Android security is taking another hit. According to Zscaler ’s annual report , more than 239 malicious apps managed to bypass Google Play’s filters in a single year, garnering over 42 million downloads from unsuspecting users. The finding confirms that despite improvements in security measures, the Android ecosystem remains the most attractive arena for cybercriminals.
Malware on the rise
Zscaler reports an explosive 67% increase in mobile malware between June 2024 and May 2025. The most dangerous types include spyware and banking trojans, which target sensitive information such as banking passwords and login data.

There is also a shift in attacks from traditional card fraud to social engineering – through phishing, smishing or SIM-swapping. This shift is attributed to the spread of mobile payments and the effectiveness of new security technologies, such as chip-and-PIN.
See also: RondoDox botnet upgraded – Significant threat
“Criminals are developing malicious applications that look like legitimate ones, with the aim of stealing financial information,” the company explains. While the overall number of attacks is increasing, the growth rate of banking trojans slowed to 3%, down from 29% the previous year — a sign that the malware market is maturing.
Adware: The new king of threats
There is also a striking change in the nature of the attacks. Adware, previously considered a secondary threat, now accounts for 69% of all detections, almost double the share from last year. The notorious Joker info-stealer, which once dominated with 38%, has now fallen to second place (23%).
At the same time, spyware skyrocketed with a 220% increase , with the SpyNote, SpyLoan and BadBazaar families being exploited for surveillance, extortion and identity theft.

The geographical distribution of attacks shows that India, the US and Canada account for 55% of the total, while Italy and Israel saw explosive increases of up to 4,000%.
See also: Malicious ads for PuTTY and Teams distribute malware
Google Play: The three most dangerous malware of 2025
Zscaler singled out three malware families with the greatest impact:
- Anatsa – A banking trojan that periodically reappears on Google Play disguised as productivity apps. Its latest version can steal data from over 831 financial institutions and crypto platforms, expanding its reach to new markets such as Germany and South Korea.
- Android Void (Vo1d) – A backdoor malware targeting Android TV devices , exploiting old versions of the operating system. 1.6 million infected devices have already been detected in India and Brazil.
- Xnotice RAT – A trojan remote access targeting oil and gas professionals. It spreads through fake job portals, recording screens, and intercepting MFA codes and SMS.
Risks for the Internet of Things as well
The report is not limited to mobile devices. Researchers warn that IoT devices, and routers, have been a major target for hackers this year. Through command injection, attackers are turning routers into botnets or proxies to distribute malware. Most attacks are located in the US, while Hong Kong, Germany, India and China are emerging as new hotspots.
See also: Hackers exploit RMM tools to penetrate Logistics networks

How to protect yourself
Zscaler recommends that users:
- keep their devices updated with the latest security versions,
- only download apps from trusted developers,
- disable accessibility permissions when they are not needed,
- avoid downloading unnecessary applications,
- and perform regular scans via Play Protect.
For businesses, the solution lies in architecture Zero Trust , hardened IoT gateways , and real-time anomaly monitoring
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In a world where apps are becoming the center of our daily lives, security remains the most vulnerable point. A new report from Zscaler is a stark reminder that even the official Android store isn't always as secure as we think.
Source: www.bleepingcomputer.com
