Doctor Web’s Q3 2026 review of virus activity on mobile devices
October 1, 2026
Compared to Q2, the number of attacks involving Android.Banker banking trojans slightly increased, and these malicious programs, with a share of 18.06%, ranked second. As before, the most active among them were members of the Android.Banker.Mamont sub-family. These can, among other things, intercept the content of SMS and notifications in order to steal one-time confirmation codes for banking transactions.
At the same time, users were less likely to encounter Android.MobiDash and Android.HiddenAds ad-displaying trojans. The number of their detections over the last three months decreased again—by 30.96% and 14.36%, respectively, and their combined share of the detected malware currently does not exceed 10%.
Programs containing junk code, added to them via NP Manager hacking utilities for modding apps, remain the top-ranked potentially dangerous software (riskware). Such modifications are made to scramble the logic of applications. Malware creators use this technique to protect malware from anti-viruses. For example, it is actively used to protect Android.Banker.Mamont banking trojans. In Q3, such modifications (detected as Tool.Obfuscator.TrashCode) accounted for 69.01% of all riskware detections.
Second place again went to programs modified using other NP Manager functional capabilities. For instance, threat actors can obfuscate the trojans’ code to protect them from being detected and analyzed. The share of such mods (detected as Tool.NPMod) accounted for 19.16% of the total number of potentially dangerous software detections. Rounding out the top three are programs modified using the Tool.LuckyPatcher utility. This tool downloads from the internet specially prepared scripts that can pose a potential threat, as anyone, including malware developers, can create them. Programs modified this way accounted for 5.77% of the riskware detections.
Program.FakeAntiVirus, apps which mimic the behavior of anti-viruses, remained the most common unwanted software in Q3. These apps notify users that they have detected certain threats and offer to sell them the full version to “cure” the alleged infection. Compared to the previous observation period, this software’s share of the total number of unwanted program detections increased from 44.10% to 51.09%.
The most widespread adware was Adware.AdPush modules embedded in Android programs. In Q3, they accounted for 39.46% of threat detections of this type. These modules display advertising notifications that mislead users. They also collect a range of confidential data.
Over the last three months, an increase in the activity of Adware.Airpush advertising modules was observed; their share rose from 7.39% to 10.34%. Adware.Airpush modules can display advertising notifications, banners, and pop-up windows, while cybercriminals also use them to distribute malware.
Users continued encountering Adware.Opensite.15 advertising apps. Their activity, however, dropped to 7.90% from Q2’s 14.26%. These programs are distributed under the guise of apps containing cheats for obtaining various in-game resources, but they only load websites with ads. One of the leading programs of previous months, Adware.Bastion.1.origin, also became less prominent, accounting for 5.73% of adware detections. Such apps create notifications containing misleading messages which inform users of alleged system errors and low memory. And during “optimization”, they display ads.
In Q3, Doctor Web’s anti-virus laboratory specialists discovered many new malicious programs on Google Play, including dozens of Android.Joker trojans which subscribe users to paid mobile services. When analyzing these trojans, our experts found that virus writers had expanded the family’s functionality. Some Android.Joker variants are now capable of not only signing up for subscriptions but also turning infected devices into exit nodes for a proxy botnet. More bogus apps from the Android.FakeApp family, used in various fraudulent schemes, were also distributed via Google Play.
PRINCIPAL TRENDS OF Q3 2026
- Users encountered high activity on the part of Android.Proxy malicious programs, which are used by threat actors to redirect network traffic through victims’ devices.
- An increase in Android.Banker banking trojan attacks was observed.
- The activity of ad-displaying trojans Android.MobiDash and Android.HiddenAds continued to decline.
- Dozens of malicious apps were detected on Google Play.
- Android.Joker trojan apps gained functionality that allows them to turn infected devices into a proxy botnet’s exit nodes.
According to statistics collected by Dr.Web Security Space for mobile devices
- Android.Proxy.60.origin
- Android.Proxy.61.origin
- Malicious apps that turn infected devices into exit nodes for proxy botnets and allow threat actors to redirect their network traffic through these devices.
- Android.SpyMax.17
- A malicious spyware program with extensive functionality. Cybercriminals use it, among other things, as a banking trojan to intercept SMS containing verification codes sent by financial institutions.
- Android.HiddenAds.4236
- A trojan app designed to display intrusive ads. Members of the Android.HiddenAds family are often distributed as popular and harmless applications. In some cases, other malware can install them in the system directory. When these infect Android devices, they typically conceal their presence from the user. For example, they “hide” their icons from the home screen menu.
- Android.Banker.Mamont.263.origin
- A banking trojan that intercepts SMS containing one-time codes from credit organizations, hijacks the contents of notifications, and collects other confidential information. This includes technical data about the infected device, the list of installed apps, and information about the SIM card, phone calls, and sent and received SMS.
- Program.FakeAntiVirus.1
- Program.FakeAntiVirus.5.origin
- Program.FakeAntiVirus.5
- The detection name for adware programs that imitate anti-virus software. Such apps can mislead users and report non-existent threats, or erroneously identify safe programs as malicious. In some cases, they may demand that users purchase the software’s full version to “cure” the supposedly detected threats.
- Program.FakeMoney.11
- The detection name for Android applications that allegedly allow users to earn money by completing different tasks. These apps make it look as if rewards are accruing for each one that is completed. At the same time, users are told that they have to accumulate a certain sum to withdraw their “earnings”. Typically, such apps have a list of popular payment systems and banks that supposedly could be used to withdraw the rewards. But even if users succeed in accumulating the needed amount, in reality they cannot get any real payments. This virus record is also used to detect other unwanted software based on the source code of such apps.
- Program.CloudInject.1
- The detection name for Android programs that have been modified using the CloudInject cloud service and the eponymous Android utility (the latter was added to the Dr.Web virus database as Tool.CloudInject). Such programs are modified on a remote server; meanwhile, the modders (users) who are interested in such modifications cannot control exactly what will be added to the apps. Moreover, these programs receive a number of dangerous system permissions. Once modification is complete, modders can remotely manage these apps—blocking them, displaying custom dialogs, tracking when other software is being installed or removed from a device, etc.
- Tool.Obfuscator.TrashCode.1
- Tool.Obfuscator.TrashCode.2
- The detection name for Android programs to which junk code has been added, using hacker tools for modifying Android apps. Such modifications are made to obfuscate the logic of apps. This technique is often found in banking trojans and pirated software.
- Tool.NPMod.3
- Tool.NPMod.1
- The detection name for Android programs that have been modified using the NP Manager utility. This tool contains modules for obfuscating and protecting the apps’ code as well as for bypassing their digital signature verification post modification. The obfuscation it adds is often used to make the malware more difficult to detect and analyze.
- Tool.LuckyPatcher.2.origin
- A tool that allows apps installed on Android devices to be modified (i.e., by creating patches for them) in order to change the logic of their work or to bypass certain restrictions. For instance, users can apply it to disable root-access verification in banking software or to obtain unlimited resources in games. To add patches, this utility downloads from the internet specially prepared scripts, which can be crafted and added to a common database by any third party. The functionality of such scripts can prove to be malicious; thus, patches made with this tool can pose a potential threat.
- Adware.AdPush.3.origin
- Adware.Adpush.21846
- Adware modules that can be built into Android apps. They display notifications containing ads that mislead users. For example, such notifications can look like messages from the operating system. In addition, these modules collect a variety of confidential data and are able to download other apps and initiate their installation.
- Adware.Opensite.15
- Apps passed off as cheat tools for obtaining resources in games. In fact, they are created to display ads. These programs receive a configuration from a remote server and use it to open a target website containing ads like banners, pop-up windows, video clips, etc.
- Adware.Airpush.7.origin
- Adware modules that can be built into Android apps and display various ads. Depending on the modules’ version and modification, these can be notifications containing ads, pop-up windows or banners. Malicious actors often use these modules to distribute malware by offering their potential victims diverse software for installation. Moreover, such modules collect personal information and send it to a remote server.
- Adware.Bastion.1.origin
- The detection name for optimization programs that periodically create notifications containing misleading messages. They inform users about alleged low memory and system errors in order to display ads during “optimization”.
Threats on Google Play
In Q3 2026, Doctor Web's anti-virus laboratory experts detected over 50 malicious programs on Google Play. Most of them belonged to the Android.Joker trojan family; such trojans secretly subscribe users to paid mobile services. To do this, they steal one-time confirmation codes by intercepting SMS and notification content. Malware creators distributed these trojans disguised as various programs, including messengers, device optimization utilities, camera apps, text recognition tools, and multimedia players for streaming movies, and TV series.
Examples of apps from Google Play that contained Android.Joker trojans: Special Camera — Android.Joker.2679, Color Messages — Android.Joker.2682
While examining new Android.Joker samples, our specialists found that functionality had been added to some of them, enabling infected devices to be turned into exit nodes for a proxy botnet. Threat actors can utilize this functionality to sell internet access services via the victims’ network.
The analysis revealed that one of the botnet’s C2 servers was not protected by authorization. This allowed Doctor Web’s malware analysts to retrieve from the control panel information about the botnet’s operational statistics and the programs embedded with the Android.Joker malicious modules. As of the end of August, over 187,000 devices had been infected with updated trojans from this family, while the number of active renters of the illegal proxy network had reached 93.
A web control panel for a proxy botnet based on devices infected with certain modifications of Android.Joker trojans
Other identified threats were new trojans from the Android.FakeApp family that can load various websites, including malicious and fraudulent ones. They were distributed under the guise of programs for financial management and family budget planning, note-taking apps, job search software, and various games. To mask their true nature, most of these trojans would indeed provide the declared functionality; however, under certain conditions, they loaded fraudulent sites instead.
Examples of the bogus Android.FakeApp programs our experts found on Google Play in Q3 2026
For instance, Android.FakeApp.2022 loaded a website containing a list of “current vacancies” with high salaries and attractive working conditions. At the same time, the design of the fraudulent site featured a logo styled and colored to resemble the official logo of the Russian Gosuslugi (Госуслуги) internet portal.
One of the vacancies allegedly available to the potential victim
Users were offered the chance to learn more about vacancies that interested them. To do this, they had to submit an application, after which they could supposedly “start earning today”. Malicious actors requested their confidential information, including their full name, age, citizenship and mobile phone number, and asked them to choose a convenient time to receive a call from a “specialist”.
The website loaded by the trojan collects personal data that fraudsters can later use to scam their victims
To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.