How serious is the mobile malware threat to businesses?

How serious is the mobile malware threat to businesses?

Share post

Mobile malware is a growing threat to businesses. The number of attackers who have diversified their tools to attack mobile targets in addition to desktop targets has increased significantly. There are mutliple reasons for this. An analysis of Lookout.

Certain categories of malware, such as ransomware, have proven successful in attacking non-mobile infrastructure. Attackers are now hoping for financial gains by targeting a user base that often does not expect to be targeted by mobile "locker" or ransomware applications. While mobile ransomware does not directly affect corporate infrastructure, it can affect employees' access to corporate resources on their devices.

Mobile ransomware

Surveillance malware offers attackers a more reliable way to gather sensitive information about a company or its employees. This information can be used to launch sophisticated spearphishing attacks against corporate infrastructure or resources, even if they are not accessible from a compromised employee's device. In general, more and more employees are using mobile devices to connect to corporate infrastructure when working remotely. This increasing reliance on mobile devices for work—and even for personal errands like banking—offers a wider attack surface for attackers.

Listen and spy on smartphones

If smartphones play a bigger role in accessing accounts (2FA, using authentication apps), will they become a bigger threat to the business? This is to be expected, yes. Greater reliance on mobile devices for work and access to accounts gives attackers a wider attack surface. Many users also use their mobile devices for personal applications and are not necessarily as adept at preventing attacks or keeping up to date with important security updates. As a result, attackers often see mobile devices as a way to move laterally to collect sensitive data from other accounts or applications installed on the victim's device.

Annoying and dangerous adware

According to the latest Malwarebytes threat analysis, adware is the largest mobile malware category. Are there ways adware can pose a threat to the business? Adware can encompass a number of different functions beyond faking advertising revenue. For businesses that depend on mobile advertising, it costs a significant amount of money. More sophisticated adware can cripple devices, requiring a full factory reset of the device or preventing users from accessing corporate accounts and applications. Some adware can also sniff out more sensitive data about the user and their device as part of their campaigns. However, an adware family is unlikely to pose a serious threat to an organization in the same way that a surveillance application or ransomware sample would. However, it can disrupt devices or collect more data than necessary about a company's employees.

Future: Will mobile malware threaten businesses?

That is very likely. The pandemic has changed the way many of us work, and we're unlikely to reduce our reliance on mobile devices for that work. While people are increasingly understanding that their mobile devices are just as vulnerable to attacks as their desktop computers, there is still less knowledge about how to protect their devices and avoid compromise.

Mobile devices are basically the perfect espionage tool: they can collect sensitive data about a potential target, record passive audio recordings, photos and details about the victim's social network and are almost always connected to a network. These features we're leveraging are tempting to attackers looking for details on sophisticated spear phishing attacks. They can also prove useful in an attempt to compromise or access corporate infrastructure when accessed from an employee device. As we increasingly rely on mobile devices for work and personal life, threat actors will continue to diversify their malware to exploit this dependency.

More at Lookout.com

 


About Lookout

Lookout co-founders John Hering, Kevin Mahaffey, and James Burgess came together in 2007 with the goal of protecting people from the security and privacy risks posed by an increasingly connected world. Even before smartphones were in everyone's pocket, they realized that mobility would have a profound impact on the way we work and live.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

IT security: NIS-2 makes it a top priority

Only in a quarter of German companies do management take responsibility for IT security. Especially in smaller companies ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

Cyber ​​attacks increase by 104 percent in 2023

A cybersecurity company has taken a look at last year's threat landscape. The results provide crucial insights into ➡ Read more

Mobile spyware poses a threat to businesses

More and more people are using mobile devices both in everyday life and in companies. This also reduces the risk of “mobile ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

Crowdsourced security pinpoints many vulnerabilities

Crowdsourced security has increased significantly in the last year. In the public sector, 151 percent more vulnerabilities were reported than in the previous year. ➡ Read more