Doctor Web's Q3 2025 review of virus activity on mobile devices revealed that Android.MobiDash ad-displaying trojans were the most prevalent mobile threats, with their detection rate increasing by 18.19% compared to the previous quarter. Android.HiddenAds, which had been the leading threat, saw a significant decline in activity, dropping by 71.85%, but remained the second most common mobile malware. These adware trojans are known for concealing their icons to evade detection and removal, while displaying intrusive ads, including full-screen videos. Android.FakeApp trojans, often used in fraudulent schemes and to load malicious or gambling websites, maintained their position as the third most detected threat, though their activity decreased by 7.49%. Banking trojans such as Android.Banker, despite a 38.88% decline in activity, continued to be the most widespread banking malware, employing tactics like phishing overlays, SMS interception, and mimicking legitimate banking apps to steal credentials and funds. Android.BankBot trojans, which can intercept confirmation codes and execute remote commands, saw an 18.91% increase in detections. Android.SpyMax, based on SpyNote spyware, was also among the top banking trojans, though its activity dropped by 17.25%.
Doctor Web's broader Q3 2025 virus activity review indicated a 4.23% decrease in total threats detected, but a 2.17% increase in unique threats, highlighting the evolving threat landscape. The most common threats included adware, ad-displaying trojans, and malicious scripts, with email traffic dominated by scripts, backdoors, and various trojans such as downloaders and password stealers. Ransomware activity was notable, with Trojan.Encoder.35534, Trojan.Encoder.35209, and Trojan.Encoder.35067 being the most frequently encountered. In July, Doctor Web reported on the Trojan.Scavenger family, which targets cryptocurrency and password theft by masquerading as game mods and exploiting DLL Search Order Hijacking vulnerabilities. August saw the emergence of Android.Backdoor.916.origin, a multifunctional backdoor targeting Russian business representatives, capable of remote control and data theft. That same month, a targeted attack on a Russian engineering enterprise by the Scaly Wolf group was uncovered, utilizing the Updatar modular backdoor to exfiltrate confidential data. The quarter also saw an increase in fake Telegram websites and fraudulent finance-themed online resources, as well as the appearance of dozens of malicious and unwanted apps on Google Play. These findings underscore the persistent and diverse nature of cyber threats facing both mobile and desktop users, with attackers employing increasingly sophisticated methods to evade detection and compromise victims.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-15, Dr.Web published its annual review of virus activity on mobile devices in 2025. This is a new reporting milestone distinct from the earlier Q3 2025 mobile threat report.
On October 1, 2025, Dr.Web published its Q3 2025 review of mobile malware activity, reporting Android.MobiDash as the most prevalent Android threat with detections up 18.19% quarter over quarter. The report also noted major shifts among HiddenAds, FakeApp, Banker, BankBot, and SpyMax detections.
Across Q3 2025, Dr.Web reported that many malicious apps were distributed through Google Play, collectively reaching more than 1,459,000 installations. The apps included dozens of Android.Joker subscription trojans, Android.FakeApp samples, and the fake-earnings app Zeus Jackpot Mania detected as Program.FakeMoney.16.
During Q3 2025, Dr.Web observed a social-engineering campaign distributing the Android.Backdoor.916.origin backdoor through messenger-sent APKs disguised as an antivirus app. The campaign was assessed as targeting representatives of Russian businesses.
3 references tracked. Mallory keeps watching after this page renders.
news.drweb.com
Open sourcenews.drweb.com
Open sourcenews.drweb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.