My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets


May 2015 Android malware review from Doctor Web

May 29, 2015


  • Distribution of numerous banking Trojans
  • Emergence of new locker ransomware for Android
  • Emergence of new SMS Trojans

Number of entries for malicious and unwanted software targeting Android OS in Dr.Web virus database

April 2015May 2015Dynamics

Mobile threat of the month

May was marked by high activity of banking Trojans targeting users of Android devices and distributed by cybercriminals in a number of countries. For this purpose, virus makers extensively used unsolicited SMS messages containing a link to download one or another Trojan. For example, in Russia, cybercriminals used already known topics for their MMS messages. Among banking Trojans, spread by means of short messages, a number of Android malware belonging to the Android.SmsBot family were detected (in particular, Android.SmsBot.269.origin and Android.SmsBot.291.origin).

screen screen

Again, a large number of attacks with the use of banking Trojans were registered is South Korea; that is, in May, Doctor Web security researchers detected more than 20 spam campaigns organized by cybercriminals. The following topics were used for the messages:


Malicious applications that performed the attacks


Moreover, during the previous month, new banking Trojans belonging to the Android.BankBot family came into view. Despite the fact that the virus makers responsible for the creation of these Trojans had been arrested in April, distribution of this malware continued by other cybercriminals.

The number of entries for banking Trojans of the Android.BankBot family in Dr.Web virus database:

April 2015May 2015Dynamics

Android ransomware

May also experienced the discovery of new ransomware species of the Android.Locker family. These programs lock Android devices and demand a ransom to unlock them. The number of entries for these dangerous malicious applications in Dr.Web virus database:

April 2015May 2015Dynamics

SMS Trojans

During the previous month, Doctor Web security researchers detected a large number of new SMS Trojans belonging to the Android.SmsSend family and designed to send messages to premium numbers and subscribe users to chargeable services.

The number of entries for SMS Trojans of the Android.SmsSend family in Dr.Web virus database:

April 2015May 2015Dynamics

Protect your Android handheld with Dr.Web now

Buy online Buy via Google Play Free of charge