Doctor Web’s Q3 2026 virus activity review

Virus reviews | All the news

October 1, 2026

According to statistics collected by the Dr.Web anti-virus, in the third quarter (Q3) of 2026, users encountered various threats 14.86% less often, compared to the second quarter (Q2). The number of unique files involved in attacks decreased by 49.26%. At the same time, compared to the previous observation period, 63.39% fewer unique names were among the threats detected. Most commonly found on protected devices were ad-displaying programs and trojans, malware that steals passwords and other confidential information, and also droppers and downloaders that install various threats on target systems. In addition, trojans used to automatically launch other malicious programs remained active.

The number of decryption requests received by the Doctor Web Technical Support Service increased by 5.85%, compared to Q2. The requests primarily concerned the encoder trojans Trojan.Encoder.35534, Trojan.Encoder.41868, and Trojan.Encoder.44474.

Malicious scripts, mostly downloaders and droppers that install other threats on target systems, were the threats most frequently detected in email traffic. Phishing documents, exploits, and various trojans were also distributed via email. As with malicious scripts, the highest activity among the latter was from droppers and downloaders.

In Q3, Doctor Web’s internet analysts continued to observe growing fraudster interest in targeting users of the Russian messenger MAX. Our experts identified numerous new phishing websites created to steal accounts for this platform. At the same time, threat actors remained interested in gaining access to accounts for other messengers, including Telegram. Users also encountered other phishing online resources, including more fake banking websites.

In July, Doctor Web’s anti-virus laboratory informed users about a trojan targeting software developers. It infects C++ and C# programming projects, causing the compiled apps to also become infected and participate in spreading the threat further. Furthermore, if the affected projects are made publicly available, other developers who download and use them also compromise their own systems and all of the programs they create. This trojan performs several malicious functions at once: it operates as a data stealer, a cryptocurrency miner, a backdoor, and also as a clipper, which hijacks information from the clipboard.

During the last three months, Android users most frequently encountered Android.Proxy malicious programs, which allow attackers to redirect traffic through infected devices. An increase in the activity of Android.Banker banking trojans was also observed. Android apps modified using hacking tools remain among the most commonly detected threats; malware creators use such utilities to protect malicious programs from detection and analysis.

Over the course of Q3, Doctor Web’s virus analysts identified dozens of trojan apps on Google Play. Among them were numerous Android.Joker trojans which subscribe victims to paid services. Our specialists discovered that functionality has been added to some new variants of these malicious apps, enabling infected devices to be turned into exit nodes for a proxy botnet.

Principal trends in Q3

  • Users encountered various threats less often.
  • The number of unique files involved in attacks decreased.
  • There were fewer unique names among the detected threats.
  • The number of user requests to decrypt files affected by encoder trojans increased, compared to Q2.
  • Online fraudsters continued to actively target users of the Russian messenger MAX in an attempt to gain access to their accounts.
  • Doctor Web’s virus analysts discovered a dangerous, multifunctional trojan that targets software developers and spreads by infecting projects created in the C++ and C# programming languages.
  • Trojans from the Android.Proxy family, which allow attackers to redirect network traffic through infected devices, were the most prevalent Android threats.
  • New malicious apps were discovered on Google Play.

According to Doctor Web’s statistics service

The most common threats in Q3 2026

Adware.Downware.20091
Adware that often serves as an intermediary installer of pirated software.
Trojan.Siggen31.34463
A trojan written in the Go programming language and designed to download various miner trojans and adware into infected systems. This malware is a DLL file located at %appdata%\utorrent\lib.dll. To launch, it exploits a DLL Search Order Hijacking vulnerability in the uTorrent client.
Trojan.PWS.Salat.390
A trojan program that steals passwords from various services as well as other confidential information.
Adware.Ubar.20
A torrent client designed to install unwanted programs on a user’s device.
Adware.Proxy.32
A program that turns a target computer into a proxy network exit node and allows third-party traffic to be routed through the device.

Statistics for malware discovered in email traffic

The most widespread threats in email traffic in Q3 2026

X97M.DownLoader.2343
An XLSX file (the Microsoft Excel spreadsheet format) with an OLE object that downloads a malicious file onto an attacked computer.
W97M.DownLoader.2938
A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.
JS.DownLoader.9376
A malicious JavaScript that downloads other malware onto the target system.
VBS.Starter.541
A malicious script in Visual Basic Script format. It is designed to launch various malicious apps on target computers.
JS.Muldrop.1417
A malicious JavaScript that executes malware hidden within it on the target system.

Encryption ransomware

From Q2 to Q3 2026, the number of requests made to decrypt files affected by encoder trojans rose by 5.82%.

The dynamics of the decryption requests received by Doctor Web’s Technical Support Service:

User requests were most frequently related to the activity of the following encoders:

  • Trojan.Encoder.35534 — 13.98% of requests
  • Trojan.Encoder.41868 — 3.76% of requests
  • Trojan.Encoder.44474 — 3.23% of requests
  • Trojan.Encoder.30356 — 2.69% of requests
  • Trojan.Encoder.44383 — 2.15% of requests

Network fraud

In Q3 2026, fraudsters continued to show increasing interest in users of the Russian messenger MAX—a trend Doctor Web’s internet analysts had noted in the previous quarter. Over the course of the last three months, our experts identified a large group of bogus lookalike websites created by threat actors to steal accounts for this messenger. On these sites, potential victims could allegedly access a variety of services and offerings. To do so, they were asked, under various pretexts, to provide their mobile phone number and the verification code sent to it. In some cases, users were directly told that, in order to get what they wanted, they needed to log in to their MAX account. In other scenarios, authentication was not mentioned at all, and the required phone number and confirmation code were supposedly needed only to verify that visitors were human, not bots. However, regardless of the stated reason, if users fell for the trick and provided the corresponding data, the outcome was the same: scammers gained access to their accounts. Furthermore, such websites frequently contained spelling, grammatical, and punctuation errors.

One of the covers for the attackers was the resumption of Roblox gaming platform operations in Russia in early summer. This platform is popular among children and teenagers—an audience traditionally more vulnerable to cyber threats and, therefore, an attractive target for malicious actors.

In one scenario, potential victims were offered free Robux (the service’s in-game digital currency) as a gift to “celebrate the unblocking” of Roblox. Depending on the website, the fraudsters promised between 1,000 and 30,000 coins:

To “obtain” those, users had to click the corresponding button, e.g., Забрать (Claim) or Получить (Get), provide a mobile phone number for “confirmation”, and then enter a verification code received via SMS or directly within the MAX messenger:

In other scenarios, visitors were offered the chance to get various scripts and cheats for Roblox, rare in-game items, and “tappers”—simple clicker games and apps where tapping the screen accumulates virtual resources (e.g., points, bonuses, and coins) that can supposedly be transferred to a specific game. To “access” them, potential victims similarly had to press the corresponding button (Скачать (Download), Подтвердить (Confirm), etc.) and provide a phone number for “verification”:

Cybercriminals also exploited the image of Brawl Stars—yet another game popular with young audiences. As with Roblox, the fraudulent sites offered potential victims a chance to get free in-game items and bonuses. MAX users could supposedly obtain them by scanning a special QR code:

To “obtain” the corresponding QR code, they were required to “complete verification via MAX” by providing a mobile phone number and a code received via SMS or the messenger:

In addition, on some of these phishing websites, scammers—supposedly on behalf of the game itself or its developers—promised various gifts, such as free reward boxes:

Fraudsters promise gifts from Brawl Stars and SUPERCELL, including free boxes with in-game items (for example, boxes of the character Bolt). Users are asked to press the confirmation button and enter a mobile phone number and a verification code

In addition to offering the chance to obtain various bonuses and gifts for popular games, cybercriminals attempted to lure potential victims with other offers as well. These included alleged social media promotion services, such as Likee. Scammers promised to artificially boost the number of followers, likes, and comments, but for this, users supposedly had to log in to MAX messenger:

A phishing website promises promotion on the Likee social network, but this supposedly requires authentication via the MAX messenger

Some of these sites offered visitors specialized mods (modified versions) of the MAX app for installation. Such mods allegedly allowed users to pin music tracks to their messenger profiles. To “get” the mods, users had to authenticate using their mobile phone number and then log in to their account. It is worth noting that the functionality for adding music to one’s profile is currently missing from the official MAX version, but it is available on a number of competing services. The fraudsters are counting on their potential victims, in pursuit of this attractive feature, to let their guard down and fall for the deceit.

A fraudulent website offers the “opportunity to add music tracks to a MAX profile”

Threat actors also used other deception scenarios. Some websites, for instance, offered users access to an electronic class record book to check their school grades:

Other sites supposedly allowed visitors to use the web version of the MAX messenger and prompted them to authenticate using their mobile phone number to go to their “profile”:

Some of these fraudulent online resources promised help finding out the name under which a potential victim is recorded in other user contact lists. To do this, visitors were asked to “verify their identity” by authenticating via MAX:

A number of sites promised free access to exclusive materials of bloggers and adult-industry content creators, including “leaked” media archives and trial subscriptions to specialized services. Here, fraudsters also requested users to authenticate via the MAX messenger and provide the confirmation code. They justified this requirement by citing, among other things, the need to “protect against bots and blocking”:

Furthermore, this campaign targeted not only the MAX audience but also other messengers’ users, including Telegram. For example, some of the identified sites mimicked a chat with an official messenger account and, supposedly on behalf of the platform, offered potential victims a gift—a Telegram Premium subscription:

To “obtain” it, users had to log in to their account by entering their mobile phone number and the one-time security code sent to it:

In a similar scenario, the attackers promised potential victims the opportunity to receive free virtual gifts from the Telegram ecosystem’s various collections, such as Toy Bear, Snoop Dogg, and others. For this, scammers asked users to “complete a verification” (for example, to prove they were not robots and to ensure each visitor would supposedly receive the gift only once) by entering a mobile phone number and a confirmation code. It is possible that these variants of fraudulent websites, much like those themed around gaming, were primarily targeting children and teenagers:

Cybercriminals also attempted to lure potential victims with the chance of getting Telegram stars (the messenger’s internal digital currency) by “subscribing” to various channels on the platform. In this case, users were again required to log in to their Telegram accounts and provide a verification code:

In Q3 2026, Doctor Web’s experts observed the continued evolution of fraudulent schemes aimed at stealing personal data and accounts across various services. One common scenario in the scammers’ arsenal remains notifying users about the alleged compromise of their accounts. Typically, threat actors immediately confront potential victims with the fact of a data “leak” and the need to take urgent measures to protect confidential information (for instance, by following the provided internet link, calling “support”, etc.). However, in a number of cases our internet analysts identified, the phishing sites employed the strategy of gradually escalating their scare tactics regarding the supposed security breach. Step by step, the user is made increasingly anxious so that eventually they let their guard down and perform the actions the attackers require. Among the websites implementing such scams were, for example, the latest fake utility provider websites.

A phishing site masquerading as the official web portal of a Russian electric grid company prompts the user to log in to their account

When the potential victim, believing they are on a legitimate website, enters their account login credentials, the fraudulent site simulates the authentication process via Госуслуги (Gosuslugi/Government Services) and “synchronization” with the databases of various government agencies:

The website creates the appearance of authentication via Gosuslugi and synchronization with “departmental databases”

However, the website subsequently reports that the user’s Gosuslugi account has been compromised. To make it look more convincing, it reports on a specific device supposedly having been used to log in to the Gosuslugi portal and specifies a remote geographic location from which the unauthorized connection “occurred”. The website also warns that if the user did not perform these actions, their account will be blocked. To “cancel the synchronization” of the unfamiliar device and keep their personal information from leaking, the potential victim is “required to contact the operator immediately”:

To “unlink” the third-party’s device from their Gosuslugi account and allegedly protect their personal data, including their passport information, СНИЛС (SNILS/Individual Insurance Account Number), and the ИНН (INN/Taxpayer Identification Number), the user is asked to contact the “operator”

After the user clicks the “request a call” button, the website stalls for time by displaying a countdown timer set for one or several minutes and a message stating that the request is being processed:

The website states that the request is being processed and that a “duty operator” will contact the user within the specified timeframe

Once the timer runs out, nothing happens that could clarify the situation. Instead, buttons appear on the fraudulent page—to repeat the “request” and to contact the “duty operator” directly:

The website offers the option to re-request a callback from a specialist or to call the “duty operator” directly

When the first button is pressed, the “request processing” timer reappears, and the process repeats. When the second button is pressed, “dedicated support line” phone numbers, which actually belong to the fraudsters, are displayed. The goal of this scheme is to make the potential victim—after being forced to wait—more panicked and more likely to call one of the provided numbers, driven by the fear that their personal data will be leaked and their access to Gosuslugi will be lost. Moreover, the cybercriminals are killing two birds with one stone by directly stealing the data required to log in to the user’s personal account for the utility provider’s website.

So that the “problem” can be resolved more quickly, the potential victim is offered “dedicated support line” phone numbers

Over the last three months, Doctor Web’s internet analysts continued to identify new fraudulent sites promising various payments and benefits. Cybercriminals passed off some of them as the official site of the Russian state platform Работа в России (Rabota v Rossii/Work in Russia), located at trudvsem.ru; it hosts job listings and resumes and also assists with employment. The fake websites claimed that citizens who had previously registered on the official portal could supposedly receive an additional payment from the Employment Center. At the same time, the amount of the promised payment could, in some cases, be as high as tens of thousands of rubles.

To “receive” the money, users were asked to apply for a separate Mir payment system bank card, to which the “allowance” would supposedly be deposited. They were also required to activate it by making any purchase. To apply for the card, the fraudulent sites provided a form for entering personal data, such as full name, phone number, and email address:

A fake site of the Rabota v Rossii platform promises an “additional payment from the Employment Center”—on the condition that a new bank card would be issued

After filling out the form and clicking the “Apply for a Mir card” button, visitors were redirected to a legitimate website of one of the banks, where they were indeed given the opportunity to order a new card. However, such applications were, in fact, in no way connected to receiving the benefit promised by the scammers. Malicious actors deceived potential victims into obtaining bank cards so that they could receive a commission for each successful customer acquisition under a partnership program with credit institutions. In the end, the users did not receive any payments from the Employment Center. Moreover, cybercriminals could subsequently use the personal data collected via fake Rabota v Rossii websites in other fraudulent schemes or sell it on the black market.

Confidential data for accessing online banking accounts, including logins, passwords, and bank card details, remains a prime target for cybercriminals. In Q3, our specialists identified new phishing websites created to steal such information. Some of them mimicked the website of a Russian credit organization and promised gifts as part of a “large-scale campaign marking the company’s anniversary”. Users could supposedly receive a guaranteed bonus, ranging from 5,000 rubles to a doubling of all funds in their account:

A fake bank website promises gifts to mark the financial institution’s anniversary

The potential victim was asked to complete a short survey. After answering the questions, a “guaranteed prize” would supposedly become available to them:

The phishing website thanks the user for their answers and informs them that their account “is ready to participate in the promotion”. To “reveal the guaranteed prize”, the potential victim is prompted to click the “Get reward” button (the above screenshot shows that the scammers made a typo)

When the user clicked the button for “receiving” the reward, the website displayed a form for entering their first and last names, mobile phone number, and bank card number:

The site informs the user that they allegedly gained a doubling of their account balance as a gift and that they must enter certain personal data to “receive” the money

After the data was entered, the website requested an SMS verification code—supposedly required “to credit the funds to the account”. In reality, this was a login confirmation code for the victim’s online bank, which the fraudsters were accessing using the details obtained in the previous step. If the victim entered the code, the malicious actors gained access to their bank accounts and card details, enabling them to steal money.

The user is asked to provide a verification code from an SMS “to have the funds credited to the account”

Fake online dating and communication platforms remain a relevant threat. With their help, fraudsters seek to obtain users’ personal data and money. During Q3, Doctor Web’s internet analysts identified many such sites. In one common scheme, fraudsters trick potential victims into paying for a premium subscription that supposedly activates their account and grants access to the service’s full functionality, including the ability to send messages. However, the required payment is not a one-time fee: a mandatory condition for accessing chats is agreeing to the service’s auto-renewal. By seeking consent for recurring payments, the threat actors count on their victims forgetting about the active subscription or being unable to cancel it for one reason or another.

As part of one fraudulent scheme, potential victims may, via a chain of web redirects (for example, while visiting other sites), end up on intermediate websites advertising particular online dating service. Visitors are asked to take a survey to determine their “compatibility” with potential partners, after which a registration form is provided. The required fields include username, password, and email address. Users who enter their data are then redirected straight to the online dating “platform” website.

A website that is part of the fraudulent chain “checks” a potential victim’s compatibility with other users

Almost immediately, users begin receiving messages from “interested” participants, but such messages are actually programmed and do not originate from real people. Furthermore, responding to these messages is not possible. To “continue the conversation”, the user is prompted to activate an account by paying for premium access and agreeing to subscription auto-renewal every 30 days:

When requesting payment for a “premium subscription”, such websites may display an insecure form for entering bank card details, including the card number, expiration date, and even the three-digit security code. Since this form is not linked to secure payment gateways, users are at risk of not only signing up for an expensive service but also losing all the funds on their card by handing over their information to an unknown party.

The bank card details are requested via an insecure input form

If users attempt to cancel the subscription or get a refund, the sites ask for their bank card details again (for instance, its expiration date and part of its number). This also takes place outside the secure payment gateway environment, creating the additional risk of sensitive data being leaked and confidential data being stolen.

When the user asks to cancel their paid subscription, the website requests the first 6 and last 4 digits of the bank card number as well as its expiration date

Malicious and unwanted programs for mobile devices

According to detection statistics collected by Dr.Web Security Space for mobile devices, in Q3 2026, Android.Proxy trojans, used to redirect cybercriminals’ network traffic through victims’ devices, became the most active malicious programs. Users most frequently encountered variants like Android.Proxy.60.origin and Android.Proxy.61.origin, which, in total, accounted for nearly a quarter of all malware detections. The number of Android.Banker banking trojan attacks increased, compared to Q2. At the same time, the activity of Android.MobiDash and Android.HiddenAds adware trojan apps continued its downward trend.

Program.FakeAntiVirus, bogus anti-viruses, was once again the most widespread unwanted software. They offer to sell users the full anti-virus version to cure threats that have allegedly been detected. Among adware programs, the most frequently encountered were apps with built-in Adware.AdPush and Adware.Airpush modules, which display advertising notifications, and Adware.Opensite.15 programs. The latter are distributed under the guise of game cheat software, but their sole function is to load websites containing ads.

Apps supplied with junk code by means of NP Manager hacking tools for modding remained the most common potentially dangerous software (these apps are detected as Tool.Obfuscator.TrashCode). Malware authors continue utilizing this type of modification to protect malicious programs—banking trojans in particular—from being detected by anti-viruses. Other mods created with the help of NP Manager and detected by Dr.Web as Tool.NPMod also remain widespread. For example, code obfuscation can be used in such mods—also to protect against detection and analysis. Among the most frequently encountered riskware programs in Q3 were those modified using the Tool.LuckyPatcher utility. This tool downloads scripts from the internet that could potentially be malicious.

During the last three months, Doctor Web’s malware analysts detected over 50 malicious programs on Google Play. Among them were dozens of Android.Joker trojans that subscribed victims to paid services. Our specialists discovered that some new versions of malicious apps in this family have been updated with new functionality, enabling them to use infected devices as proxy botnet exit nodes to redirect the attackers’ internet traffic. Also distributed via Google Play were more Android.FakeApp trojans, which cybercriminals use in various fraudulent schemes.

The most noteworthy Q3 2026 events involving mobile malware

  • High activity was observed on the part of Android.Proxy trojan apps, which allow threat actors to redirect network traffic through infected devices.
  • The number of Android.Banker banking trojan attacks increased.
  • The activity of Android.MobiDash and Android.HiddenAds ad-displaying trojans continued to decline.
  • Malware creators added functionality to Android.Joker trojans that allows infected devices to be turned into exit nodes for a proxy botnet.
  • Malicious programs were once again distributed via Google Play.

To find out more about the security-threat landscape for mobile devices in Q3 2026, read our special overview.

Latest All news