Mobile Malware Surges By 500%

Proofpoint researchers have reported that attempted delivery of Mobile Malware Surges By 500% in Europe.

 

Trend

Smishing (text-based phishing) and malware targeting mobile devices have increased significantly in the past few years.

 

Android Is A More Popular Target

Research shows that Android is a far more popular target for cybercriminals than Apple iOS. This may be because Apple’s App Store has strict quality controls and iOS doesn’t allow sideloading. However, most mobile malware is still downloaded from app stores due to Android’s more open approach. For example, it is available to multiple app stores, and users can easily sideload apps from anywhere.

 

What Mobile Malware Does

The Proofpoint research shows that even though the primary purpose of malware (i.e. to give attackers control of a system) remains the same, the latest versions are becoming more advanced. For example, Proofpoint reports that some of this malware can record telephone and non-telephone audio and video, track locations, and destroy or wipe content and data, to name but a few. Also, mobile banking malware lies in wait until the user activates a financial app and then intervenes to steal credentials or information.

 

Adapted For Different Languages, Regions, and Devices

Researchers at Proofpoint’s Cloudmark Mobile Threat Research have found that Mobile malware has no geographic or linguistic boundaries. Threat actors adapt their campaigns to various languages, parts, and devices.

 

Common Mobile Malware Types

Some of the common types of mobile malware highlighted in Proofpoint’s research include:

  • FluBot – spreads by accessing the infected device’s contacts list or address book and sending the information back to a command-and-control (C&C) server. This malware can access the internet, read and send messages, read notifications, make voice calls, and delete other installed applications.
  • TeaBot – a multifunctional Trojan that can steal credentials and messages and stream an infected device’s screen contents to the attacker.
  • TangleBot – Discovered by Proofpoint and Cloudmark researchers in 2021, this mobile malware spreads via fake package-delivery notifications.
  • Moqhao – originating from China, this remote access Trojan has spying and exfiltration features to monitor device communications and grant an attacker remote access to the device.

 

How To Protect Your Device

Ways to protect your device from becoming infected with mobile malware include:

  • Use a mobile antivirus app from a trusted source (three-quarters of users don’t have this on their smartphone).
  • Be wary of unexpected or unrequested messages with links, URLs or requests for data, and don’t click on the links.
  • Report spam, smishing and suspected malware delivery to the Spam Reporting Service by using the spam reporting feature in your messaging client or forwarding suspicious text messages to 7726 (“SPAM” on the phone keypad).

 

What Does This Mean For Your Business?

With many people now using their smartphones for many aspects of business, remote working and BYOD are now commonplace. While mobile malware is surging and becoming more sophisticated, there is clearly an increased risk. With three-quarters of users not having a trusted mobile antivirus app on their phone, downloading and using one would be an excellent start (while ensuring it’s a trusted one). Also, awareness should be raised among the staff of the danger of clicking on links in unsolicited and suspicious messages (smishing risk) and of the threat of downloading apps outside of the Google Play Store. The Google Play Store should also be used with caution since some apps may contain malware. In addition, public WiFi should be avoided, particularly without a VPN, and Bluetooth and WiFi should be disabled when they aren’t in use to minimize the chance of being hacked.

Fully managed IT

IT Security

Networking

Disaster Recovery

Telephony