By Krishna Vishnubhotla, VP of Product Strategy at Zimperium
Every Halloween, we prepare ourselves for the arrival of the most frightening of beings: ghosts, goblins, vampires, skeletons, witches, zombies-you name it. We douse our houses in sage, eat mounds of garlic, and triple check that our doors are locked to ensure these monsters stay far, far away. Unfortunately, these tactics don’t work on the even scarier horrors that haunt us year round, the ones that plague our most valuable possessions: our mobile devices.
Whether you’re an employee using your personal device at work, or an entire healthcare organization using various apps and mobile devices to manage patient care, it’s important to be aware of the horrors lurking and waiting patiently to infiltrate your devices and apps. Here are some of the scariest threats that keep security experts from a peaceful night’s sleep:
A Mobile Ransomware Apocalypse
Mobile ransomware is a form of malware that affects mobile devices. A cybercriminal can use mobile malware to steal sensitive data from a smartphone or lock a device, before demanding payment to return the data to the user or unlock the device. Sometimes people are tricked into accidentally downloading mobile ransomware through social networking schemes, because they think they are downloading innocent content or critical software.
Malicious developers employ a range of techniques and methods to craft mobile ransomware that can effectively take control of a device or lock out a user from their data. These can include tactics such as ‘Locker ransomware’, where the attacker blocks the victim from interacting with the device by creating a lock screen or ‘Crypto ransomware’ where an attacker compromises a device by encrypting files, usually pictures and document files. Victims are extorted for payment, and if payment is not made, those behind the ransomware will distribute all personal information that was accessed to the victim’s contacts.
Zombie “Man” in the Middle
Man-in-the-Middle (MITM) attacks refers to an attack in which a malicious actor intercepts the communication between the device and a remote location in order to exfiltrate data, modify or redirect the traffic. In doing so successfully, attackers are able to steal login credentials, account details, and credit card numbers.
An example of a MITM attack would be for example, if an attacker sets up a fake chat service that mimicked that of a well-known bank, starts a chat with the target, then starts a chat on the real bank site, pretending to be the target and passing along the needed information to gain access to the target’s account.
Phishing for Candy and Mobile Devices
One of the most commonly used social engineering attacks is known as phishing. Threat actors use authentic-looking assets, such as e-mail, webpages, and text messages, to attempt to trick users into revealing sensitive data or clicking malicious links.
According to Zimperium’s Global Mobile Threat Report, 80% of phishing sites now either specifically target mobile devices or are built to function on both mobile devices and desktops. More so, the average user is 6-10 times more likely to fall for an SMS phishing attack than an email-based one.
That being said, don’t be surprised if you catch a ghostly being lurking in your inbox or your messages.
Be on alert for Ghosts, Goblins, Ghouls, and Spyware?
Spyware is a malicious software application that can secretly monitor a user’s activity, including their internet usage, keystrokes, sensitive information like credit card numbers, and login credentials. It is frequently installed on mobile devices without the user’s knowledge, often through mobile phishing or by exploiting software vulnerabilities.
Mobile devices are particularly vulnerable to spyware for several important reasons. First, they are always connected to the internet. This connectivity provides a long window of opportunity for surreptitious spyware-related activity. Second, the ease with which mobile devices can be customized allows unsuspecting users many opportunities to install malicious apps, perhaps disguised as legitimate apps. Third, while mobile operating systems have inherent security advantages over traditional endpoints (e.g., the OS kernel is locked down, and apps are in containers), mobile phones are less likely to have effective solutions to detect malware and device exploits.
Protecting Yourself from Mobile Menaces
As mobile phones continue to be used for increasingly essential services, whether shopping, banking, or working, cybercriminals know there are growing opportunities to profit.
It’s clear that mobile threats are becoming more frequent and dangerous as bad actors increasingly target smartphones as high-value targets. To survive these ghoulish attackers, teams must employ a mobile-first security strategy in order to be proactive and immediately spot suspicious activity, prevent account takeovers, and even stop fraud before it can occur. By applying a strong mobile-first approach to security, teams can establish advanced, adaptive protections that safeguard against device, network, phishing, and app attacks.
##
ABOUT THE AUTHOR
Krishna Vishnubhotla, VP of Product Strategy at Zimperium
Krishna Vishnubhotla is a seasoned professional in the SaaS industry, specializing in catalyzing startup growth through adept product and marketing strategies. With a keen focus on mobile application security products, he has a proven track record in defining and executing product visions that drive significant revenue growth. In addition to managing a global customer success portfolio, he established high-value strategic partnerships. His leadership skills extend to spearheading revenue generation efforts, serving a diverse clientele across multiple industries.






