According to detection statistics collected by Dr.Web Security Space for mobile devices, ad-displaying Android.HiddenAds trojans remained the most common Android malware. Moreover, they were detected on protected devices more than twice as often as in the fourth quarter of last year. Second place once again went to Android.FakeApp malware, which cybercriminals use in various fraudulent schemes—their activity increased by almost 8%. Adware trojans from the Android.MobiDash family ranked third; the number of their detections almost quintupled.
Similar dynamics were observed among many banking trojans. For instance, an increase was recorded in the number of attacks involving
Android.BankBot and Android.Banker trojan family members—by 20.68% and 151.71%, respectively. At the same time, Android.SpyMax
trojans, whose activity grew throughout almost all of 2024, were detected 41.94% less frequently than in the previous quarter.
Over the past 3 months, Doctor Web’s specialists discovered dozens of new threats on Google Play. Our virus laboratory’s findings in
this catalog included cryptocurrency-stealing malware and other trojans that display intrusive ads, along with the traditionally large
number of Android.FakeApp trojans.
PRINCIPAL TRENDS OF Q1 2025
- Increased activity on the part of adware trojans
- Increased numbers of Android.BankBot and Android.Banker banker malware attacks
- Decreased activity on the part of Android.SpyMax spyware trojans
- The emergence of many new threats on Google Play
Threats on Google Play
In Q1 2025, Doctor Web’s virus laboratory detected several dozen malicious programs. Among them were various modifications of the trojans
Android.HiddenAds.4213 and Android.HiddenAds.4215, which conceal their presence on infected devices and
start displaying ads on top of other apps’ windows and the operating system UI. They masqueraded as software for taking photos and videos
with different effects, image-editing programs, an image collection app, and a women’s health diary.
The Android.HiddenAds adware trojans concealed in the apps “Time Shift Cam” and “Fusion Collage Editor”
Our specialists also discovered Android.CoinSteal.202, Android.CoinSteal.203, and
Android.CoinSteal.206, malicious programs designed to steal cryptocurrency that are distributed under the guise
of official software from the Raydium and Aerodrome Finance blockchain platforms and the Dydx cryptocurrency exchange.
The “Raydium” and “Dydx Exchange” programs are trojans that steal cryptocurrency
When launched, these malicious apps ask potential victims to enter a mnemonic phrase (the seed phrase)—supposedly to connect their crypto wallet.
But, in reality, the data that users provide is sent to threat actors. To further mislead users, forms for entering mnemonic phrases can be disguised
as requests from other crypto platforms. As shown in the example below, Android.CoinSteal.206
displayed a phishing form allegedly on behalf of the crypto exchange PancakeSwap.
At the same time, Android.FakeApp fake programs were once again being distributed via Google Play.
Fraudsters passed off many of them as finance-related software, including teaching aids, instruments for accessing
investing services, and personal finance software. They loaded various phishing websites, including those used by threat actors to collect personal information.
Examples of the Android.FakeApp trojan apps distributed under the guise of financial software: «Умные Деньги» (“Smart Money”) is Android.FakeApp.1803,
and “Economic Union” is Android.FakeApp.1777
Under certain conditions, other Android.FakeApp trojans loaded bookmaker and online casino sites. Such malware variants were distributed as different games and other software,
like a speed-typing trainer and a drawing tutorial. Among them were new modifications of the
Android.FakeApp.1669 trojan.
Examples of malicious fake apps that, instead of providing the declared functionality, could load online casino and bookmaker websites
To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web anti-virus products for Android.