Zimperium - Experts & Thought Leaders
Latest Zimperium news & announcements
Zimperium, the pioneer in AI-empowered mobile security, releases new research revealing how threat actors are using sophisticated recruitment-themed phishing campaigns to specifically target corporate credentials, with mobile devices creating an especially effective attack surface. The campaigns impersonate recruiters and HR personnel from well-known global brands, using realistic interview and scheduling experiences to lure victims into counterfeit login pages. Critically, the phishing infrastructure actively rejects personal email addresses and requires victims to enter corporate credentials, demonstrating that these attacks are intentionally designed to compromise enterprise accounts rather than indiscriminately harvest consumer credentials. Legitimate authentication windows On desktop devices, attackers can use Browser-in-the-Browser (BitB) techniques to simulate legitimate authentication windows. On mobile, the attack becomes even harder to identify. The phishing experience adapts to the smaller screen and presents victims with a full-screen counterfeit login page. With limited visibility into URLs and other browser indicators, employees can have fewer visual cues that the authentication request is fraudulent. “What makes these recruitment scams particularly concerning for enterprises is the deliberate focus on corporate identities,” said Nico Chiaraviglio at Zimperium. “Attackers are not simply looking for any credential they can steal. They are screening for enterprise accounts that can provide a path into corporate email, cloud applications and other business-critical systems. Mobile makes that deception even more effective because many of the visual signals employees rely on to recognize phishing are reduced or absent.” Impersonating prominent organizations Zimperium analyzed a year of telemetry associated with brand-impersonating recruitment domains and found that the threat extends beyond the recent surge in recruitment scams. Attackers have maintained persistent infrastructure while impersonating prominent organizations across technology, retail, aviation, professional services, consumer goods and other industries. As part of its investigation, Zimperium identified 46 previously unpublished indicators of compromise (IOCs) associated with this activity. The analysis also found significant delays between the registration of impersonation domains and their identification by public threat feeds. In several cases, domains remained unreported for months or even years, creating an extended window in which employees could encounter malicious infrastructure before it appeared on traditional blocklists. Desktop-centric security controls The findings underscore a broader challenge for enterprise security teams: attacks targeting corporate identity increasingly begin on mobile devices, outside the visibility of desktop-centric security controls. Zimperium Mobile Threat Defense (MTD) dynamically analyses network activity and mobile threats directly at the device level, helping organizations identify and block credential-harvesting attacks in real time, including newly created phishing infrastructure that may not yet appear in static URL and reputation feeds.
Zimperium, the global pioneer in AI-empowered mobile security, announces new research from its zLabs threat research team detailing the evolution of ToxicPanda 2.0, an advanced Android banking trojan that significantly expands both its technical capabilities and the scale of its fraud campaign. The latest variant represents a new generation of the original ToxicPanda banking Trojan and introduces 167 remote commands, expanding credential theft from a handful of banking applications to 349 banking, financial, e-wallet, and cryptocurrency applications across 16 countries, and adding sophisticated techniques to compromise Android devices, harvest banking credentials, and maintain long-term persistence on infected devices. Adding sophisticated techniques As mobile app adoption continues to rapidly grow for use in banking services, enterprise applications, digital identities, and sensitive corporate data, increasingly sophisticated Android malware poses ever greater risks to both consumers and corporations. "ToxicPanda 2.0 demonstrates how quickly mobile malware continues to evolve," said Nico Chiaraviglio, Chief Scientist at Zimperium zLabs. "Rather than simply stealing credentials, this malware automates device compromise, expands financial targeting on a global scale, and abuses legitimate Android features to gain control over infected devices. It reflects the increasing sophistication of modern mobile threats." Zimperium's AI-empowered, on-device mobile security protects organizations against advanced threats like ToxicPanda by detecting malware, device compromise, phishing overlays, and malicious application behavior before attackers can steal credentials or gain control of the device.
Zimperium, the global pioneer in AI-empowered mobile security, announces Zimperium Deep Insights, the industry's only enterprise-wide solution to unify real-time Mobile Threat Defense with automated mobile forensics. This solution enables security teams to investigate AI-powered mobile attacks in minutes instead of weeks or months. By automating forensic analysis and reconstructing complete mobile attack timelines, Deep Insights transforms complex mobile investigations into a streamlined, evidence-driven workflow that any security team can use. AI-generated mobile phishing Artificial intelligence has dramatically increased the speed, scale, and sophistication of mobile attacks. AI-generated mobile phishing (mishing), commercial spyware, and other mobile-targeted threats are making it increasingly difficult for security teams to quickly determine how a mobile device was compromised, what changed, and whether sensitive enterprise data was exposed. Organizations need more than threat detection. They need the ability to rapidly investigate incidents, validate compromise, and respond with confidence. “AI has fundamentally changed how attackers target mobile devices, forcing security teams to investigate more incidents with fewer resources," said Shridhar Mittal, CEO of Zimperium. "Organizations need more than alerts, they need immediate answers. Deep Insights gives security teams the forensic evidence and attack context they need to rapidly understand compromise, accelerate response, and reduce business risk." Mobile security incident Unlike traditional mobile security solutions that stop at detection, Deep Insights reconstructs the complete sequence of events surrounding a mobile security incident. It automatically correlates critical forensic artifacts including configuration changes, app activity, permission shifts, and suspicious network traffic to construct a complete attack timeline. Additionally, Deep Insights enables security teams to baseline a device's state before and after travel or suspected compromise. By comparing these states side-by-side, analysts can instantly spot unauthorized changes, confirm breach severity, and determine if a device is safe to reconnect to enterprise networks, all without shipping physical hardware to specialized forensic labs. By dramatically reducing investigation time, Deep Insights enables organizations to contain threats faster, minimize business disruption, and strengthen incident response. Zimperium Deep Insights is expected to become generally available in September 2026, and will be demonstrated at Black Hat 2026 in booth #2761.