
Mobile malware targets smartphones and tablets (Android, iOS) for data theft, financial fraud, surveillance, and botnet recruitment. The mobile threat landscape has evolved from simple SMS fraud to sophisticated zero-click exploits and nation-state spyware.
| Aspect | Android | iOS |
|---|
| App Sources | Play Store + sideloading | App Store only (no sideload) |
| Malware Volume | High | Low (but high-value) |
| Common Vectors | Sideloaded APKs, Play Store | Zero-click, enterprise certs |
| Root/Jailbreak | Common | Rare (checkm8, checkra1n) |
| Permissions Model | Runtime permissions | Strict sandbox, entitlements |
| Category | Description | Examples |
|---|
| Banking Trojan | Overlay attacks, SMS interception | Anubis, Cerberus, EventBot |
| Spyware | Surveillance, data theft | Pegasus, Predator, SpyNote |
| SMS Fraud | Premium SMS subscription | Joker, Fleeceware |
| Adware/Clicker | Ad fraud, background clicks | HiddenAds, Clicker |
| Ransomware | File encryption, locker | Android/Filecoder |
| Cryptominer | Background mining | Hidden in apps |
| Dropper/Loader | Install secondary payload | Droppers, Triada |
| Root Exploit | Gain root, persist | Dirty COW, Towelroot |
| Family | Platform | Year | Type | Notable |
|---|
| Cabir | Symbian | 2004 | Worm | First mobile worm; Bluetooth |
| DroidDream | Android | 2011 | Root exploit | 50K+ in Play Store |
| Pegasus | iOS/Android | 2016+ | Spyware | NSO Group; zero-click |
| Joker | Android | 2019+ | Fleeceware | Premium SMS; Play Store |
| FluBot | Android | 2020-22 | Banking | SMS spread; Europe |
| Anubis | Android | 2017+ | Banking | Overlay, keylog, RAT |
| Cerberus | Android | 2019+ | Banking | RAT + overlay |
| EventBot | Android | 2020 | Banking | Accessibility service abuse |
| SpyNote | Android | 2022+ | Spyware | RAT, commercial |
| Predator | iOS/Android | 2021+ | Spyware | Cytrox; zero-click |
| Vector | Android | iOS |
|---|
| Sideloading | Primary | Enterprise certs, TestFlight |
| Play Store | Malicious apps | Rare (review) |
| Phishing/SMS | APK links | Profile install, WebClips |
| Zero-Click | RCE in media/libs | iMessage, Safari, iOS kernel |
| Enterprise Certs | N/A | Revoked certs, TestFlight |
| Pre-installed | OEM/Supply chain | Rare |
| Aspect | Details |
|---|
| Targets | Journalists, activists, politicians |
| Infection | Zero-click iMessage (FORCEDENTRY) |
| Capabilities | Messages, contacts, mic, cam, location, keys |
| Persistence | Reboot survives (kernel exploit) |
| Detection | Amnesty International MVT, Kaspersky |
- ✅ Official stores only — No sideloading
- ✅ OS updates — Install immediately
- ✅ App permissions — Deny camera/mic/location/SMS
- ✅ No jailbreak/root — Breaks sandbox
- ✅ Mobile EDR — Lookout, Zimperium, Jamf
- ✅ Remote wipe — MDM / Find My
- ✅ High-risk — GrapheneOS on Pixel; Lockdown Mode (iOS 16+)
| Technique | ID | Description |
|---|
| Malicious App | T1474 | Sideloaded malicious app |
| Exploit Public-Facing App | T1190 | Zero-click RCE |
| Masquerading | T1036.005 | Legitimate app names |
| Accessibility Abuse | T1546.015 | Android accessibility |
| Data from Local System | T1005 | Contacts, SMS, call logs |