Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution.
Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1.
Yet the apparent decline obscures a significant tactical change: banking payloads are being wrapped in loader applications and subsequently detected as Trojan-Droppers rather than conventional Trojan-Bankers.
The change has materially altered threat-category rankings. Trojan-Banker detections remained the most prevalent mobile-malware category, accounting for 30.77% of detected applications, while Trojan-Dropper activity increased sharply.
Although the number of new banking-Trojan packages fell compared with Q1, financial malware remains dominant because operators are modifying their delivery chain, testing new builds, and cycling variants faster.
The dropper model separates an apparently harmless application from its final malicious payload.
This gives operators greater flexibility: a trojanized utility can pass initial review with limited or dormant malicious functionality, then retrieve or activate a banking Trojan only after installation.
One example involved a PDF reader hosted on Google Play that presented victims with a fake update prompt before installing the Anatsa banking malware.

The technique turns a routine software-update interaction into the payload-delivery stage, reducing the visibility of the actual banking component during application vetting.
Kaspersky said in a report shared with GBhackers, identified 304,128 Android malware samples during the quarter, including 93,574 mobile banking Trojan packages and 570 mobile ransomware packages.
Another loader, detected in the Cleanova application and related apps, demonstrates a more selective approach.
The malware transmitted data collected through installation-source analytics SDKs to a command-and-control server.
Android Banking Droppers
The server returned a malicious payload only when telemetry indicated that the install originated from a source selected by the operators.
If the app was installed through an unwanted source, including environments likely associated with researchers or automated scanners, its malicious behavior could remain inactive.
This source-aware filtering offers a practical method for bypassing app-store review while preserving campaign targeting.
The classification shift is particularly visible in the detection rankings. Trojan-Dropper.AndroidOS.Banker.dd rose from 0.01% of attacked Kaspersky mobile users in Q1 to 2.16% in Q2.
Meanwhile, Mamont banking variants continued to gain ground: Trojan-Banker.AndroidOS.Mamont.hl reached 2.48% of attacked users in the overall malware ranking, while newer Mamont builds displaced older variants across the mobile-banker leaderboard.
The continued emergence of Mamont variants indicates active development, not merely recycled infrastructure.
Creduz also became disproportionately represented among newly identified banking samples, despite generating comparatively low victim telemetry.
That mismatch suggests its operators may be producing substantial volumes of builds to test features, delivery methods, or detection bypasses ahead of wider deployment.
Earlier Kaspersky reporting likewise identified Mamont and Creduz as leading Android banking-malware families, underscoring their sustained role in the ecosystem.
For defenders, the central lesson is that a reduction in direct banker detections should not be read as reduced financial-malware risk.
Droppers conceal intent until late in the execution chain and enable rapid payload replacement without rebuilding the initial lure.
Android users should treat unexpected in-app update requests, especially from document readers and utilities, as high-risk; keep Play Protect enabled; avoid sideloading; and scrutinize permissions such as Accessibility and SMS access.
Security teams should correlate app provenance, installation referrer data, outbound C2 traffic, and delayed payload retrieval rather than relying solely on static APK classification.
Why use the 2026 Agentic SOC Buyer’s Guide? 8 Best Platforms Compared – Download the 2026 Buyer’s Guide

