Zimperium
Reports
All Statistics
TsarBot targeted 450 banking apps and accounted for 58% of its global activity.
CopyBara targeted 446 banking apps.
Nexus concentrated 90% of its global targets in EMEA.
Almost 86% of phishing attacks contain AI-generated elements.
The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
Spyware is present on nearly one in ten mobile devices, representing more than a 4x year-over-year increase.
Around 19% of Android shopping apps expose at least one unprotected exported Service, potentially leading to data leakage.
Approximately 24% of analyzed Android shopping apps can retrieve Java classes or DEX files from remote locations.
Roughly 29% of reviewed iOS shopping apps access user data without declaring it in their App Store Privacy Overview.
3 VPN apps still utilized a legacy version of the OpenSSL library.
On iOS, over 6% of VPN apps were found requesting private entitlements, which are typically restricted from third-party developers. This represented a total of 30 apps
25% of the VPN apps analyzed on iOS failed to include a valid privacy manifest at all.
Vishing (voice-call phishing) tactics grew by 28%.
There was a 50% increase year-over-year in the use of Trojans in attacks.
70% of organizations support BYOD (Bring Your Own Device)
88% of all apps use one or more cryptographic methods that do not follow best practices.
43% of the top 100 apps use one or more cryptographic methods that do not follow best practices.
103 of 9,078 analyzed Android apps were found to use unprotected or misconfigured cloud storage. 4 of these Android apps were in the top 1000 of the PlayStore popularity list.
Compromised app detections surge by a factor of 12 on rooted devices compared to stock devices.
System compromise incidents are 250 times higher on rooted devices compared to stock devices.
The exposure factor of rooted devices versus stock devices varies from 3x to ~3000x, which suggests that rooted devices are potentially much more vulnerable to threats than stock devices.
Quishing (QR code phishing) is emerging, with notable activity in Japan (17%), the U.S. (15%), and India (11%).
3% of phishing sites use device-specific redirection, showing benign content on desktops while targeting mobile devices with phishing payloads.
Smishing (SMS/text based phishing) is the most common mobile phishing vector, accounting for 37% of attacks in India, 16% in the U.S., and 9% in Brazil.
Hook targeted 385 banking apps.
34 malware families targeted 1,243 mobile banking and fintech apps across 90 countries globally.
In EMEA, 30 mobile malware families targeted over 800 banking and fintech applications across 44 countries.
TsarBot, CopyBara, and Hook collectively targeted more than 60% banking and fintech apps.
The United States had 162 banking apps under active targeting, the highest concentration of any single country globally.
Ukraine, Russia, and the United States are the top three countries hosting command-and-control infrastructure across the malware families analyzed.
Android malware transactions increased by 67% year-over-year.
More than 60% of mobile banking apps lack basic code protection.
AI adoption within mobile applications has grown 14x on Android and 7x on iOS.
Phishing events detected on employee mobile devices have grown 380% since January 2025.
The median threat actor uses AI across 15 MITRE attack techniques.
The United States had the highest concentration of targeted apps globally, with 162 banking applications under active targeting, up from 109 in 2023.
Nearly half of the active malware families have financial extortion capabilities, including ransomware that can encrypt files on the device.
Android malware-driven financial transactions increase 67% year-over-year.
Thirty-four active malware families targeted 1,243 financial apps across 90 countries.
TsarBot, CopyBara, and Hook collectively targeted more than 60% of global banking and fintech apps.
During the 2024 shopping season, there was a 4x increase in mishing sites compared to monthly averages.
Approximately 1% of the analyzed VPN apps were found to be vulnerable to a Man-in-the-Middle (MitM) attack.
50% of mobile devices are running on outdated operating systems.
Over 60% of iOS apps lack basic code protection.
Up to 34% of Android apps lack basic code protection.
Over 25% of mobile devices cannot upgrade to the latest OS versions.
Nearly 60% of iOS apps are vulnerable to PII data leakage.
43% of Android apps are vulnerable to PII data leakage.
Smishing has rapidly grown to comprise over two-thirds of mobile phishing attacks. Specifically, SMS/text based phishing (Smishing) is now 69.3% of all mishing attacks.