

Last year’s stats on the number of attacks involving mobile banking Trojans were eye-catching. This trend will affect the statistical map of detected threats: we will see fewer unique mobile malware families, replaced by droppers of various kinds. There is no doubt that established groups that have not yet embraced droppers will soon either create their own or buy ready-made ones. Growth continued in Q2 and beyond, but much more smoothly. The biggest contribution was made by members of the family. Virus writers need this, for instance, when using their platform with a fake app store.Īlthough mobile droppers are nothing new, in Q1 2018 we saw a sharp rise in the number of users attacked by packed malware. Enables any number of unique files to be created.The dropper works particularly well against detection based on file hashes, since it generates a new hash each time, while the malware inside does not change a single byte. Droppers are used as a means to hide the original malicious code, which simultaneously: A dropper creator may have several clients involved in developing ransomware Trojans, banking Trojans, and apps showing persistent ads. The methods for assembling these Matryoshka-like programs were streamlined, allowing them to be easily created, used and sold by various groups. In the past three years, dropper Trojans have become the weapon of choice for cybercriminals specializing in mobile malware.

Alongside these campaigns, this report touches on all the major events in the world of mobile threats that occurred during the year. In 2018, we uncovered three mobile APT campaigns aimed primarily at spying on victims, including reading messages in social networks.

The analytical scope was expanded due to the growing popularity of various Kaspersky Lab products and their geographical reach, which made it possible to obtain statistically reliable data. Consequently, the comparative data for 2017 may differ from the data for the same period published in the previous report. The statistical data for this report came from all Kaspersky Lab mobile security solutions, not just Kaspersky Mobile Antivirus for Android.
