Kaspersky warns of a return of backdoors pre-installed in the firmware of new Android devices, including Keenadu and several variants of Triada. In total, Kaspersky solutions blocked 14,059,465 mobile attacks in 2025, an average of 1.17 million per month.
The data comes from Kaspersky Security Network (KSN), a global threat intelligence analysis network run anonymously by users. Kaspersky specifies that their statistical methodology has been updated since Q3 2025, which may make the figures incomparable with previous publications – with the exception of statistics on installation packages, which are still calculated using the original methodology. The progress figures presented in the publisher’s marketing communications may therefore differ from the data in the primary report.
The primary function of mobile banking Trojans is to steal login credentials: identifiers for online banking services, electronic payment systems, and credit card details. While adware remains the most common threat in terms of volume – and accounts for 62% of all discoveries by 2025 – experiencing banking Trojans and spyware the most significant growth. For IT managers managing mobile device fleets in enterprise environments, the convergence of the increasing number of variants and the expansion of distribution vectors represents a measurable deterioration in the attack surface.
Mamont dominates the rankings, Coper makes strong progress
The Mamont and Creduz families account for the majority of the volume: Mamont represents 49.8 % of the newly detected banking trojan packages and Creduz 22.5 %. In the ranking of banking attacks, Mamont variants occupy six of the top ten positions, with dramatic increases compared to 2024 for the .da (+14.79 percentage points) and .db (+13.29 points). Coper.c also saw significant growth, from 7.19 % to 9.65 % of attacked users, and is listed in regional data as the dominant strain in Turkey – distributed via the Hqwar dropper.
The increase to 255,090 unique detected banking installation packages confirms a variant-based distribution strategy. Producing a large volume of distinct APK files allows cybercriminals to overload signature-based detection engines and extend the exposure window before neutralization. Anton Kivva, Head of the Malware Analysis Team at Kaspersky, draws a direct economic conclusion: “Given the increase in the number of unique malicious packages, we can conclude that these attacks generate significant profits for cybercriminals.”
Regional data confirms that strains adapt to local contexts. In India, Rewardsteal variants dominate, with over 90 % geographical concentrations, targeting payment data under the guise of fake rewards programs. In Germany, a proxy Trojan was hidden in an app that mimicked a discount service from a national supermarket chain. In Brazil, Pylcasa attackers redirect to phishing or illegal gambling sites.
Keenadu and Triada: backdoors in firmware
The most difficult threat to neutralize, as documented by Kaspersky 2025, is not distributed via application vectors but is integrated into the firmware of Android devices before they are released. The Triada family and the Keenadu backdoor, discovered in Q4 2025, are its most active representatives. Triada appears three times in the top 20 mobile malware by number of users attacked, including a variant (.fe) that increased from 0.04 % to 9.84 % between 2024 and 2025 – the largest increase in the ranking.
Keenadu has a particularly aggressive architecture. The malicious code is injected into `libandroid_runtime.so`, the core library of the Android Java runtime environment, allowing it to access the address space of any application running on the device. Its malicious modules are dynamically downloaded and can be updated remotely, giving it the ability to evolve after infection regardless of user interaction. Observed actions include manipulating ad impressions, displaying banners for other applications, and hijacking search queries – but its actual functional scope is theoretically unlimited.
The measures are structurally limited. A factory reset of devices is insufficient to eradicate a backdoor pre-installed in the firmware. The only documented method involves checking for an available firmware update from the manufacturer, followed by a full analysis of the new firmware to ensure that it is not itself compromised—a procedure that requires a device lifecycle management policy that few organizations have for their personal devices in a BYOD context.
For IT teams, the convergence of two distinct vectors – download-distributed Trojans and pre-installed backdoors – defense strategies. Traditional MDM policies, which focus on controlling application installations and managing operating system updates, are effective against the first vector but ineffective against the second. In this context, traceability in the hardware supply chain becomes an important part of the endpoint security policy.
The increasing volume of unique APKs associated with banking Trojans also indicates that detection solutions that rely solely on static signatures will become increasingly less effective. For CISOs, the ability of mobile EDR solutions to detect abnormal execution behavior – accessing payment data, intercepting OTP codes, communicating with command and control servers – regardless of the variant signature is becoming the most important differentiator when evaluating their mobile security tools.








