Defend what you create

Other Resources

Close

Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Back to news

Mobile threats in December 2013

January 13, 2014

Russian anti-virus company Doctor Web would like to draw your attention to its review of mobile threats for the last month of the year just ended. The review is based on statistics collected with the aid of users who have installed and run the new, ninth version of Dr.Web for Android on their mobile devices. A total of 4,637,717 malicious or unauthorized applications were discovered on handhelds in the period from December 4-25, 2013, i.e., from the moment the new version of Dr.Web for Android was released.

Adware.Revmob.origin.1 (525,500 times), Adware.Airpush.origin.7 (476,304 times) and Adware.Airpush.origin.21 (387,881 times) were the programs most frequently detected. Android.SmsSend.origin.749 became the most "popular" malicious program (249,405 incidents). The top 20 undesirable and malicious applications found in December on mobile devices are listed in the table below.

NameQuantity
1Adware.Revmob.origin.1525 500
2Adware.Airpush.origin.7476 304
3Adware.Airpush.origin.21387 881
4Android.SmsSend.origin.749249 405
5Adware.Leadbolt.origin.7240 274
6Android.SmsSend.origin.872234 596
7Android.SmsSend.origin.990126 982
8Adware.Revmob.origin.3125 555
9Android.SmsSend.origin.315101 150
10Adware.Startapp.origin.895 639
11Adware.Revmob.origin.291 756
12Android.Subser.origin.178 124
13Adware.Startapp.origin.567 906
14Android.SmsSend.origin.98766 512
15Adware.Leadbolt.origin.564 833
16Adware.Airpush.origin.362 143
17Adware.Callflakes.origin.155 225
18Android.SmsSend.origin.30953 138
19Android.SmsSend.origin.75852 815
20Android.SmsSend.origin.90852 372

The statistics lead to the conclusion that various Android.SmsSend Trojan modifications remain the most common threats to Android. Also, Dr.Web anti-virus software for Android effectively neutralises various applications that display annoying ads on the screens of smart phones and tablets.

Whenever a malicious or unwanted program was detected, users most often removed it—this happened in 65.5% of incidents. In 27% of cases, the application was not yet installed but stored on the memory card or in the internal memory as an apk file that was removed by the anti-virus. A minor portion of users (4%) moved detected threats to the quarantine. Only 1.8% of users ignored danger warnings from the anti-virus and continued using the infected device, and another 1.4% immediately cancelled the installation of malicious applications on their mobile phones and tablets upon receiving an alert from the anti-virus program.

Samsung Galaxy S III became the most popular device among users of Dr.Web for Android in December—it accounted for 10.72% of the devices on which Dr.Web anti-virus software was installed. Samsung Galaxy S II ranks second with 5.19% of installations, Samsung Galaxy S IV ranks third with 4.70%, and Samsung Galaxy Note II ranks fourth—4.53% of Dr.Web for Android installations occurred on this device. Our users’ preferences regarding Android-device manufacturer are shown in the chart below.

Dr.Web user preferences by device manufacturer screenshot

Information about the most common versions of Android on devices protected with Dr.Web can be found on the diagram below.

The most common versions of Android on devices protected with Dr.Web screenshot

In addition to the threats that pose a danger to Android, Dr.Web for Android often detected and neutralised some malicious programs for Windows—those that penetrated devices while they were connected to a desktop or a laptop and used them as portable storage devices to spread further. Thus, 12,755 copies of the worm Win32.HLLW.Olala were identified and removed from mobile devices in December 2013. The mobile Dr.Web virus database contains multiple entries for malware that can replicate itself to removable media. In addition, Dr.Web promptly detected and removed numerous cross-platform Trojans of the Java.SMSSend family which can work on any mobile device that supports Java.

Doctor Web's analysts will continue to monitor the statistics and inform users about the latest threats and the overall security situation.

Learn more with Dr.Web

Virus statistics Virus descriptions Virus monthly reviews Laboratory-live

Tell us what you think

You will be awarded one Dr.Webling per comment. To ask Doctor Web’s site administration about a news item, enter @admin at the beginning of your comment. If your question is for the author of one of the comments, put @ before their names.


Other comments

The Russian developer of Dr.Web anti-viruses

Doctor Web has been developing anti-virus software since 1992

Dr.Web is trusted by users around the world in 200+ countries

The company has delivered an anti-virus as a service since 2007

24/7 tech support

© Doctor Web
2003 — 2019

Doctor Web is the Russian developer of Dr.Web anti-virus software. Dr.Web anti-virus software has been developed since 1992.

2-12А, 3rd street Yamskogo polya, Moscow, Russia, 125040