Surge in Smartphone Malware Infections in Russia Driven by Trojans
Article Content
- •Smartphone malware infections in Russia rose 70% in early 2026 compared to 2025.
- •The Mamont banking trojan is responsible for 15% of all detected infections this year.
- •Approximately 1.5 million Android devices in Russia are compromised by malware.
In the first half of 2026, smartphone malware infections in Russia increased by 70% compared to the same period in 2025, as reported by Kommersant. The primary target is Android devices, with the Mamont banking trojan being a significant threat, rising from 10-12% of infections last year to 15% this year. Approximately 1.5 million Android devices in Russia are compromised by this malware. The rise in infections is attributed to the unavailability of apps in official stores, leading users to install APK files from third-party sources. Criminals exploit this behavior by distributing fake banking apps and updates. The growing interest in AI services has also contributed to the distribution of these trojans. Cybersecurity firm F6 has noted that campaigns using Mamont have been active since 2023.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Mamont in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…