Summary is AI-generated, newsdesk-reviewed
  • Mobile credential theft surges; Zimperium warns of increasing attacks via malicious apps.
  • 16% of cyberattacks in 2024 tied to credential theft, up from 10% in 2023.
  • Key industries targeted include finance, retail, and software; global threat scope.

Zimperium, the global pioneer in mobile security, issued a stark warning to organizations worldwide: mobile-based credential theft is accelerating, and the wave is far from over.

Looking back over the past year, Zimperium’s global telemetry revealed more than 2,400 variants of mobile malware specifically engineered to steal login credentials and intercept multi-factor authentication (MFA) codes. These attacks are powered by mishing (mobile focused phishing) campaigns and sideloaded apps that silently harvest access keys from the very devices employees rely on every day.

Massive breaches

Massive breaches are no longer starting on desktops, they’re starting in your pocket,” said Nicolás Chiaraviglio, Chief Scientist at Zimperium, adding What we saw last year is only the beginning. Organizations must take mobile security seriously to stop credential-stealing malware before it compromises enterprise resources.”

Key trends from the past year:

  • Credential theft was tied to 16% of cyberattacks in 2024, up from 10% in 2023
  • Attacks spread through mishing campaigns and sideloaded apps, often disguised as legitimate tools
  • Major hotspots include Southeast Asia, but detections are global in scope
  • Targeted industries: finance, retail, and software, where stolen credentials have immediate value

Families like TriaStealer, TrickMo, AppLite, Triada, and SMS Stealer show how attackers exploit mobile devices — intercepting one time passwords, hijacking messaging apps, and exfiltrating sensitive data without detection.

Mobile credential theft

The rise in mobile credential theft in 2024 is not an isolated spike; it signals a fundamental shift in how attackers operate. As mobile usage in the workforce continues to climb, these threats will only multiply.

Nicolás Chiaraviglio continues, “Enterprises can no longer treat mobile as secondary in their security strategies. If your mobile defenses aren’t proactive and real-time, you’re leaving the keys to your business exposed.”

Zimperium’s Mobile Threat Detection (MTD) and Mobile Runtime Protection (zDefend) provide on-device, AI-driven security to stop these threats in real time — even when no known signatures exist. 

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...