 
        CraxsRAT and G700 RAT. Dr.Web Security Space detection statistics show that members of this family became more active in the second half of 2023; 
        since then, almost every month they have been detected in increasing numbers, and this trend continues.
    &lt;/p&gt;
    &lt;p&gt;
        &lt;b&gt;Android.SpyMax&lt;/b&gt; trojans target users all over the world. Last year, they were also found to be involved in numerous attacks on Russian users, 
        as 46.23% of the detections of this family were registered on devices belonging to this particular audience. These trojans were also most actively 
        distributed among Brazilian (35.46% of detections) and Turkish (5.80% of detections) Android device owners.
    &lt;/p&gt;
    &lt;p&gt;
        It is noteworthy that these malicious programs are mainly distributed in Russia not via spam or classic phishing, but during one stage of telephone fraud. 
        At the beginning of their call, threat actors traditionally try to convince their victims that they are employees of a bank or a law enforcement agency. 
        They inform them about a problem that has allegedly occurred, e.g., an attempt to steal money from the victim’s bank account or an unplanned loan; or, on 
        the contrary, they report “good news” about free money that is supposedly due their victims from the government. When the scammers realize that a user has 
        believed them, they encourage their victim to install an “anti-virus update”, a “banking program”, or some other similar app—for example, to “ensure a secure 
        transaction”. Such a program will, in fact, contain an &lt;b&gt;Android.SpyMax&lt;/b&gt; trojan.
    &lt;/p&gt;

    &lt;div class="column_grid_review column_grid_review--o"&gt;
        &lt;a href="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/36_Android.SpyMax_share_2024_en.png" class="preview"&gt;
          &lt;img src="https://st.drweb.com/static/new-www/news/2025/january/review_mobile/36_Android.SpyMax_share_2024_en.png" alt="Android.SpyMax_2024"&gt;
        &lt;/a&gt;
    &lt;/div&gt;

    &lt;p&gt;
        In 2024, Russian users also encountered the Falcon banking trojan family (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.988.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5703&lt;/b&gt;) 
        and the Mamont family (&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.637.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.712.origin&lt;/b&gt;). In addition, attacks involving the banking trojans 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.791.origin&lt;/b&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.829.origin&lt;/b&gt; were observed. These targeted Android device owners from Russia and Uzbekistan. 
        Other attacks were perpetrated by &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.802.origin&lt;/b&gt; and affected Russian, Azerbaijani, and Uzbekistani users. 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.757.origin&lt;/b&gt; targeted users from Russia, Uzbekistan, Tajikistan, and Kazakhstan.
    &lt;/p&gt;
    &lt;p&gt;
        Our experts once again detected attacks coming from the MoqHao trojans (&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.367.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.430.origin&lt;/b&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.470.origin&lt;/b&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.593.origin&lt;/b&gt;) 
        that were aimed at users from many countries, including Southeast Asian and Asia-Pacific countries. 
        The same audience was also targeted by other trojans. For example, South Korean Android device owners encountered families like Fakecalls 
        (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.919.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14423&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5297&lt;/b&gt;), 
        IOBot (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.IOBot.1.origin&lt;/b&gt;), and Wroba (&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.360.origin&lt;/b&gt;). Other Wroba modifications 
        (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.907.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1128.origin&lt;/b&gt;) 
        attacked users from Japan.
    &lt;/p&gt;
    &lt;p&gt;
        Banking trojans that threatened Chinese users included, for instance, the &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.480.origin&lt;/b&gt; trojan, 
        and Vietnamese users were attacked by &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1111.origin&lt;/b&gt;. 
        At the same time, cybercriminals used trojans like TgToxic (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.TgToxic.1&lt;/b&gt;) to attack bank customers from Indonesia, 
        Thailand, and Taiwan, and the GoldDigger trojan
        (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.GoldDigger.3&lt;/b&gt;) was used to target users from Thailand and Vietnam.
    &lt;/p&gt;
    &lt;p&gt;
        Attacks on Iranian users were again recorded. These users encountered such banking trojans as &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.709.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5292&lt;/b&gt;, 
        &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.777.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1106.origin&lt;/b&gt;, and some others. 
        And banking trojans that attacked Turkish bank customers included representatives of the Tambir family 
        (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1104.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1099.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1117.origin&lt;/b&gt;), along with some others.
    &lt;/p&gt;
    &lt;p&gt;
        Banking trojans like &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.797.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.817.origin&lt;/b&gt; 
        and &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5435&lt;/b&gt; targeted Indian users.
        These trojans were camouflaged as software that was allegedly related to the credit institutions Airtel Payments Bank, PM KISAN, and IndusInd Bank. 
        In addition, Rewardsteal banking trojans (&lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.719.origin&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5147&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Banker&amp;lng=en"&gt;&lt;b&gt;Android.Banker&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.5443&lt;/b&gt;) 
        remained active. These primarily targeted Indian customers of banks like Axis bank, HDFC Bank, SBI, ICICI Bank, RBL bank, and Citi bank.
    &lt;/p&gt;
    &lt;p&gt;
        In Latin American counties, PixPirate (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1026.origin&lt;/b&gt;) trojan activity was observed; these trojans target Brazilian bank customers.
    &lt;/p&gt;
    &lt;p&gt;
        Among the trojans targeting European users were Anatsa (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.Anatsa.1.origin&lt;/b&gt;) and Copybara (&lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.15140&lt;/b&gt; and 
        &lt;a href="https://vms.drweb.com/search/?q=Android.BankBot&amp;lng=en"&gt;&lt;b&gt;Android.BankBot&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1100.origin&lt;/b&gt;). The latter mainly targets users from Italy, the United Kingdom, and Spain.
    &lt;/p&gt;
    &lt;p&gt;
        During 2024, Doctor Web’s virus analysts observed an increase in the popularity of certain methods of protecting Android malware (primarily banking trojans) 
        from analysis and detection. In particular, attackers performed various manipulations with the ZIP format on which Android APK files are based. As a result, 
        many instruments of static analysis that use standard algorithms to work with ZIP archives are unable to correctly process such “damaged” files. At the same 
        time, the Android OS accepts such modified trojans as normal programs, allowing them to be installed and run.
    &lt;/p&gt;
    &lt;p&gt;
        One common technique is to manipulate the fields &lt;span class="string"&gt;compression method&lt;/span&gt; and &lt;span class="string"&gt;compressed size&lt;/span&gt; 
        in the local file header inside the APK. Threat actors intentionally specify the wrong values for the fields &lt;span class="string"&gt;compressed size&lt;/span&gt; 
        and &lt;span class="string"&gt;uncompressed size&lt;/span&gt; or write an incorrect or nonexistent compression method in the 
        &lt;span class="string"&gt;compression method&lt;/span&gt; field. Another option is to specify a method that does 
        not involve compression for the archive. The header fields &lt;span class="string"&gt;compressed size&lt;/span&gt; 
        and &lt;span class="string"&gt;uncompressed size&lt;/span&gt; will not match, although they should.
    &lt;/p&gt;
    &lt;p&gt;
        Another popular technique is to use incorrect information about the disk in the ECDR (End of Central Directory Record) and in the CD (Central Directory 
        that contains data about files and archive parameters). Both these parameters should match for a single archive. However, cybercriminals can specify 
        different values for these as if it were not a single archive, but a multi-archive.
    &lt;/p&gt;
    &lt;p&gt;
        Also widespread was a technique whereby a flag was set in the local file headers of some files in the archive, indicating that these files are encrypted. 
        In reality they are not encrypted but due to this, such an archive will be parsed incorrectly.
    &lt;/p&gt;
    &lt;p&gt;
        Along with manipulating the structure of APK files, malware creators also used other practices, such as modifying the 
        &lt;span class="string"&gt;AndroidManifest.xml&lt;/span&gt; configuration file of Android apps. In particular, they added garbage bytes &lt;span class="string"&gt;b'\x00'&lt;/span&gt; 
        to this file’s attribute structure, causing it to be read incorrectly.
    &lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="future"&gt;
    &lt;h2 class="alignCenter"&gt;Prospects and trends&lt;/h2&gt;
    &lt;p&gt;
        The past year has shown that cybercriminals are still actively enriching themselves at the expense of Android device owners. 
        Their main tools remain ad-displaying and banking trojans, malicious programs with spyware capabilities, and fraudulent software. 
        In this regard, we should expect the emergence of new threats of this type in 2025.
    &lt;/p&gt;
    &lt;p&gt;
        Despite the steps taken to improve the security of Google Play, this app catalog still remains an Android threat distribution source. 
        Therefore, new malicious and unwanted apps emerging in it should not be ruled out.
    &lt;/p&gt;
    &lt;p&gt;
        Another case of Android TV box sets being infected was detected last year, indicating that malware creators use different attack vectors. 
        It is quite possible that threat actors will not only turn their attention to such devices again, but will also continue to look for other 
        potential targets among the variety of Android gadgets.
    &lt;/p&gt;
    &lt;p&gt;
        It is possible that malware developers will continue to actively introduce new techniques that allow their malicious programs to bypass analysis and detection.
    &lt;/p&gt;
    &lt;p&gt;
        Doctor Web’s specialists continue to both monitor the evolution of mobile cyber threats and ensure that our users are protected. To improve your mobile device security, 
        install Dr.Web Security Space, which helps in the fight against malicious, unwanted, and other dangerous programs; fraudsters; and other threats.
    &lt;/p&gt;
&lt;/section&gt;

&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/2024 review of virus activity on mobile devices/README.adoc" target="_blank" rel="noopener noreferrer"&gt;Indicators of compromise&lt;/a&gt;

&lt;style&gt;
    .custom-color-link a {
        color: #73b320;
    }
&lt;/style&gt;

</description></item><item><guid>https://news.drweb.com/show/?i=14950&amp;lng=en</guid><title>Doctor Web’s Q4 2024 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=14950&amp;lng=en&amp;c=10</link><pubDate>Thu, 26 Dec 2024 10:00:00 GMT</pubDate><description>


&lt;p&gt;&lt;b&gt;December 26, 2024&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
  &lt;p&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojans were the malware programs most frequently detected in the fourth quarter of 2024 (Q4). The second most common threats were &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans, which are used in fraudulent schemes. Trojans from the &lt;b&gt;Android.Siggen&lt;/b&gt; family, capable of executing various malicious tasks, ranked third.&lt;/newslead&gt;&lt;/p&gt;
  &lt;p&gt;Over the course of Q4, Doctor Web’s malware analysts discovered many threats on Google Play. Among them were numerous &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans and malware from the &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; families, which subscribe users to paid services. More &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans were also detected. In addition, threat actors distributed malicious apps protected with a sophisticated software packer.&lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
  &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
    &lt;h4 class="white alignCenter"&gt;PRINCIPAL TRENDS OF Q4 2024&lt;/h4&gt;
    &lt;ul&gt;
      &lt;li&gt;High activity on the part of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans and &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fraudulent apps&lt;/li&gt;
      &lt;li&gt;The distribution of many malicious programs through the Google Play catalog&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/div&gt;

  &lt;h2 class="alignCenter"&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h2&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/01_malware_q4_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/01_malware_q4_2024_en.1.png" alt="According to statistics collected by Dr.Web Security Space for mobile devices"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A trojan app that loads a website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.655.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.657.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;Trojan apps designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57083&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for malicious applications protected with an ApkProtector software packer. Among them are banking trojans, spyware, and other malicious software.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click.1751&amp;lng=en"&gt;&lt;b&gt;Android.Click.1751&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
      &lt;dd&gt;This trojan is built into third-party WhatsApp messenger mods and camouflaged as Google library classes. While the host application is being used, &lt;a href="https://vms.drweb.com/search/?q=Android.Click.1751&amp;lng=en"&gt;&lt;b&gt;Android.Click.1751&lt;/b&gt;&lt;/a&gt; connects to one of the C&amp;C servers and receives two URLs from it. One of them is intended for Russian-speaking users, and the other is for everyone else. The trojan then displays a dialog box whose contents it has also received from a remote server. When a user clicks on the confirmation button, malware loads the corresponding link in the browser.&lt;/dd&gt;    
  &lt;/dl&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/02_unwanted_q4_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/02_unwanted_q4_2024_en.1.png" alt="According to statistics collected by Dr.Web Security Space for mobile devices"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, users can remotely manage these apps. They can block them, display custom dialogs, and track when other software is being installed or removed from a device, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for a program that allows users to be monitored via their Android devices. Malicious actors can utilize it to track a target device’s location, use the camera to record video and take photos, eavesdrop via the microphone, record audio, etc.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for various modifications of an application that is designed to record videos and take photos in the background, using built-in Android device cameras. It can operate covertly by allowing notifications about ongoing recordings to be disabled. It also allows an app’s icon and name to be replaced with fake ones. This functionality makes this software potentially dangerous.&lt;/dd&gt;
  &lt;/dl&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/03_riskware_q4_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/03_riskware_q4_2024_en.1.png" alt="According to statistics collected by Dr.Web Security Space for mobile devices"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. A special module is embedded in such apps, and it allows them to bypass digital signature verification once they have been modified.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.14.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A riskware platform that allows applications to launch APK files without installing them. It creates a virtual runtime environment in the context of the apps in which they are integrated. The APK files launched with the help of this platform can operate as if they are part of such programs and can also obtain the same permissions.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads specially prepared scripts from the Internet, which can be crafted and added to the common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A packer tool designed to protect Android applications from unauthorized modifications and reverse engineering. This tool is not malicious in itself, but it can be used to protect both harmless and malicious software.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Androlua&amp;lng=en"&gt;&lt;b&gt;Tool.Androlua&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for some potentially dangerous versions of a specialized framework for developing Android software based on the Lua scripting language. The main logic of Lua-based apps resides in the corresponding scripts that are encrypted and decrypted by the interpreter upon execution. By default, this framework often requests access to a large number of system permissions in order to operate. As a result, the Lua scripts that it executes can potentially perform various malicious actions in accordance with the acquired permissions. &lt;/dd&gt;
  &lt;/dl&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/04_adware_q4_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/04_adware_q4_2024_en.1.png" alt="According to statistics collected by Dr.Web Security Space for mobile devices"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.ModAd&amp;lng=en"&gt;&lt;b&gt;Adware.ModAd&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for some modified versions (mods) of the WhatsApp messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Basement.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;These are apps that display unwanted ads which often lead to malicious and fraudulent websites. They share a common code base with the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney.11&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney.11&lt;/b&gt;&lt;/a&gt; unwanted applications.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;An adware module that malicious actors embed into the cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display obnoxious ads.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3.origin&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21846&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;
  &lt;/dl&gt;
&lt;/section&gt;


&lt;section class="margTM margBM" id="formobile"&gt;
  &lt;h2 class="alignCenter"&gt;Threats on Google Play&lt;/h2&gt;
  &lt;p&gt;In Q4 2024, Doctor Web’s malware analysts discovered over 60 malicious apps on Google Play, most of which were trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; family. Some of them were distributed as financial programs, teaching aids, reference books, and other software, including diaries, notepads, and so on. Their primary task was to load fraudulent websites.&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/05_Android.FakeApp.1708_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/05_Android.FakeApp.1708_q4_2024.1.png" alt="Android.FakeApp"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/06_Android.FakeApp.1729_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/06_Android.FakeApp.1729_q4_2024.1.png" alt="Android.FakeApp"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;The “QuntFinanzas” and “Trading News” apps, which, among other numerous Android.FakeApp trojans, loaded fraudulent sites&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Malicious actors disguised other &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans as games. These could load online casino and bookmaker websites.&lt;/p&gt;
  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/07_Android.FakeApp.1719_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/07_Android.FakeApp.1719_q4_2024.1.png" alt="Android.FakeApp"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/08_Android.FakeApp.1733_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/08_Android.FakeApp.1733_q4_2024.1.png" alt="Android.FakeApp"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;“Bowl Water” and “Playful Petal Pursuit” are examples of games with trojan functionality&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Our experts also &lt;a href="https://news.drweb.com/show/?i=14935&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;uncovered&lt;/a&gt; new variants of the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; trojan that was hiding behind the mask of various programs and could also load online casino websites. &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp.1669&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp.1669&lt;/b&gt;&lt;/a&gt; is interesting in that it gets the target website URL from the malicious DNS server’s TXT file. At the same time, it only manifests itself when connected to the Internet through certain providers.&lt;/p&gt;
  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/09_Android.FakeApp.1669_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/09_Android.FakeApp.1669_q4_2024.1.png" alt="Android.FakeApp"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/10_Android.FakeApp.1669_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/10_Android.FakeApp.1669_q4_2024.1.png" alt="Android.FakeApp"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;Examples of new Android.FakeApp.1669 trojan modifications. The “WordCount” app was disguised as a text tool, and the “Split it: Checks and Tips” app was supposed to help café- and restaurant-goers pay their bills and calculate tips.&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Several new members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojan family were among the threats detected on Google Play. They conceal their presence on infected devices.&lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/11_Android.HiddenAds.4013_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/11_Android.HiddenAds.4013_q4_2024.1.png" alt="Android.HiddenAds"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;This “Cool Fix Photo Enhancer” photo-editing software was hiding the Android.HiddenAds.4013 ad-displaying trojan&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Moreover, trojans protected with a sophisticated software packer were also discovered: &lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57156&lt;/b&gt;, &lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57157&lt;/b&gt;, and &lt;a href="https://vms.drweb.com/search/?q=Android.Packed&amp;lng=en"&gt;&lt;b&gt;Android.Packed&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.57159&lt;/b&gt;, for example.&lt;/p&gt;
  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/12_Android.Packed.57156_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/12_Android.Packed.57156_q4_2024.1.png" alt="Android.Packed"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/13_Android.Packed.57159_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/13_Android.Packed.57159_q4_2024.1.png" alt="Android.Packed"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;The “Lie Detector Fun Prank” and “Speaker Dust and Water Cleaner” programs are trojans protected with a software packer&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Our specialists also detected &lt;a href="https://vms.drweb.com/search/?q=Android.Subscription&amp;lng=en"&gt;&lt;b&gt;Android.Subscription&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.22&lt;/b&gt;, malware designed to subscribe users to paid services.&lt;/p&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/14_Android.Subscription.22_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/14_Android.Subscription.22_q4_2024.1.png" alt="Android.Subscription"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;Instead of editing photos, the “InstaPhoto Editor” program subscribed users to a paid service &lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;At the same time, cybercriminals again distributed trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.Joker&amp;lng=en"&gt;&lt;b&gt;Android.Joker&lt;/b&gt;&lt;/a&gt; family, which also subscribed victims to paid services.&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/15_Android.Joker.2281_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/15_Android.Joker.2281_q4_2024.1.png" alt="Android.Joker"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/16_Android.Joker_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_mobile/16_Android.Joker_q4_2024.1.png" alt="Android.Joker"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;The SMS messenger “Smart Messages” and the third-party keyboard “Cool Keyboard” tried to covertly subscribe victims to a paid service&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.&lt;/p&gt;
  &lt;p&gt;&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q4%202024%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank" rel="noopener noreferrer"&gt;Indicators of compromise&lt;/a&gt;&lt;/p&gt;

&lt;/section&gt;

&lt;style&gt;
    .custom-color-link a {
        color: #73b320;
    }
&lt;/style&gt;


</description></item><item><guid>https://news.drweb.com/show/?i=14959&amp;lng=en</guid><title>Doctor Web’s Q4 2024 virus activity review</title><link>https://news.drweb.com/show/?i=14959&amp;lng=en&amp;c=10</link><pubDate>Thu, 26 Dec 2024 04:00:00 GMT</pubDate><description>


&lt;p&gt;&lt;b&gt;December 26, 2024&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
  &lt;p&gt;&lt;newslead&gt;According to the statistics collected by the Dr.Web anti-virus, the total number of threats detected in the fourth quarter of 2024 decreased by 1.53%, compared to the third quarter. At the same time, the number of unique threats increased by 94.43%. Among the most commonly detected threats were adware programs and adware trojans, malicious scripts, and trojans that are distributed with other malware and used to make the main payload difficult to detect. The majority of detections in email traffic were due to malicious scripts, adware trojans, and cryptocurrency-mining trojans. Increased activity on the part of spyware malicious apps was also noted.&lt;/newslead&gt;&lt;/p&gt;
  &lt;p&gt;Users whose files were affected by encoder trojans most commonly encountered &lt;b&gt;Trojan.Encoder.35534&lt;/b&gt;, &lt;b&gt;Trojan.Encoder.35067&lt;/b&gt;, and &lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.26996&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.26996&lt;/b&gt;&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;Once again, the most widespread threats observed on Android devices were &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojans. At the same time, our malware analysts discovered many new threats.&lt;/p&gt;

  &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
    &lt;h4 class="white alignCenter"&gt;Principal trends in Q4 2024&lt;/h4&gt;
    &lt;ul&gt;
      &lt;li&gt;Adware software and adware trojans were once again the most commonly detected threats.&lt;/li&gt;
      &lt;li&gt;The number of unique threats increased, compared to the previous quarter.&lt;/li&gt;
      &lt;li&gt;Increased activity on the part of spyware trojans in email traffic.&lt;/li&gt;
      &lt;li&gt;The distribution of many trojan apps through Google Play.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/div&gt;
&lt;/section&gt;


&lt;section class="margTM margBM" id="stat"&gt;
  &lt;h2 class="alignCenter"&gt;According to Doctor Web’s statistics service&lt;/h2&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/01_stat_q4_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/01_stat_q4_2024_en.1.png" alt="According to Doctor Web’s statistics service"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;p&gt;The most common threats in Q4 2024:&lt;/p&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Downware.20091&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;VBS.KeySender.6&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A malicious script that, in an infinite loop, searches for windows containing the text &lt;span class="string"&gt;mode extensions&lt;/span&gt;, &lt;span class="string"&gt;разработчика&lt;/span&gt;, and &lt;span class="string"&gt;розробника&lt;/span&gt; and sends them an Escape key press event, forcibly closing them.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
      &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.BPlug.4210&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for malicious components of the WinSafe browser extension. These components are JavaScript files that display intrusive ads in browsers.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Starter.8242&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A malicious program that launches a mining trojan.&lt;/dd&gt;
  &lt;/dl&gt;

  &lt;h2 class="alignCenter"&gt;Statistics for malware discovered in email traffic&lt;/h2&gt;
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/02_mail_traffic_q4_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/02_mail_traffic_q4_2024_en.1.png" alt="Statistics for malware discovered in email traffic"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
      &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;  
    &lt;dt&gt;&lt;b&gt;JS.Inject&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A family of malicious JavaScripts that inject a malicious script into the HTML code of webpages.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;LNK.Starter.56&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for a shortcut that is crafted in a specific way. This shortcut is distributed through removable media, like USB flash drives. To mislead users and conceal its activities, it has a default icon of a disk. When launched, it executes malicious VBS scripts from a hidden directory located on the same drive as the shortcut itself.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Win32.HLLW.Rendoc.3&amp;lng=en"&gt;&lt;b&gt;Win32.HLLW.Rendoc.3&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
      &lt;dd&gt;A network worm that spreads via removeable storage media and other channels.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Fbng.123&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A spyware trojan also known as Formbook. Designed to steal various data from infected devices, it hijacks passwords saved in web browsers, email clients, online messengers, and other software; intercepts input data in web forms; monitors keystrokes (it executes a keylogger functionality); and takes screenshots. In addition, it can download and run other programs and execute various commands, operating as a backdoor.&lt;/dd&gt;  
  &lt;/dl&gt;

&lt;/section&gt;


&lt;section class="margTM margBM" id="encryptor"&gt;
  &lt;h2 class="alignCenter"&gt;Encryption ransomware&lt;/h2&gt;
  &lt;p&gt;In Q4 2024, the number of requests made to decrypt files affected by encoder trojans decreased by 18.96%, compared to Q3 2024.&lt;/p&gt;
  &lt;p&gt;The dynamics of the decryption requests received by Doctor Web’s technical service:&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/03_encoder_requests_q4_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/03_encoder_requests_q4_2024_en.1.png" alt="Encryption ransomware"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;p&gt;The most common encoders of Q4 2024:&lt;/p&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 22.63% of user requests&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder. 35067&lt;/b&gt; — 3.91% of user requests&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.26996&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.26996&lt;/b&gt;&lt;/a&gt; — 3.35% of user requests&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.35209&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.35209&lt;/b&gt;&lt;/a&gt; — 3.07% of user requests&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.38200&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.38200&lt;/b&gt;&lt;/a&gt; — 3.07% of user requests&lt;/dt&gt;
  &lt;/dl&gt;
&lt;/section&gt;


&lt;section class="margTM margBM" id="dangerous"&gt;
  &lt;h2 class="alignCenter"&gt;Network fraud&lt;/h2&gt;
  &lt;p&gt;In Q4 2024, threat actors continued exploiting a popular fraudulent scheme in which they used specially crafted websites to offer potential victims opportunities to make money through different investments. To “access” the investing service, users are asked to register an account by providing personal data that subsequently ends up in the fraudsters’ hands. Residents of various countries have encountered such websites.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/04_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/04_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;On this fraudulent site, supposedly affiliated with the World Bank, European users are assured that they will get dividends for investing in promising economic sectors&lt;/em&gt;&lt;/p&gt;


  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/05_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/05_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A fraudulent website offers Slovak users the chance to “earn more than $192,460 per month” with the help of some investing service&lt;/em&gt;&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/06_fraud_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/06_fraud_q4_2024.1.png" alt="Network fraud"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/07_fraud_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/07_fraud_q4_2024.1.png" alt="Network fraud"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;Fraudsters pose as large banks and oil and gas companies and offer users from Armenia and Moldova opportunities to “make money on stocks”&lt;/em&gt;&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/08_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/08_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;The fake website of an Azerbaijani oil and gas company on which visitors are promised income starting from 1,000 manat per month&lt;/em&gt;&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/09_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/09_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;The website of a “new Google investing platform” offers the opportunity to take a survey and get access to a service that will supposedly allow users to make at least €1,000&lt;/em&gt;&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/10_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/10_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;One of the fraudulent sites promises Russian users “a safe passive income”, starting from 150,000 rubles per month&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Doctor Web’s experts noted a seasonal change in the contents of such sites. Ahead of the New Year holidays, scammers began exploiting the gifts theme, allegedly acting on behalf of banks, oil and gas companies, crypto exchanges, and other organizations. On one such fake site, Russian users supposedly could receive payments from a crypto exchange in accordance with some “lists”. And to check whether such payments are available to them, potential victims were asked to take a survey and provide personal data.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/11_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/11_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;A fake crypto exchange website offers Russian users the chance to get “New Year payments”&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Another fake site informed visitors about some “New Year’s offer” from an oil and gas company, whereby many Kazakhstani users could allegedly start receiving from 200,000 to 1,000,000 tenge per month in honor of the country’s Independence Day. To “receive” payments, potential victims had to submit an “application” by providing their personal information on this website.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/12_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/12_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;This fraudulent site promised Kazakhstani users large payments in honor of Independence Day as part of a “New Year’s offer”&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;At the same time, our Internet analysts detected the emergence of new fake websites of Russian banks. On these, potential victims are asked to take part in a service-quality survey and then allegedly receive a money reward for doing so. Users are asked to provide personal data, including their full names, the mobile phone number linked to their bank account, as well as their bank card number.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/13_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/13_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;An example of a bogus site that mimics the appearance of a genuine bank website and offers potential victims the opportunity to participate in the survey for a reward&lt;/em&gt;&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/14_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/14_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;To “participate” in the survey, the user has to fill out the form by providing their personal information &lt;/em&gt;&lt;/p&gt;


  &lt;p&gt;Moreover, fraudulent sites offering online training, such as programming, were identified. Interested visitors were asked to leave their contact information to “receive a consultation”.&lt;/p&gt;


  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/15_fraud_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/15_fraud_q4_2024.1.png" alt="Network fraud"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/16_fraud_q4_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/16_fraud_q4_2024.1.png" alt="Network fraud"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;A website that offers programming courses online. To “receive a consultation”, users have to provide their personal information.&lt;/em&gt;&lt;/p&gt;


  &lt;p&gt;Online scammers keep trying to steal Telegram accounts. In Q4 2024, more phishing sites disguised as various online voting platforms were discovered, for example, for “children’s drawing competitions”. To “confirm” their vote, users are asked to provide their mobile phone number to which a verification code will be sent. However, by typing this code on the bogus website, they are granting fraudsters access to their accounts.&lt;/p&gt;


  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/17_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/17_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A scammer website on which visitors are asked to vote in the children’s drawing competition&lt;/em&gt;&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/18_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/18_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;A “vote counting system” demands a mobile phone number for “confirming the vote” and sending a one-time code&lt;/em&gt;&lt;/p&gt;


  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/december/review_common/19_fraud_q4_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/december/review_common/19_fraud_q4_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargT alignCenter"&gt;&lt;em&gt;When victims enter the received code, they grant the fraudsters access to their Telegram accounts &lt;/em&gt;&lt;/p&gt;

  &lt;div class="CellBlock dangerous_urls_new alignCenter"&gt;
    &lt;a href="https://antifraud.drweb.com/dangerous_urls/?lng=en" target="_blank" rel="noopener noreferrer" class="fontM font2X white textShadow"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;
  &lt;/div&gt;  
&lt;/section&gt;

&lt;section class="margTM margBM" id="formobile"&gt;
  &lt;h2 class="alignCenter"&gt;Malicious and unwanted programs for mobile devices&lt;/h2&gt;
  &lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q4 2024, users most often encountered &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojans and the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Android.Siggen&lt;/b&gt; malicious apps. At the same time, over the past quarter, Doctor Web’s experts discovered many new threats on Google Play.&lt;/p&gt;
  &lt;p&gt;The following Q4 2024 events involving mobile malware are the most noteworthy:&lt;/p&gt;
  &lt;ul&gt;
    &lt;li&gt;High activity on the part of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojans and &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fraudulent malware,&lt;/li&gt;
    &lt;li&gt;The emergence of new malicious apps on Google Play.&lt;/li&gt;
  &lt;/ul&gt;

  &lt;p&gt;To find out more about the security-threat landscape for mobile devices in Q4 2024, read our &lt;a href="https://news.drweb.com/show/review/?i=14950&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;special overview&lt;/a&gt;.&lt;/p&gt;

&lt;/section&gt;


&lt;style&gt;
    .custom-color-link a {
        color: #73b320;
    }
&lt;/style&gt;

</description></item><item><guid>https://news.drweb.com/show/?i=14912&amp;lng=en</guid><title>Doctor Web’s Q3 2024 review of virus activity on mobile devices</title><link>https://news.drweb.com/show/?i=14912&amp;lng=en&amp;c=10</link><pubDate>Tue, 01 Oct 2024 03:00:00 GMT</pubDate><description>


&lt;p&gt;&lt;b&gt;October 1, 2024&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
  &lt;p&gt;&lt;newslead&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojan apps, used by threat actors in various fraudulent schemes, were the malicious programs most frequently detected on protected devices in the third quarter of 2024. Adware trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family ranked second. The third most commonly detected threats were &lt;b&gt;Android.Siggen&lt;/b&gt; trojans—programs that have different malicious functionality and that are difficult to classify into any particular family.&lt;/newslead&gt;&lt;/p&gt;
  &lt;p&gt;In August, Doctor Web’s experts discovered the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor, which had infected nearly 1.3 million Android TV box sets belonging to users in 197 countries. This malicious app places its components into the system storage area of infected devices and, when commanded by threat actors, can covertly download and install various programs.&lt;/p&gt;

&lt;p class="alignCenter"&gt;
  &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/02_Android.Vo1d_map_en.png" class="preview"&gt;
    &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/02_Android.Vo1d_map_en.png" alt="Countries with the highest number of infected devices detected" style="width:75%;"&gt;
  &lt;/a&gt;
&lt;/p&gt;

  &lt;p&gt;In addition, banking trojans targeting Indonesian users were found. One of these, &lt;b&gt;Android.SmsSpy.888.origin&lt;/b&gt;, is protected with a software packer and detected as &lt;b&gt;Android.Siggen.Susp.9415&lt;/b&gt;. It was distributed under the guise of the BRI bank customer support app BRImo Support.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_1_en.jpg" class="preview alignCenter"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_1_en.1.jpg" alt="#drweb"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  
  &lt;p&gt;When launched, the trojan loads the real bank website https://bri.co.id in WebView. At the same time, it uses a Telegram bot API to send technical information about the infected device into the Telegram chat created by the threat actors.&lt;/p&gt;
  &lt;p&gt;&lt;b&gt;Android.SmsSpy.888.origin&lt;/b&gt; intercepts incoming SMS and also sends them into this chat. When it receives messages like &lt;span class="string"&gt;55555, &amp;lt;number&amp;gt;, &amp;lt;text&amp;gt;&lt;/span&gt;, it interprets them as commands and sends corresponding messages containing the text &lt;span class="string"&gt;&amp;lt;text&amp;gt;&lt;/span&gt; to the number &lt;span class="string"&gt;&amp;lt;number&amp;gt;&lt;/span&gt;. This way, the malware can both send SMS spam and spread among users.&lt;/p&gt;
  &lt;p&gt;Another trojan that attacked Indonesian users was &lt;b&gt;Android.SmsSpy.11629&lt;/b&gt;. This malicious program is an SMS spy that is distributed under the guise of all kinds of apps. The variant in question was targeting Bank Mandiri Taspen customers and was passed off by the attackers as an official banking app—Movin by Bank Mandiri Taspen. The trojan displays instructions to potential victims and asks them to accept a user agreement. When a user accepts it, the trojan requests the permissions needed to work with SMS.&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_2_en.jpg" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_2_en.1.jpg" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_3_en.jpg" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_3_en.1.jpg" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_4_en.jpg" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_4_en.1.jpg" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;  

  &lt;p&gt;Next, the malicious program loads a real page of the bank’s website https://mail.bankmantap.co.id/: in WebView:&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_5_en.jpg" class="preview alignCenter"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/mob_review_5_en.1.jpg" alt="#drweb"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;p&gt;&lt;b&gt;Android.SmsSpy.11629&lt;/b&gt; intercepts all incoming SMS. Next, it uses the Telegram bot API to send these messages into the attackers’ Telegram chat. It adds the text &lt;span class="string"&gt;developed by : @AbyssalArmy&lt;/span&gt; to all of the messages.&lt;/p&gt;
  &lt;p&gt;At the same time, our malware analysts again discovered threats on Google Play. Among them were many new fake apps and several ad-displaying trojans.&lt;/p&gt;
&lt;/section&gt;

&lt;section class="margTM margBM" id="stat"&gt;
  &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
    &lt;h4 class="white alignCenter"&gt;PRINCIPAL TRENDS OF Q3 2024&lt;/h4&gt;
    &lt;ul&gt;
      &lt;li&gt;The &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor infected over a million TV box sets&lt;/li&gt;
      &lt;li&gt;High activity on the part of &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious apps, which are used to commit fraud&lt;/li&gt;
      &lt;li&gt;High activity on the part of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans &lt;/li&gt;
      &lt;li&gt;The emergence of new malware on Google Play      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/div&gt;

  &lt;h2 class="alignCenter"&gt;According to statistics collected by Dr.Web Security Space for mobile devices&lt;/h2&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/02_malware_q3_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/02_malware_q3_2024_en.1.png" alt="According to statistics collected by Dr.Web Security Space for mobile devices"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1600&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A trojan app that loads a website that is hardcoded into its settings. Known modifications of this malicious program load an online casino site.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.3994&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A trojan app designed to display intrusive ads. Members of the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7815&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.MobiDash&amp;lng=en"&gt;&lt;b&gt;Android.MobiDash&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.7813&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;Trojans that display obnoxious ads. These are special software modules that developers incorporate into applications.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Android.Click.1751&amp;lng=en"&gt;&lt;b&gt;Android.Click.1751&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
      &lt;dd&gt;This trojan is built into third-party WhatsApp messenger mods and camouflaged as Google library classes. While the host application is being used, &lt;a href="https://vms.drweb.com/search/?q=Android.Click.1751&amp;lng=en"&gt;&lt;b&gt;Android.Click.1751&lt;/b&gt;&lt;/a&gt; connects to one of the C&amp;C servers. It receives two URLs from it. One of them is intended for Russian-speaking users, and the other is for everyone else. The trojan then displays a dialog box whose contents it has also received from a remote server. When a user clicks on the confirmation button, malware loads the corresponding link in their browser.&lt;/dd&gt;
  &lt;/dl&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/03_unwanted_q3_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/03_unwanted_q3_2024_en.1.png" alt="Статистика вредоносных программ в почтовом трафике"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.CloudInject&amp;lng=en"&gt;&lt;b&gt;Program.CloudInject&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as &lt;a href="https://vms.drweb.com/search/?q=Tool.CloudInject&amp;lng=en"&gt;&lt;b&gt;Tool.CloudInject&lt;/b&gt;&lt;/a&gt;). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, users can remotely manage these apps. They can block them, display custom dialogs, and track when other software is being installed or removed from a device, etc.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.FakeAntiVirus&amp;lng=en"&gt;&lt;b&gt;Program.FakeAntiVirus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for adware programs that imitate anti-virus software. These apps inform users of nonexistent threats, mislead them, and demand that they purchase the software’s full version.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.SecretVideoRecorder&amp;lng=en"&gt;&lt;b&gt;Program.SecretVideoRecorder&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for various modifications of an application that is designed to record videos and take photos in the background, using built-in Android device cameras. It can operate covertly by allowing notifications about ongoing recordings to be disabled. It also allows an app’s icon and name to be replaced with fake ones. This functionality makes this software potentially dangerous.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Program.TrackView&amp;lng=en"&gt;&lt;b&gt;Program.TrackView&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for a program that allows users to be monitored via their Android devices. Malicious actors can utilize it to track a target device’s location, use the camera to record video and take photos, eavesdrop via the microphone, record audio, etc.&lt;/dd&gt;
  &lt;/dl&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/04_riskware_q3_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/04_riskware_q3_2024_en.1.png" alt="Статистика вредоносных программ в почтовом трафике"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.Packer&amp;lng=en"&gt;&lt;b&gt;Tool.Packer&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A packer tool designed to protect Android applications from unauthorized modifications and reverse engineering. This tool is not malicious in itself, but it can be used to protect both harmless and malicious software.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.SilentInstaller&amp;lng=en"&gt;&lt;b&gt;Tool.SilentInstaller&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.17.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A riskware platform that allows applications to launch APK files without installing them. It creates a virtual runtime environment in the context of the apps in which they are integrated. The APK files, launched with the help of this platform, can operate as if they are part of such programs and can also obtain the same permissions.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.1&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Tool.NPMod.2&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for Android programs that have been modified using the NP Manager utility. A special module is embedded in such apps, and it allows them to bypass digital signature verification once they have been modified.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Tool.LuckyPatcher&amp;lng=en"&gt;&lt;b&gt;Tool.LuckyPatcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads specially prepared scripts from the Internet, which can be crafted and added to the common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.&lt;/dd&gt;   
  &lt;/dl&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/05_adware_q3_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/05_adware_q3_2024_en.1.png" alt="Статистика вредоносных программ в почтовом трафике"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;Adware.ModAd.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for some modified versions (mods) of the WhatsApp messenger, whose functions have been injected with a specific code. This code is responsible for loading target URLs by displaying web content (via the Android WebView component) when the messenger is in operation. Such web addresses perform redirects to advertised sites, including online casino, bookmaker, and adult sites.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Basement.1&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;These are apps that display unwanted ads which often lead to malicious and fraudulent websites. They share a common code base with the &lt;a href="https://vms.drweb.com/search/?q=Program.FakeMoney&amp;lng=en"&gt;&lt;b&gt;Program.FakeMoney&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.11&lt;/b&gt; unwanted applications.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Fictus&amp;lng=en"&gt;&lt;b&gt;Adware.Fictus&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.1.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;An adware module that malicious actors embed into the cloned versions of popular Android games and applications. Its incorporation is facilitated by a specialized net2share packer. Copies of software created this way are then distributed through various software catalogs. When installed on Android devices, such apps and games display obnoxious ads.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.Adpush&amp;lng=en"&gt;&lt;b&gt;Adware.Adpush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.21846&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Adware.AdPush&amp;lng=en"&gt;&lt;b&gt;Adware.AdPush&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.39.origin&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.&lt;/dd&gt;  
  &lt;/dl&gt;

&lt;/section&gt;

&lt;section class="margTM margBM" id="formobile"&gt;
  &lt;h2 class="alignCenter"&gt;Threats on Google Play&lt;/h2&gt;

  &lt;p&gt;In Q3 2024, Doctor Web’s malware analysts continued uncovering threats on Google Play. Among these were many new &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; fake programs that were distributed under the guise of a variety of software. Malicious actors passed some of them off as finance-related programs, such as investing apps, financial reference books and teaching aids, different home bookkeeping tools, and so on. Quite a few of these did actually provide the stated functionality, but their primary task is to load fraudulent websites. Such sites promise potential victims quick and easy money through investments, trading natural resources, cryptocurrency, etc. To supposedly join the “service”, users are asked to register an account or to provide personal data by filling out an “application”.&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/06_Android.FakeApp.1643_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/06_Android.FakeApp.1643_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/07_Android.FakeApp.1644_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/07_Android.FakeApp.1644_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;

  &lt;p&gt;It is noteworthy that fraudsters disguised one of the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans as an online dating and chat app. However, it also loaded a bogus “investing” site.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/08_Android.FakeApp.1624_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/08_Android.FakeApp.1624_q3_2024.1.png" alt="Статистика вредоносных программ в почтовом трафике"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;p&gt;Other &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; trojans were again distributed as games. Under certain conditions, they loaded online casino and bookmaker sites.&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/09_Android.FakeApp.1663_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/09_Android.FakeApp.1663_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/10_Android.FakeApp.1649_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/10_Android.FakeApp.1649_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;

  &lt;p&gt;Among these fake apps, our experts also detected new trojan variants that masquerade as job-search tools. Such malware loads fake job lists and suggests to users that they contact the applicable employer via a messenger (this “employer” is, in fact, a fraudster) or that they create a “resume” by providing personal data.&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/11_Android.FakeApp.1627_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/11_Android.FakeApp.1627_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/12_Android.FakeApp.1661_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/12_Android.FakeApp.1661_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;

  &lt;p&gt;Doctor Web’s virus analysts also discovered more &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; trojans on Google Play. These trojans conceal their icons from the home screen menu and start displaying intrusive ads. The detected malware was camouflaged as various apps, including image collections, photo-editing software, and barcode scanners.&lt;/p&gt;

  &lt;div class="margTM margBM column_grid_review column_grid_review--h"&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/13_Android.HiddenAds.4034_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/13_Android.HiddenAds.4034_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
    &lt;div class="flex fxCenter"&gt;
      &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/14_Android.HiddenAds.4100_q3_2024.png" class="preview"&gt;
        &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_mobile/14_Android.HiddenAds.4100_q3_2024.1.png" alt="spinok_ads_2023"&gt;
      &lt;/a&gt;
    &lt;/div&gt;
  &lt;/div&gt;

  &lt;p&gt;To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.&lt;/p&gt;

  &lt;p&gt;&lt;a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Q3%202024%20review%20of%20virus%20activity%20on%20mobile%20devices/README.adoc" target="_blank" rel="noopener noreferrer"&gt;Indicators of compromise&lt;/a&gt;&lt;/p&gt;

&lt;/section&gt;

&lt;style&gt;
    .custom-color-link a {
        color: #73b320;
    }
&lt;/style&gt;

</description></item><item><guid>https://news.drweb.com/show/?i=14915&amp;lng=en</guid><title>Doctor Web’s Q3 2024 virus activity review</title><link>https://news.drweb.com/show/?i=14915&amp;lng=en&amp;c=10</link><pubDate>Tue, 01 Oct 2024 01:00:00 GMT</pubDate><description>


&lt;p&gt;&lt;b&gt;October 1, 2024&lt;/b&gt;&lt;/p&gt;

&lt;section class="margTM margBM" id="main"&gt;
  &lt;p&gt;&lt;newslead&gt;According to the detection statistics collected by the Dr.Web antivirus, the total number of threats detected in the third quarter of 2024 was up 10.81% over the previous quarter. The number of unique threats decreased by 4.73%. The majority of detections were due to adware programs. Also widespread were malicious scripts, ad-displaying trojans, and trojans distributed within other malware to make the latter more difficult to detect. In email traffic, malicious scripts and programs that exploit vulnerabilities in Microsoft Office documents were most commonly detected.&lt;/newslead&gt;&lt;/p&gt;
  &lt;p&gt;On Android devices, the most commonly detected threats were trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; family, which are used for fraudulent purposes; &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; adware trojans; and &lt;b&gt;Android.Siggen&lt;/b&gt; malicious apps possessing different functionality. At the same time, in August, our experts discovered &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt;, a new trojan that had infected nearly 1.3 million TV box sets running Android. In addition, several banking trojans targeting Indonesian users were found.&lt;/p&gt;
  &lt;p&gt;Doctor Web’s virus laboratory also uncovered many new threats on Google Play throughout the third quarter.&lt;/p&gt;
  
  &lt;div class="paddXM paddYM bg_ocean_1 white custom-color-link"&gt;
    &lt;h4 class="white alignCenter"&gt;Principal trends in Q3 2024&lt;/h4&gt;
    &lt;ul&gt;
      &lt;li&gt;Adware programs remained the most commonly detected threats.&lt;/li&gt;
      &lt;li&gt;Malicious scripts were again predominant in malicious email traffic.&lt;/li&gt;
      &lt;li&gt;Over 1 million Android-based TV box sets were found to be infected with the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor.&lt;/li&gt;
      &lt;li&gt;New threats were discovered on Google Play.      &lt;/li&gt;
    &lt;/ul&gt;
  &lt;/div&gt;
&lt;/section&gt;


&lt;section class="margTM margBM" id="stat"&gt;
  &lt;h2 class="alignCenter"&gt;According to Doctor Web’s statistics service&lt;/h2&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/01_stat_q3_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/01_stat_q3_2024_en.1.png" alt="According to Doctor Web’s statistics service"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;p&gt;The most common threats in Q3 2024:&lt;/p&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Downware.20091&lt;/b&gt;&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Downware.20477&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;Adware that often serves as an intermediary installer of pirated software.&lt;/dd&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
      &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.StartPage1.62722&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A malicious program that can modify the home page in the browser settings.&lt;/dd&gt;
    &lt;dt&gt;&lt;b&gt;Adware.Ubar.20&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A torrent client designed to install unwanted programs on a user’s device.&lt;/dd&gt; 
  &lt;/dl&gt;


  &lt;h2 class="alignCenter"&gt;Statistics for malware discovered in email traffic&lt;/h2&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/02_mail_traffic_q3_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/02_mail_traffic_q3_2024_en.1.png" alt="Statistics for malware discovered in email traffic"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=JS.Siggen5.44590&amp;lng=en"&gt;&lt;b&gt;JS.Siggen5.44590&lt;/b&gt;&lt;/a&gt;&lt;/dt&gt;
      &lt;dd&gt;Malicious code added to the es5-ext-main public JavaScript library. It shows a specific message if the package is installed on a server with the time zone of a Russian city.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;b&gt;JS.Inject&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A family of malicious JavaScripts that inject a malicious script into the HTML code of webpages.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;b&gt;LNK.Starter.56&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for a shortcut that is crafted in a specific way. This shortcut is distributed through removable media, like USB flash drives. To mislead users and conceal its activities, it has a default icon of a disk. When launched, it executes malicious VBS scripts from a hidden directory located on the same drive as the shortcut itself.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;b&gt;W97M.DownLoader.6154&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.&lt;/dd&gt;
    
    &lt;dt&gt;&lt;b&gt;Trojan.AutoIt.1410&lt;/b&gt;&lt;/dt&gt;
      &lt;dd&gt;The detection name for packed versions of the &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; malicious app that are written in the AutoIt scripting language. This trojan is distributed as part of a group of several malicious applications, including a miner, a backdoor, and a self-propagating module. &lt;a href="https://vms.drweb.com/search/?q=Trojan.AutoIt.289&amp;lng=en"&gt;&lt;b&gt;Trojan.AutoIt.289&lt;/b&gt;&lt;/a&gt; performs various malicious actions that make it difficult for the main payload to be detected.&lt;/dd&gt;  
  &lt;/dl&gt;
&lt;/section&gt;


&lt;section class="margTM margBM" id="encryptor"&gt;
  &lt;h2 class="alignCenter"&gt;Encryption ransomware&lt;/h2&gt;
  &lt;p&gt;In Q3 2024, the number of requests made to decrypt files affected by encoder trojans decreased by 15.73%, compared to Q2 2024.&lt;/p&gt;
  &lt;p&gt;The dynamics of the requests Doctor Web’s technical service received to decrypt files affected by encoder trojans:&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/03_encoder_requests_q3_2024_en.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/03_encoder_requests_q3_2024_en.1.png" alt="Encryption ransomware"&gt;
    &lt;/a&gt;
  &lt;/div&gt;

  &lt;p&gt;The most common encoders of Q3 2024:&lt;/p&gt;
  &lt;dl class="dlList"&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35534&lt;/b&gt; — 19.38%&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.3953&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.3953&lt;/b&gt;&lt;/a&gt; — 9.42%&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.38200&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.38200&lt;/b&gt;&lt;/a&gt; — 3.99%&lt;/dt&gt;
    &lt;dt&gt;&lt;a href="https://vms.drweb.com/search/?q=Trojan.Encoder.26996&amp;lng=en"&gt;&lt;b&gt;Trojan.Encoder.26996&lt;/b&gt;&lt;/a&gt; — 2.89%&lt;/dt&gt;
    &lt;dt&gt;&lt;b&gt;Trojan.Encoder.35067&lt;/b&gt; — 2.72%&lt;/dt&gt;
  &lt;/dl&gt;
&lt;/section&gt;


&lt;section class="margTM margBM" id="dangerous"&gt;
  &lt;h2 class="alignCenter"&gt;Network fraud&lt;/h2&gt;
  &lt;p&gt;During Q3 2024, Internet scammers continued distributing spam emails containing links leading to various fraudulent sites. Russian-speaking users, for example, again dealt with messages that were supposedly sent on behalf of well-known online stores. Some of these mails offered users the ability to participate in prize draws or get a gift. After clicking on the links in such emails, potential victims were directed to fraudulent sites where they were asked to pay a commission to “receive” their gift or their winnings.&lt;/p&gt;
  
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/04_fake_store_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/04_fake_store_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;Scammers, allegedly on behalf of an online store, offer their potential victim the chance to “receive their winnings” of 208,760 rubles&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;In other emails, users were supposedly given a discount that could be used to purchase goods in a large electronics store. The links from such messages led to a fake website designed in the style of the genuine store’s site. When potential victims placed an “order” on this fake Internet resource, they had to provide their personal data and bank card information.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/05_fake_store_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/05_fake_store_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;A fraudulent email that lets recipients “activate a promo code” for buying electronics&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Finance-themed spam remains popular among fraudsters. For instance, threat actors were sending unwanted emails for users to “confirm” their receipt of large money transfers. An example of one such mail targeting English-speaking users is shown below. It contained a link that led to the phishing login form of an online bank that outwardly resembled the form on the real bank’s website.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/06_fake_bank_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/06_fake_bank_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;The user supposedly needs to confirm receipt of US $1,218.16&lt;/em&gt;&lt;/p&gt;

  &lt;div class="margTM column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/07_fake_bank_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/07_fake_bank_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;A phishing site that fraudsters pass off as a genuine bank website&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;Among the unwanted emails targeting Japanese users, our experts detected yet more fake bank notifications—for example, ones that supposedly contained the previous month’s bank card statement. In one of these messages, the scammers camouflaged the link to the phishing site. In the text of the letter, users saw links to the real addresses of the bank’s website, but when they clicked on them, they were taken to a fraudulent Internet resource.&lt;/p&gt;
  
  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/08_ja_spam_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/08_ja_spam_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;All the links in this email actually lead to a phishing website&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;French-speaking users (from Belgium, in particular) encountered phishing emails informing them that their bank accounts were “blocked”. To get them “unblocked”, they were asked to follow a link that actually led to the fraudsters’ website.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/09_fake_bank_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/09_fake_bank_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;Scammers scare potential victims with a “blocked” bank account message&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;And among Russian users, email spam, sent presumably on behalf of famous banks and offering investor opportunities, was once again actively being distributed. The links in such unwanted emails lead to fraudulent sites where visitors, under the pretense of accessing investing services, are asked to provide personal data.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/10_fake_bank_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/10_fake_bank_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;The user, allegedly on behalf of the bank, is being offered the chance to complete a test and become an investor&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;At the same time, Doctor Web’s Internet analysts detected new phishing websites targeting cryptocurrency owners. On one of them, for example, visitors were informed, supposedly on behalf of a large cryptocurrency exchange, about an undelivered Bitcoin transfer. To “complete” the transaction, potential victims were asked to pay a “commission”. Naturally, no cryptocurrency was ever received by the users—all they did was give their own assets to the scammers.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/11_fake_crypto_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/11_fake_crypto_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;This fraudulent site informs users about a supposedly unreceived Bitcoin transfer&lt;/em&gt;&lt;/p&gt;

  &lt;p&gt;In addition, websites were detected that imitated the look of the VKontakte Russian social network. Visitors to these fake sites were offered the chance to participate in some prize drawing, for which they needed to open several virtual gift boxes. After the potential victims opened the “correct” boxes and allegedly won a large amount of money, the site proposed that they pay a “fee” to receive their “winnings”.&lt;/p&gt;

  &lt;div class="column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/12_fake_social_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/12_fake_social_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;A fraudulent site offering visitors the opportunity to “try their luck”&lt;/em&gt;&lt;/p&gt;

  &lt;div class="margTM column_grid_review column_grid_review--o"&gt;
    &lt;a href="https://st.drweb.com/static/new-www/news/2024/september/review_common/13_fake_social_q3_2024.png" class="preview"&gt;
      &lt;img src="https://st.drweb.com/static/new-www/news/2024/september/review_common/13_fake_social_q3_2024.1.png" alt="Network fraud"&gt;
    &lt;/a&gt;
  &lt;/div&gt;
  &lt;p class="noMargY alignCenter"&gt;&lt;em&gt;This user has supposedly won a prize of 194,562 rubles&lt;/em&gt;&lt;/p&gt;

  &lt;div class="CellBlock dangerous_urls_new alignCenter"&gt;
    &lt;a href="https://antifraud.drweb.com/dangerous_urls/?lng=en" target="_blank" rel="noopener noreferrer" class="fontM font2X white textShadow"&gt;Find out more about Dr.Web non-recommended sites&lt;/a&gt;
  &lt;/div&gt;  
&lt;/section&gt;


&lt;section class="margTM margBM" id="formobile"&gt;
  &lt;h2 class="alignCenter"&gt;Malicious and unwanted programs for mobile devices&lt;/h2&gt;
  &lt;p&gt;According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q3 2024, &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious apps, which threat actors use in various fraudulent schemes, were most often detected on protected devices. The second most common were adware trojans from the &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; family. These were followed by &lt;b&gt;Android.Siggen&lt;/b&gt; trojans.&lt;/p&gt;
  &lt;p&gt;Over the past observation period, our specialists discovered many new threats on Google Play. Among them were different trojan variants from the &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; and &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; families. Moreover, an attack on Android TV box sets was detected, with the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor infecting about 1.3 million devices from users in 197 countries. It placed its component in the system storage area and, when commanded by threat actors, could covertly download and install third-party software. Additionally, banking trojans &lt;b&gt;Android.SmsSpy.888.origin&lt;/b&gt; and &lt;b&gt;Android.SmsSpy.11629&lt;/b&gt; were found that targeted Indonesian users.&lt;/p&gt;
  &lt;p&gt;The following Q3 2024 events involving mobile malware are the most noteworthy:&lt;/p&gt;
  &lt;ul&gt;
    &lt;li&gt;The discovery of the &lt;a href="https://vms.drweb.com/search/?q=Android.Vo1d&amp;lng=en"&gt;&lt;b&gt;Android.Vo1d&lt;/b&gt;&lt;/a&gt; backdoor, which infected over a million TV box sets,&lt;/li&gt;
    &lt;li&gt;High activity on the part of &lt;a href="https://vms.drweb.com/search/?q=Android.FakeApp&amp;lng=en"&gt;&lt;b&gt;Android.FakeApp&lt;/b&gt;&lt;/a&gt; malicious apps,&lt;/li&gt;
    &lt;li&gt;High activity on the part of &lt;a href="https://vms.drweb.com/search/?q=Android.HiddenAds&amp;lng=en"&gt;&lt;b&gt;Android.HiddenAds&lt;/b&gt;&lt;/a&gt; ad-displaying trojans,&lt;/li&gt;
    &lt;li&gt;The emergence of new threats on Google Play.&lt;/li&gt;
  &lt;/ul&gt;

  &lt;p&gt;To find out more about the security-threat landscape for mobile devices in Q3 2024, read our &lt;a href="https://news.drweb.com/show/review/?i=14912&amp;lng=en" target="_blank" rel="noopener noreferrer"&gt;special overview&lt;/a&gt;.&lt;/p&gt;

&lt;/section&gt;

&lt;style&gt;
    .custom-color-link a {
        color: #73b320;
    }
&lt;/style&gt;
</description></item></channel></rss>
