Mobile Devices: Top Cyber Attack Vector
- Mobile devices are increasingly targeted for unauthorized company access, with a surge in complex phishing attacks exploiting device vulnerabilities and user errors, according to a new report.
- The report highlights a meaningful increase in "smishing" attacks – phishing attempts via SMS – which now account for more than two-thirds of all mobile phishing incidents. Voice...
- A concerning number of mobile devices are running on outdated operating systems, creating a significant security risk.
Mobile Security Threats Rise as Devices remain Outdated
Table of Contents
- Mobile Security Threats Rise as Devices remain Outdated
- Mobile Security Threats: Your Questions Answered
- Why are mobile devices increasingly targeted?
- What are “smishing” and “vishing,” and why are they dangerous?
- Why are outdated operating systems a security risk?
- What percentage of mobile devices are running outdated operating systems?
- How vulnerable are mobile applications?
- What are the risks associated with data leaks in mobile apps?
- What is “mishing,” and what are the implications?
- What types of malware are targeting mobile devices?
- What is “app sideloading” and its associated risks?
- What are the risks of using compromised apps?
- How does BYOD (Bring Your Own Device) increase mobile security risks?
- Summarizing Key Risks: A Comparison
- How can I protect my mobile device from these threats?
Mobile devices are increasingly targeted for unauthorized company access, with a surge in complex phishing attacks exploiting device vulnerabilities and user errors, according to a new report.
smishing on the Rise
The report highlights a meaningful increase in “smishing” attacks – phishing attempts via SMS – which now account for more than two-thirds of all mobile phishing incidents. Voice phishing, or “vishing,” attempts have also increased.
- Smishing attacks increased by 22 percent.
- Vishing attacks increased by 28 percent.
Outdated Systems a Key Vulnerability
A concerning number of mobile devices are running on outdated operating systems, creating a significant security risk. The report indicates that a quarter of mobile devices are unable to update to the latest OS versions, leaving them vulnerable to known exploits.
App Security lacking
Many mobile applications, both on iOS and Android platforms, lack basic code protection, making them susceptible to reverse engineering, manipulation, and data theft. Specifically:
- Over 60 percent of iOS apps lack basic code protection.
- Up to 34 percent of Android apps lack basic code protection.
Furthermore, a significant percentage of apps are vulnerable to data leaks, possibly exposing personal information.
- Almost 60 percent of iOS applications are susceptible to data leaks.
- 43 percent of Android apps are susceptible to data leaks.
Mishing: A Growing Threat
“Mishing,” or mobile-targeted phishing, is becoming a major concern for organizations. Cybercriminals are leveraging device vulnerabilities and user behavior to bypass traditional security measures.
Malware, Spyware, and App Sideloading
Cybercriminals continue to employ mobile malware, spyware, and advanced persistent threats (APTs). Researchers observed a 50 percent increase in attacks involving Trojans compared to the previous year. New banking Trojan families, including vultur, Droidbot, Errorather, and Blankbot, have also been identified.
Spyware remains a critical threat, capable of silently intercepting sensitive data, including login credentials and one-time passwords. The practice of “app sideloading,” or installing applications from unofficial sources, further exacerbates the risk. In 2024, approximately 23.5 percent of business smartphones had risky applications from unknown sources installed.
Risks of Compromised Apps
Using apps without proper security checks can lead to severe consequences, including the spread of malware, installation of Trojans, and loss of sensitive data. Internally developed apps frequently enough lack basic protective mechanisms, increasing their vulnerability.
Bring-your-own-device (BYOD) scenarios can also introduce risks, as over 50 percent of mobile devices may be running outdated or compromised operating systems. Data indicates that 25.3 percent of mobile devices can no longer be updated due to their age.
Methodology
The findings are based on anonymized threat and risk data collected worldwide from iOS and Android devices.
Mobile Security Threats: Your Questions Answered
Welcome to a thorough guide to the rising threats facing mobile devices. This article,based on insights from a recent report,addresses common questions about mobile security,providing clear explanations and actionable advice. Our focus is on providing you with information that is relevant and can help you protect yourself.
Why are mobile devices increasingly targeted?
Mobile devices are becoming prime targets for cyberattacks because they hold sensitive data and are often used for accessing company resources. The report states that “mobile devices are increasingly targeted for unauthorized company access, with a surge in complex phishing attacks exploiting device vulnerabilities and user errors.” Cybercriminals are constantly refining their tactics to exploit these vulnerabilities.
What are “smishing” and “vishing,” and why are they dangerous?
Smishing (SMS phishing) is a type of phishing attack that uses text messages to trick users into giving up personal information or installing malware.
Vishing (voice phishing) uses phone calls to deceive individuals into revealing sensitive data.
The report highlights a notable increase in both types of attacks: “Smishing attacks increased by 22 percent,” and “Vishing attacks increased by 28 percent.” These attacks are dangerous as they can lead to identity theft, financial loss, and the compromise of personal and company data.
Why are outdated operating systems a security risk?
Outdated operating systems, or OS, are a critical vulnerability.”A concerning number of mobile devices are running on outdated operating systems, creating a significant security risk.” This is because older OS versions often lack the latest security patches, leaving devices susceptible to known exploits and vulnerabilities. “The report indicates that a quarter of mobile devices are unable to update to the latest OS versions.”
What percentage of mobile devices are running outdated operating systems?
The report indicates that approximately 25% of mobile devices are unable to update to the latest OS versions. This leaves them vulnerable to potential security breaches.
How vulnerable are mobile applications?
Many mobile applications, both on iOS and android platforms, lack basic code protection, making them susceptible to reverse engineering, manipulation, and data theft.
Over 60 percent of iOS apps lack basic code protection.
Up to 34 percent of Android apps lack basic code protection.
What are the risks associated with data leaks in mobile apps?
Data leaks in mobile apps can expose personal information, potentially leading to identity theft, financial loss, or privacy violations.
almost 60 percent of iOS applications are susceptible to data leaks.
43 percent of Android apps are susceptible to data leaks.
What is “mishing,” and what are the implications?
“Mishing,” or mobile-targeted phishing,is becoming a major concern for organizations. Cybercriminals are leveraging device vulnerabilities and user behavior to bypass customary security measures. This is concerning because it shows cybercriminals are constantly innovating to exploit the weakspots of businesses and the vulnerabilities of outdated devices.
What types of malware are targeting mobile devices?
Cybercriminals continue to employ mobile malware,spyware,and advanced persistent threats (APTs). Researchers observed a 50 percent increase in attacks involving Trojans compared to the previous year. New banking Trojan families like vultur, droidbot, Errorather, and Blankbot have also been identified, highlighting the breadth of emerging risks.
What is “app sideloading” and its associated risks?
“App sideloading” is the practice of installing applications from unofficial sources. This can expose devices to malware and other security threats, as these apps are not subject to the same security checks as apps from official app stores. Installing applications from unexpected sources further exacerbates the risk. In 2024, approximately 23.5% of business smartphones had risky applications from unknown sources installed.
What are the risks of using compromised apps?
Using apps without proper security checks can lead to severe consequences, including:
The spread of malware
Installation of Trojans
Loss of sensitive data.
Internally developed apps frequently lack basic protective mechanisms, increasing their vulnerability.
How does BYOD (Bring Your Own Device) increase mobile security risks?
Bring-your-own-device (BYOD) scenarios can introduce risks, as over 50 percent of mobile devices may be running outdated or compromised operating systems. Data indicates that 25.3 percent of mobile devices can no longer be updated due to their age. This poses a security risk to both the individual and the association if access is granted to company data through these devices.
Summarizing Key Risks: A Comparison
Here is a summary of the key risks described in the report:
| threat | iOS Apps Vulnerability | Android apps Vulnerability | Description |
| ————————— | ———————– | ————————– | ———————————————————————————————————————————————————————————————————————————————————— |
| Lack of Code Protection | Over 60% | Up to 34% | Applications can be reverse engineered and manipulated. |
| Data Leaks | Almost 60% | 43% | Personal information is at risk of exposure. |
| Outdated Operating Systems | High | High | Leaves devices open to known exploits; a quarter of devices cannot be upgraded to latest OS. |
| App Sideloading | N/A | N/A | Installing apps from unofficial sources, increasing the risk of malware and data breaches; Approximately 23.5% of business smartphones had apps from unknown sources installed (2024 analysis). |
| Smishing/Vishing | All Apps | All Apps | Phishing attacks via SMS and voice calls; Smishing attacks increased by 22% and vishing by 28% |
| Malware/Spyware/APTs | All Apps | All Apps | increase in trojan attacks (50 % increase); can lead to the theft of credentials, one-time passwords, and other sensitive data through banking Trojans like vultur, Droidbot, Errorather, and Blankbot. |
How can I protect my mobile device from these threats?
Keep your OS and apps updated: Ensure your device’s operating system and all applications are up-to-date with the latest security patches.
Be cautious of links and attachments: Avoid clicking on links or opening attachments from unknown senders.
Use strong passwords and enable two-factor authentication: Protect your accounts with strong, unique passwords and multi-factor authentication.
Only download apps from trusted sources: Stick to official app stores (Apple App store and Google Play Store) to minimize the risk of downloading malicious apps.
Be aware of your surroundings: Pay attention to your surroundings and avoid using public wi-fi networks for sensitive transactions.
* Install a mobile security solution: Consider using a reputable mobile security app to scan for malware and protect your device.
By staying informed and implementing these best practices, you can substantially reduce your risk of becoming a victim of mobile security threats.
