Kaspersky Q2 2026 mobile threat telemetry shows a continued decline in overall mobile attacks to 1.99 million, but banking Trojans remain the dominant threat category at 30.77% of detected applications. Multiple malicious loaders were found on Google Play, including a trojanized PDF reader dropping Anatsa and the Cleanova app using SDK-based installation source telemetry to selectively deliver payloads only to targeted victims. The Creduz banking Trojan family saw a surge in detected packages without corresponding victim telemetry, indicating active development cycles by the threat actors.
Banking Trojan
10 posts
IT threat evolution in Q2 2026. Mobile statistics Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware PhantomEnigma is an active Brazil-focused crimeware campaign that compromises government infrastructure (.gov.br portals and police mailboxes) to deliver a modular Node.js backdoor embedded in patched Boostnote/Electron applications via Delphi-compiled Inno Setup installers. The operation uses at least two beacon generations (GET /laravel.php and POST /nbw/), rotates C2 domains weekly behind Cloudflare, and leverages trusted government email channels to bypass SPF/DKIM/DMARC checks. ANY.RUN analysts linked 231 sandbox analyses through a recurring build-chain fingerprint and connected a separate Ofício-PC QR-code phishing arm to the same operator via shared compromised government hosts.
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula FortiGuard Labs identified an ongoing Ousaban banking Trojan campaign targeting users in Spain and Portugal, delivered via phishing PDFs that redirect victims to geofenced malicious webpages. The attack chain involves a VBS script extracting a ZIP payload from a steganographic image, with the final Ousaban EXE establishing persistence via registry Run keys and communicating with C2 servers resolved through daily-changing DDNS hostnames. The malware targets over 25 Spanish and Portuguese financial institutions and employs a custom encryption algorithm shared with the Casbaneiro family to evade detection.
AI Generated ClickFix Attack Delivers SmartRAT | ThreatLabz ThreatLabz identified a ClickFix campaign utilizing AI-generated typosquatting domains to impersonate Brazilian banks and deliver a PowerShell-based banking RAT dubbed SmartRAT. The malware establishes persistence via scheduled tasks or Windows services, communicates over a custom TCP protocol on port 51888, and features advanced capabilities including keylogging, fake banking overlays, and QR code interception for financial fraud.
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Trend Micro MDR analyzed Banana RAT, a sophisticated banking trojan operated by SHADOW-WATER-063 targeting Brazilian financial institutions. The malware utilizes a server-side polymorphic build pipeline to deliver unique, AES-encrypted PowerShell payloads that execute filelessly in memory. Once active, it enables operator-driven fraud through remote input control, keylogging, deceptive banking overlays, and a specialized Pix QR code interception subsystem.
IT threat evolution in Q1 2026. Mobile statistics In Q1 2026, mobile banking Trojans saw a significant surge, with Mamont variants driving a 50% increase in malicious installation packages. Additionally, a sophisticated new variant of the SparkCat crypto stealer was identified in official app stores, employing custom virtual machines and OCR techniques to compromise both Android and iOS users.
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook Elastic Security Labs identified TCLBANKER, a new Brazilian banking trojan distributed via DLL sideloading that features robust anti-analysis mechanisms and environment-gated payload decryption. The malware deploys a full-featured banking trojan with a WPF-based social engineering overlay framework, alongside worm modules that self-propagate by hijacking WhatsApp Web sessions and Microsoft Outlook accounts.
Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time A new phishing campaign targets Brazilian users with fake judicial summons to deliver agenteV2, a Nuitka-compiled interactive banking trojan. The malware establishes a persistent WebSocket backdoor for live screen streaming and remote shell access, enabling attackers to conduct real-time, operator-assisted financial fraud.
New NGate variant hides in a trojanized NFC payment app ESET researchers identified a new variant of the NGate Android malware that trojanizes the legitimate HandyPay application to facilitate NFC relay attacks and steal payment card PINs. Targeting users in Brazil through social engineering and fake app stores, the malware allows attackers to conduct unauthorized ATM cash-outs while requiring no suspicious device permissions.
Latin America and the Caribbean Cybercrime Landscape In 2025, the Latin America and the Caribbean (LAC) region faced escalating cybercriminal activity driven by rapid digital adoption and economic instability. Threat actors heavily utilized Telegram and dark web forums to distribute ransomware, banking trojans, and infostealers, increasingly targeting the healthcare, manufacturing, and government sectors while adapting to law enforcement disruptions.