My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets


Doctor Web’s July 2020 overview of malware detected on mobile devices

August 10, 2020

In July, the number of threats detected on Android devices decreased by 6.7% compared to June. The number of active malware lowered by 6.75%, unwanted applications by 4.6%, riskware by 8.42% and adware by 9.83%.

Throughout the month, Doctor Web malware analysts uncovered yet more malicious apps on Google Play. The Android.Banker.3259 banking trojan, disguised as an SMS manager, was one of them. New modifications of the Android.HiddenAds adware trojan family, capable of displaying advertisement banners, were among other threats. Furthermore, a new member of the dangerous Android.Joker trojan family, designed to subscribe users to premium services and execute arbitrary code, has also been spotted.


  • The number of threats detected on Android mobile devices has decreased
  • The discovery of new threats on Google Play

According to statistics collected by Dr.Web for Android

According to statistics collected by Dr.Web for Android #drweb

A trojan designed to display obnoxious ads and distributed as popular applications. In some cases, it can be installed in the system directory by other malware.
A trojan that automatically loads websites and clicks on links and advertisement banners. It can be spread as a harmless app so that users will not consider it as a threat.
Malicious applications that download and execute arbitrary code. Depending on their modification, they can load various websites, open web links, click on advertisement banners, subscribe users to premium services and perform other actions.
A trojan that downloads other malware and unwanted software. It can be hidden inside seemingly harmless apps found on Google Play or malicious websites.

According to statistics collected by Dr.Web for Android #drweb

Software that monitors Android user activity and may serve as a tool for cyber espionage. These apps can track device locations, collect information from SMS and social media messages, copy documents, photo and video, spy on phone calls, etc.
Detection name for adware programs that imitate anti-virus software. These apps inform users of non-existing threats, mislead them and demand they purchase the full version of the software.
Detection name for programs designed to assign credit ratings to users based on their personal data. These applications upload SMS, contact information from phonebooks, call history and other information to the remote server.

According to statistics collected by Dr.Web for Android #drweb

Riskware platforms that allow applications to launch APK files without installation. They create a virtual runtime environment that does not affect the main operating system.
A packer tool designed to protect Android applications from their unauthorised modification and reverse engineering. This tool is not malicious by itself, but it can be used to protect both harmless and malicious software.

According to statistics collected by Dr.Web for Android #drweb

Program modules incorporated into Android applications and designed to display obnoxious ads on Android devices. Depending on their family and modifications, they can display full screen ads and block other apps’ windows, show various notifications, create shortcuts and load websites.


Threats on Google Play

Among the threats found on Google Play in July were the new modifications of the Android.HiddenAds malware family, dubbed Android.HiddenAds.2190 and Android.HiddenAds.2193. Their authors spread them as an image editing software.

According to statistics collected by Dr.Web for Android #drweb According to statistics collected by Dr.Web for Android #drweb

Upon their launch, they hid their icons from the apps list on the main screen, similar to other trojans of this family. They do so to make it more difficult for the users to delete them. After that, they start to display obnoxious advertisement overlays on top of other apps and the operating system UI.

Another trojan discovered by Doctor Web malware analysts was dubbed Android.Joker.279. It hid under the guise of an application designed to work with SMS. Upon its launch, it subscribed victims for premium services and was able to run arbitrary code.

Moreover, our specialists uncovered a new banking trojan dubbed Android.Banker.3259. Malware writers based this banker on an open source SMS messenger.

According to statistics collected by Dr.Web for Android #drweb

Upon its launch, the trojan connects to the remote server and waits for further commands. Based on the received response, it either continues to operate as a harmless application or tries to steal personal data from the user by displaying a phishing window. In addition, Android.Banker.3259 saves all the incoming and outgoing SMS to the Firebase cloud database. Cybercriminals can then use the information, obtained from these messages, in future attacks.

According to statistics collected by Dr.Web for Android #drweb According to statistics collected by Dr.Web for Android #drweb

To protect your Android device from malware and unwanted programs, we recommend installing Dr.Web for Android.

Dr.Web Mobile Security

Your Android needs protection.

Use Dr.Web

  • The first Russian anti-virus for Android
  • Over 140 million downloads—just from Google Play
  • Available free of charge for users of Dr.Web home products

Free download