{"id":107123,"date":"2022-08-15T12:00:45","date_gmt":"2022-08-15T12:00:45","guid":{"rendered":"https:\/\/kasperskycontenthub.com\/securelist\/?p=107123"},"modified":"2022-08-15T11:06:34","modified_gmt":"2022-08-15T11:06:34","slug":"it-threat-evolution-in-q2-2022-mobile-statistics","status":"publish","type":"post","link":"https:\/\/securelist.com\/it-threat-evolution-in-q2-2022-mobile-statistics\/107123\/","title":{"rendered":"IT threat evolution in Q2 2022. Mobile statistics"},"content":{"rendered":"
These statistics are based on detection verdicts of Kaspersky products received from users who consented to providing statistical data.<\/em><\/p>\n According to Kaspersky Security Network, in Q2 2022:<\/p>\n In the second quarter of 2022, cybercriminal activity continued to decline \u2014 if the number of attacks on mobile devices is any indication.<\/p>\n Number of attacks targeting users of Kaspersky mobile solutions, Q1 2020 \u2014 Q2 2022 (download<\/a>)<\/em><\/p>\n As in the previous quarter, fraudulent apps occupied seven out of twenty leading positions in the malware rankings. That said, the total number of attacks by these apps started to decrease.<\/p>\n Interestingly enough, some fraudulent app creators were targeting users from several countries at once. For instance, J-Lightning Application purported to help users to invest into a Polish oil refinery, a Russian energy company, a Chinese cryptocurrency exchange and an American investment fund.<\/p>\n <\/a><\/p>\n On the contrary, the number of attacks by the RiskTool.AndroidOS.SpyLoan riskware family (loan apps that request access to users’ text messages, contact list and photos) more than quadrupled from the first quarter. The majority of users whose devices were found to be infected with this riskware were based in Mexico: a third of the total number of those attacked. This was followed by India and Colombia. The ten most-affected countries include Kenya, Brazil, Peru, Pakistan, Nigeria, Uganda and the Philippines.<\/p>\n <\/a><\/p>\n <\/a><\/p>\n <\/a><\/p>\n The second quarter was also noteworthy for Europol taking down<\/a> the infrastructure of the FluBot mobile botnet, also known as Polph and Cabassous. This aggressively spreading banking Trojan attacked mainly users in Europe and Australia.<\/p>\n In Q2 2022, Kaspersky detected 405,684 malicious installation packages, a reduction of 110,933 from the previous quarter and a year-on-year decline of 480,421.<\/p>\n Number of detected malicious installation packages, Q2 2021 \u2014 Q2 2022 (download<\/a>)<\/em><\/p>\n Distribution of newly detected mobile malware by type, Q1 and Q2 2022 (download<\/a>)<\/em><\/p>\n Adware ranked first among all threats detected in Q2 2022 with 25.28%, exceeding the previous quarter’s figure by 8.36 percentage points. A third of all detected threats of that class were objects of the AdWare.AndroidOS.Ewind family (33.21%). This was followed by the AdWare.AndroidOS.Adlo (22.54%) and AdWare.AndroidOS.HiddenAd (8.88%) families.<\/p>\n The previous leader, the RiskTool riskware, moved to second place with 20.81% of all detected threats, a decline of 27.94 p.p. from the previous quarter. More than half (60.16%) of the discovered apps of that type belonged to the Robtes family.<\/p>\n Various Trojans came close behind with 20.49%, a rise of 5.81 p.p. on the previous quarter. The largest contribution was made by objects belonging to the Mobtes (38.75%), Boogr (21.12%) and Agent (18.98%) families.<\/p>\n Note that the malware rankings below exclude riskware or PUAs, such as RiskTool or adware.<\/em><\/p>\nQuarterly figures<\/h2>\n
\n
\n
Quarterly highlights<\/h2>\n
Mobile threat statistics<\/h2>\n
Distribution of detected mobile malware by type<\/h3>\n
Top 20 mobile malware programs<\/h3>\n