Site navigation

Scot-Secure West | The Rising Mobile Attack Threat

Michael Edgar

,

Scot Secure West
Speaking at DIGIT’s Scot-Secure West conference, Ollie Sheridan – senior engineer at BitDefender – spoke about what he believes is the forgotten attack surface: mobile. 

When considering endpoint security, many are neglecting the device they carry with them everywhere they go, the device they spend hours at a time on each day: their mobile phone.

According to Broadband Search research, mobile leads the device market share in Europe at nearly 52%, compared to desktop computers, sitting at 45%.

In terms of activities by device, mobile leads desktop in emails, capturing 64% of users, also leading in social networking, messaging and chatting, and web searching. 

According to Olli Sheridan, making malware is purely a numbers game to threat actors. “At the end of the day, with people that are writing malware, spyware, and so on, they want to get the biggest bang,” he said. 

It’s practicality: threat actors will pool their resources to target devices with the most users. 

That being said, across operating systems on all devices, Android leads all others, taking up just over 40% of the market, followed by Windows at 35%, and Apple iOS far behind at 13%.

That is where the common misconception of Apple products being ‘bullet-proof’ comes from. It’s not necessarily that malware is harder to create for iOS, but there are just less targets, and by extension, less money to be made for threat actors in that domain, according to Sheridan. 

Aside from mobile phones being a target for threat actors in and of itself, they are also an entry point to organisations’ data, which threat actors are using to their advantage.

BYOD threats in your organisation

Bring your own device (BYOD) schemes have grown in popularity following the pandemic, when workers linked their personal devices to workplace operations like email and cloud servers to ease the process of working remotely. 

After the pandemic, the workforce saw a 58% jump in BYOD usage, according to Comparitech, which coincided with 68% of companies seeing a jump in productivity and companies saving an average of roughly £275 per employee, according to a report

However, a report from Slashnext shows seven out of ten employees have sensitive work information on their cellphones, and 43% of them were the target of phishing attacks. 

“What’s interesting about BYOD is you’re basically saying: that endpoint, that user, is the administrator, because it’s not your company’s device,” said Sheridan. 

This has prompted the recent revision of the National Cyber Security Centre’s (NCSC) Cyber Essentials to include guidelines on BYOD. According to the revision, an organisation has ownership of the corporate data and resources that may be accessed or stored on a device, but the device is property of the user. 

However, according to Sheridan: “There’s a kind of a kickback on that with BYOD users, because they say, ‘well, I can’t use the apps that I was using before and it’s my phone, but you’ve got control over it, and you can wipe things out.’ So they uninstall things, so you’re in a bit of a catch 22.”

By this, he means when companies take control of the data on a worker’s phone, it will drive them to use the secure methods of communication less, but if you don’t, the data remains at risk. Ultimately,  users are in full control of a device with sensitive company information on it, and can remove important security applications on a whim, leaving personal devices at greater risk of attacks.

The Mobile Gateway

As mobile is the most commonly accessible device for many people, it is often the first port of entry for malicious actors to gain access to a company’s sensitive information.

“It’s really the gateway to everything,” said Sheridan.

He points out that one of the most common security measures for accessing applications, like online banking, email, messaging, and more, is two-factor authentication (2FA). This is where you verify your identity on one device with a one-time password on another trusted device, which is often via text message on a mobile device.

“Well, if you get control of that mobile device, you basically got control of that 2FA,” he said, pointing out that this could give the threat actor access to cached information, cloud access, and entrance into apps. “It’s a computer, basically, at the end of the day, and people just forget about it.”

From a compromised mobile phone, you can glean login information, 2FA information, contacts, emails, and cloud storage, according to Sheridan.


Recommended


Vulnerabilities

According to Sheridan: “80% of the phishing sites out there, which are actually looking to harvest data through spyware, are actually targeting mobile specifically, or are doing hybrid spyware, which could infect both a desktop or a mobile device. So they’re getting very, very clever at this.”

Malicious actors, which can be individuals or malware itself, have multiple covert ways of infecting devices, for example, threat actors have embedded malware into applications available for download on official sites like Google Play. 

These ‘trojanized’ apps are pushed on victims through social engineering, for example by asking the victim to install an app to complete a quick task, then uninstall when it’s done. 

“Then they go on to Google Play, it’s got to be good, right? Because it’s on Google Play. So you’re not going to have a problem,” said Sheridan. However, Google play has shown in the past to host trojanized apps, some of which have gone months without being detected and infecting hundreds of devices. 

“What they did with this trojan application was they gained the phone number of that person,” he said, which could eventually lead to further objectives and spoofing attacks on other people in that person’s network. 

Securing Mobile Devices 

In the ongoing confrontation against threat actors in the mobile phone sphere, Sheridan says machine learning has been BitDefender’s best line of defence. 

“We looked at the way in which a threat actor, exploits our operating system,” he said. “We also look at libraries, we look at networks the devices connected to, as well as looking at the applications which are installed on a device.”

“We’re correlating that through with machine learning, providing a means to respond to that and an understanding of what’s actually going on on the endpoint,” he said. This process is made up of two components, the collection and processing of the data, and security analysis of the activity. 

“You really want to know, ‘how did that get in here?” he said. “These things can happen, and threat actors are getting very clever,” pointing out you may not have the time, training or resources to sit on your computer to analyse these questions. 

This is why leveraging machine learning in detecting threats or anomalies is proving to be an effective first line of defence, seeing as the window for system infiltration is opened wider than ever as more endpoints are introduced into the mix with mobile. 

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data