Threefold rise in mobile malware detections in 2016
2016 saw a near-threefold rise in mobile malware detections compared to 2015 – with a total of 8.5 million malicious installations identified. This means that, in the space of just one year, a volume equivalent to 50% of all the malware detected in the previous 11 years (15.77 million in 2004 – 2015) was released.
Leading the way were mobile advertising Trojans which now make up 16 of the top 20 malicious programs, up from 12 in 2015. These are the findings of Kaspersky Lab’s annual Mobile Virusology report, which also highlights the evolution of mobile banking Trojans.
Specialist officers from INTERPOL’s Global Complex for Innovation have contributed an analysis of mobile malware on the Dark Web to the report.
In 2016, Kaspersky Lab mobile security products reported:
- Nearly 40 million attacks attempts by mobile malware, with over 4 million users of Android-based devices protected (vs 2.6 million in 2015)
- Over 260,000 detections of installation packages for mobile ransomware Trojans (an increase of almost 8.5 times, year-on-year)
- More than 153,000 unique users targeted by mobile ransomware (an increase of 1.6 times compared with 2015)
- Over 128,000 mobile banking Trojans detected (nearly 1.6 times more than in 2015)
Advertising Trojan: is your device already rooted?
- The most widespread type of Trojan in 2016 was the advertising variety, accounting for 16 of the top 20 malware programs
These Trojans are capable of seizing rooting rights, allowing the malware to not only aggressively display ads on the infected device, often making it impossible to use, but also to secretly install other applications. These Trojans can also buy apps on Google Play.
In many cases, the Trojans were able to exploit previously patched vulnerabilities because the user had not installed the latest update.
Further, this malware simultaneously installs its modules in the system directory, which makes the treatment of the infected device very difficult. Some advertising Trojans are even able to infect the recovery image, making it impossible to solve the problem by restoring the device to factory settings.
Representatives of this class of malicious software have been repeatedly found in the official Google Play app store, for example, masquerading as a guide for Pokemon GO. In this case, the app was downloaded over 500,000 times, and is detected as a Trojan.AndroidOS.Ztorg.ad.
Mobile ransomware: further development
- In 2016, 153,258 unique users from 167 countries were attacked by Trojan-Ransom programs; this is 1.6 times more than in 2015.
Modern ransomware overlays windows with demand messages, thus making it impossible to use the device. This principle was used by the most popular mobile ransomware program in 2016 – Trojan-Ransom.AndroidOS.Fusob.
This Trojan mostly attacks users in Germany, the US and the UK, but avoids users from the CIS and some neighboring countries. Once launched, it runs a check of the device language and, after achieving some results, it may stop execution. The cybercriminals behind the Trojan usually demand between $100 and $200 to unblock a device. The ransom has to be paid using codes from pre-paid iTunes cards.
Mobile banking Trojan: a skyrocketing threat
- In 2016, over 305,000 users in 164 countries were attacked by mobile banking Trojans, compared with over 56,000 users in 137 countries the previous year.
- Russia, Australia and Ukraine are the top 3 countries affected in terms of the percentage of users attacked by mobile banking Trojans relative to all users hit by mobile malware.
Mobile banking Trojans continued to evolve through the year. Many of them gained tools to bypass the new Android security mechanisms and were able to continue stealing user information from the most recent versions of the OS. At the same time, the developers of mobile banking Trojans repeatedly enhanced their creations with new capabilities. For instance, the Marcher family, in addition to implementing the usual banking applications’ overlay, redirected users from financial institutions’ websites to phishing pages.
The Dark Web delusion
According to specialist officers from INTERPOL’s Global Complex for Innovation the Dark Web remains an attractive medium for conducting illicit businesses and activities.
Given its robust anonymity, low prices and client-oriented strategy, the Dark Web provides a means for criminal actors to communicate and engage in commercial transactions, buying and selling various products and services, including mobile malware kits. Mobile malware is offered for sale as software packages (e.g. remote access Trojans – RATs), individual solutions and sophisticated tools, like those developed by professional firms or, on a smaller scale, as part of a ‘Bot as a Service’ model. Mobile malware is also a ‘subject of interest’ on vendor shops, forums and social media.
Pingback: d8xc45m78oe35rm739
Pingback: asdfsdfxcvxxasa
Pingback: xwc34rwxrw34rwc34c
Pingback: cxqw234xracrwcr4
Pingback: uscojufm9r4tue4urtse4
Pingback: news
Pingback: click here
Pingback: https://www.manytube.net/
Pingback: eliminar contenido personalizado sims 4
Pingback: BEAUTY
Pingback: 메리트카지노
Pingback: proven customer reviews
Pingback: 메리트카지노 추천
Pingback: omega guldklocka
Pingback: podcast transcript
Pingback: sàn forex uy tín
Pingback: detectives privados albacete
Pingback: film izle
Pingback: soccer odds explanation
Pingback: Aaron Lal
Pingback: Aaron Lal
Pingback: my mega888 free credit
Pingback: Doll House 168
Pingback: 34cr4rxq3crq34rq3r4
Pingback: download mega888 new version ios
Pingback: Julian Di Benedetto
Pingback: c34r54wxw4r34c3
Pingback: twitter trump
Pingback: www.mega888 apk.com.my
Pingback: permainan slot
Pingback: tees
Pingback: best cbd for dogs
Pingback: اوامر الشبكه
Pingback: Free billing software
Pingback: cbd near me
Pingback: best cbd gummies
Pingback: Julian Di Benedetto
Pingback: ZTE 5G
Pingback: Geruson
Pingback: 강남 안마
Pingback: 강남안마
Pingback: cooling wristband
Pingback: https://migrationsprofi.de/
Pingback: kratom powder
Pingback: kratom capsules for sale
Pingback: kratom tea for sale
Pingback: rcsi nursing aptitude test
Pingback: cndp poste maroc
Pingback: reparation volet roulant paris
Pingback: Aaron Lal
Pingback: robe and swaddle set
Pingback: discount cigar prices
Pingback: bond street issue massage
Pingback: 欺骗客户
Pingback: skull ring men
Pingback: Supplement.
Pingback: crypto brokers
Pingback: 美しい服
Pingback: 홀덤사이트
Pingback: how to build a home bunker
Pingback: INSURANCE
Pingback: apply for a payday loan
Pingback: https://dasvibes.com/videos/jah-sun-respect-is-due/
Pingback: adnetwork
Pingback: where to buy delta 8
Pingback: tabletki na erekcje
Pingback: londonshemale
Pingback: Aaron Lal
Pingback: para kazanma
Pingback: Киевское агентство недвижимости
Pingback: read more
Pingback: get info
Pingback: horse racing malaysia schedule
Pingback: Click
Pingback: คลิปโป๊ใหม่
Pingback: read here
Pingback: read here
Pingback: read here
Pingback: read here
Pingback: d bal reviews
Pingback: https://onlymp3.net/
Pingback: Viagra bez recepty
Pingback: เว็บ สล็อต ที่ ดี ที่สุด
Pingback: credit card processing sales
Pingback: Pat Mesiti
Pingback: tiktok takipçi satın al
Pingback: how to start a merchant services company
Pingback: recettes faciles
Pingback: w88vnbet
Pingback: W88
Pingback: merchant account referral program
Pingback: it disposal
Pingback: reseller merchant services
Pingback: free computer disposal
Pingback: construtor de site
Pingback: Personal Training
Pingback: bandar bola
Pingback: Company Registration
Pingback: live oranum
Pingback: computer server disposal
Pingback: buy Instagram likes
Pingback: bong88.com
Pingback: w88club
Pingback: best cbd gummies
Pingback: buy weed
Pingback: Tulsa Lawn Mowing
Pingback: online casino malaysia
Pingback: free
Pingback: #Inside Joy
Pingback: foreclosure fraud
Pingback: exness
Pingback: security camera installation
Pingback: weed near me
Pingback: Herald Net
Pingback: Juneau Empire
Pingback: buy tiktok followers
Pingback: https://acnebase.com/what-is-acne-you-know-you-dont-want-it/
Pingback: hot uk deals
Pingback: bbin online slot game malaysia
Pingback: floor mat in car
Pingback: Liqueur
Pingback: Bladless fan reviews
Pingback: Laptop repair flower mound
Pingback: Akun Togel Resmi Dan Terpercaya
Pingback: mesothelioma onset
Pingback: Michael Wisniewski CT
Pingback: Rape porn
Pingback: Chế độ ăn keto là gì
Pingback: glycerin in germany
Pingback: canada pharmacy canada pharmacy canada pharmacy
Pingback: Pool Tile
Pingback: mens designer sneakers sale
Pingback: a level
Pingback: body back buddy
Pingback: Watches
Pingback: https://ad.beegix.com/search/wagner-santiago
Pingback: Great Dane Puppies for sale in Maryland
Pingback: letou.com
Pingback: перевод денег на украинскую карту
Pingback: 188live
Pingback: fb88go
Pingback: keonhacai88
Pingback: sbotop
Pingback: strawberry planting
Pingback: fun88link
Pingback: d2r
Pingback: bk8 vietnam
Pingback: His Secret Obsession Review
Pingback: Bartier Perry
Pingback: other sites like ebay
Pingback: m88cvf
Pingback: Painters Honolulu
Pingback: Excavating company near me
Pingback: Houston Excavating contractors
Pingback: places like craigslist
Pingback: buy cheapest vps
Pingback: EFTs
Pingback: automobile
Pingback: best seo services
Pingback: bimbim
Pingback: what is the main goal in creating the federal budget
Pingback: DailyCBD
Pingback: 파워볼
Pingback: credit repair free letter
Pingback: fn 5.7
Pingback: Look At This
Pingback: it recycling near me
Pingback: Obsługa systemu Linux
Pingback: missing persons investigator near me
Pingback: scammer Albanian
Pingback: condonlotto.com
Pingback: สมัครสล็อต
Pingback: https://canvaslock.com/three-reasons-why-you-should-use-a-silicone-sex-doll/
Pingback: idz na moj blog
Pingback: wazopresyna działanie
Pingback: สูตรสล็อต ฟรี
Pingback: Windows Server 2012 RDS User CALs
Pingback: corporate private investigators
Pingback: boyama sayfaları
Pingback: polskie gory gdzie najlepiej
Pingback: where can i print something
Pingback: illicit trade investigations
Pingback: Read more
Pingback: How to accept BTC
Pingback: heathrow to brighton minicab
Pingback: maxigra na przedwczesny wytrysk
Pingback: Human resources investigator
Pingback: Guided-Meditation-to-Fall-Asleep-Fast-with-DARK-SCREEN
Pingback: YOY là gì
Pingback: https://robloxsongidcodes.com/|https://robloxsongidcodes.com|http://robloxsongidcodes.com/|www.robloxsongidcodes.com|robloxsongidcodes.com|roblox song id codes|roblox music codes|roblox song ids|roblox song codes|roblox music id codes|roblox id|roblox mus
Pingback: events transfers brighton
Pingback: KIU
Pingback: African American Magazine
Pingback: have a peek here
Pingback: find out here
Pingback: natvisa.com
Pingback: Premium Sexpuppen
Pingback: cleaning services dubai
Pingback: on site
Pingback: Vandy Vape Mesh Wholesale
Pingback: moxibustion
Pingback: cleaning company dubai
Pingback: click
Pingback: official statement
Pingback: pozycjonowanie
Pingback: #drcharrington
Pingback: http://krajowy.biz
Pingback: Concrete company near me
Pingback: Gonzales concrete company
Pingback: Concrete company near me
Pingback: daftar bitbola
Pingback: Amazon coupon code
Pingback: power waxer
Pingback: Interior painters near me
Pingback: Interior painters near me