securelist.com 5/18/2026, 12:11:19 PM · via preferred

SparkCat stealer hides in Android apps as Mamont Trojans surge

SparkCat stealer hides in Android apps as Mamont Trojans surge
CyberSIXT Evidence Panel Source marked as original reporting

ACCORDING to Kaspersky Security Network, in Q1 2026 more than 2.67 million attacks utilizing malware, adware, or unwanted mobile software were prevented. The Trojan-Banker category was the prevalent mobile malware threat with a 10.86% share of total detections, and more than 306,000 malicious installation packages were discovered, including 162,275 packages related to mobile banking Trojans and 439 packages related to mobile ransomware Trojans.

The number of Android malware samples rose slightly to 306,070, while banking Trojan activity surged, with Mamont variants accounting for the majority of packages and entering nearly every ranking by affected user count, and Triada’s pre-installed backdoor variants also rising in the rankings. In Q1 2026, the number of installation packages for mobile banking Trojans totalled 162,275, a 50% increase on the previous quarter, which also saw a 50% rise in related attacks.

The report notes that the SparkCat crypto stealer appeared in apps on Google Play and the App Store, with the Android version obfuscated via a Rust library decrypted by a Dalvik-like VM.

View full article

Article by CyberSIXT