The growing risk of cybercriminals targeting workers’ mobile devices has been highlighted in a new study from Check Point Research (CPR).
The rise of remote and hybrid working and bring your own device (BYOD) culture has seen workforces become increasingly diffuse. Not only has this increased the size of perimeters cybersecurity practitioners need to monitor, it has also increased the number of weak points.
With home and work lives blurring, so too are the lines between personal and professional devices. As such, many people are using their own laptops, phones or flash drives for work purposes, and vice versa. This creates potential vulnerabilities.
According to previous research, 49% of organisations around the world are unable to detect an attack or breach on employee-owned devices.
CPR has warned that the mobile arena could soon become the new corporate cybersecurity battleground.
Potential threats the company pointed to include mobile spyware that can assume complete control of iOS and Android devices via zero-click exploits and credential-harvesting trojans deployed via malicious apps.
“We’ve seen some concerning developments in the mobile threat landscape throughout the past year,” CPR said in a statement.
It pointed to NSO, the group behind the malware ‘Pegasus’ which can takeover iOS and Android devices.
“In 2019, Pegasus was used to leverage WhatsApp and infect more than 1,400 user devices, from senior government officials to journalists and even human rights activists,” CPR added.
“More recently, in 2021, it was widely reported that Pegasus had been used to target the mobile devices of more than 50,000 devices around the world, including those of high-level business executives.”
Recommended
- Data Protection Summit 2022 | The current state of legislation
- Edinburgh sees tech job boost through new AND Digital Club
- Experts create new sign language glossary of digital terms
The rise of SMS phishing (smishing) puts mobile devices at further risk. Through links spread by security update warnings, parcel delivery alerts or voicemail notifications, they are simple but effective way to infect devices.
Once an individual’s device is compromised, it can be used to access corporate networks.
This poses a complex challenge for cybersecurity teams. Organisations need to balance their own protection against flexibility and their employees’ right to privacy.
“As our mobile ecosystem continues to expand, the attack surface area available to threat actors will expand right along with it,” CPR warned.
“It’s never been clearer that mobile security is no longer an option for businesses. Instead, they should be looking to broaden their capabilities while taking a more holistic approach to guarding their increasingly distributed endpoints.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





