Zimperium News

Zimperium unveils AI mobile security phishing risks

Zimperium, the pioneer in AI-empowered mobile security, releases new research revealing how threat actors are using sophisticated recruitment-themed phishing campaigns to specifically target corporate credentials, with mobile devices creating an especially effective attack surface. The campaigns impersonate recruiters and HR personnel from well-known global brands, using realistic interview and scheduling experiences to lure victims into counterfeit login pages. Critically, the phishing infrast...

Zimperium unveils ToxicPanda 2.0 trojans' threat

Zimperium, the global pioneer in AI-empowered mobile security, announces new research from its zLabs threat research team detailing the evolution of ToxicPanda 2.0, an advanced Android banking trojan that significantly expands both its technical capabilities and the scale of its fraud campaign. The latest variant represents a new generation of the original ToxicPanda banking Trojan and introduces 167 remote commands, expanding credential theft from a handful of banking applications to 349 banki...

Zimperium deep insights: AI mobile security solution

Zimperium, the global pioneer in AI-empowered mobile security, announces Zimperium Deep Insights, the industry's only enterprise-wide solution to unify real-time Mobile Threat Defense with automated mobile forensics. This solution enables security teams to investigate AI-powered mobile attacks in minutes instead of weeks or months. By automating forensic analysis and reconstructing complete mobile attack timelines, Deep Insights transforms complex mobile investigations into a streamlined, evide...

Revolutionising mobile security: Zimperium's AI insights

Zimperium, the pioneer in AI-empowered mobile security, releases its 2026 Global Mobile Threat Report, revealing that artificial intelligence is accelerating the speed, scale, and sophistication of mobile attacks years ahead of enterprise readiness. The report, which is primarily based on findings from Zimperium’s zLabs research team, indicates that AI is fundamentally reshaping the mobile threat landscape, enabling more convincing and scalable mobile phishing campaigns, increasingly ed m...

Zimperium leads mobile threat defense in AI security

Zimperium, the world's pioneer in AI-empowered mobile security, announces it has been named as a Visionary Leader in Frost & Sullivan's 2026 Frost Radar™ for Mobile Threat Défense (MTD). Frost & Sullivan identified Zimperium as the strongest performer on both the Innovation Index and Growth Index, recognising the company's continued leadership in protecting enterprises and government organisations against the rapidly evolving mobile threat landscape. The report also identif...

Zimperium unveils advanced mobile MaaS platform

Zimperium, the world pioneer in AI-Empowered mobile security, announces new research from zLabs detailing RedWing, a sophisticated Android Malware-as-a-Service (MaaS) platform that enables cybercriminals to deploy highly customizable mobile malware through a commercial subscription model. Marketed through Telegram and distributed through mobile-targeted phishing (mishing) campaigns, RedWing combines advanced remote access, credential theft, surveillance, and banking fraud capabilities into a tu...

Zimperium AI mobile security in UK fraud strategy

Zimperium, the world's pioneer in AI-empowered mobile security, today warned that the UK Government’s newly released Fraud Strategy 2026–2029 signals a major shift in both the scale of mobile-targeted fraud and the regulatory expectations placed on enterprises responsible for protecting customers and transactions. The strategy identifies mobile channels, including messaging platforms, social applications, mobile banking apps, and voice communications, as a central component of moder...

Zimperium UK mobile security partnership expands

Zimperium, the world pioneer in AI-empowered mobile security, announces a new distribution partnership with ABC Distribution, expanding its reach across the United Kingdom as organisations face increasing exposure to cyber threats targeting mobile devices and applications. As cybercriminals adopt a mobile-first attack strategy, mobile has become a primary entry point for modern threats. This includes the rapid rise of mishing—mobile-targeted phishing attacks delivered through SMS, messagi...

Zimperium's mobile app response agent debuts

Zimperium, the pioneer in AI-empowered mobile security, announces the launch of Mobile App Response Agent, enabling security teams to respond faster than ever before to fraud and security threats. Leveraging Zimperium’s unmatched expertise in mobile security, Mobile App Response Agent is part of Zimperium’s Mobile App Protection Suite (MAPS), empowering SOC and Fraud teams to assess attacks on their mobile app before they result in fraud or a breach by reducing the time required for...

Zimperium launches AI-driven Mobile SOC Agent

Zimperium, the world pioneer in AI-empowered mobile security, announced the launch of its Mobile SOC Agent, a force multiplier for security analysts confronting the rise of mobile threats aimed at iOS and Android mobile devices. Leveraging Zimperium’s unmatched expertise in mobile security, Mobile SOC Agent is an agentic AI solution that enhances Zimperium’s industry-leading Mobile Threat Defense (MTD), enabling security teams to rapidly identify, prioritise, and remediate mobile t...

Zimperium's AI-powered mobile security vision

Zimperium, the world pioneer in mobile security, outlined its new AI-empowered mobile security vision, including the availability of two new AI-powered agents that provide a force multiplier in the battle to harden the mobile attack surface. Globally, cybercriminals have moved to a mobile-first attack strategy, weaponising AI coupled with highly sophisticated social engineering campaigns. The result is that mobile apps and devices now represent the most vulnerable attack surface in most organis...

Zimperium reveals active android banking trojans

Zimperium, the pioneer in AI-empowered mobile security, announces new findings from its zLabs threat research team identifying four active Android banking trojan campaigns—RecruitRat, SaferRat, Astrinox, and Massiv—collectively targeting more than 800 banking, cryptocurrency, and social media applications worldwide. The research highlights how these malware families are evolving beyond basic credential theft, using sophisticated phishing infrastructure, deceptive overlays, Accessibi...

Zimperium's 2026 banking heist report on mobile fraud

Zimperium, the world pioneer in AI-empowered mobile security, released its 2026 Banking Heist Report. The finding is unambiguous: mobile banking apps have become the primary battleground for financial fraud — and attackers are winning. Malware bypassing app security controls Throughout 2025, Zimperium’s zLabs team tracked 34 active malware families targeting 1,243 financial institutions across 90 countries. Android malware-driven financial transactions increased 67% year-over-year....

Zimperium reveals PixRevolution targeting Brazil’s PIX

Zimperium, the pioneer in AI-empowered mobile security, announces new research from its zLabs threat intelligence team uncovering PixRevolution, a sophisticated Android banking trojan designed to hijack Brazil’s widely used PIX instant payment system in real time. PixRevolution represents a significant evolution in mobile financial malware. Unlike traditional banking trojans that rely heavily on automated overlays or credential theft, PixRevolution introduces an agent-operated attack mode...

Zimperium's new AI-driven mobile security insights

Zimperium, the world pioneer in AI-empowered mobile security, released new threat intelligence detailing extended indicators of compromise (IOCs) associated with TaxiSpy, a sophisticated Android banking malware strain targeting mobile users and financial applications. Research The research, conducted by Zimperium’s zLabs threat research team, expands on previously identified TaxiSpy samples by uncovering additional infrastructure, artifacts, and indicators tied to the malware’...

Zimperium AI mobile security transformation overview

Zimperium, the world pioneer in AI-empowered mobile security, released new analysis outlining how regulatory changes and advances in artificial intelligence are transforming the mobile threat landscape and creating new challenges for enterprises. Mobile first attack strategy Mobile devices and applications now represent one of the largest attack surfaces in the enterprise. As cybercriminals adopt a mobile-first attack strategy, the combination of new regulatory policies and AI-driven developme...

Zimperium mobile security: Combatting Keenadu backdoor

Zimperium, the world pioneer in mobile security, issued an advisory regarding Keenadu, a newly disclosed firmware-level Android backdoor that embeds itself deep within device software, bypassing traditional mobile security controls and exposing organisations to persistent, high-risk compromise. About Keenadu Unlike conventional mobile malware delivered through malicious apps, Keenadu integrates directly into device firmware and injects itself into the Android Zygote process, the parent process...

Zimperium exposes android threat: Arsink RAT

Zimperium, the pioneer in mobile security, announced new research from its zLabs threat research team revealing a large-scale Android surveillance campaign dubbed Arsink RAT, a cloud-native Remote Access Trojan (RAT) designed to harvest sensitive data and give attackers intrusive control over infected devices while blending into legitimate cloud traffic. The investigation, titled “The Rise of Arsink RAT,” identified 1,216 unique malicious Android app samples, tied to 317 distinct co...

Zimperium uncovers mobile PDF phishing threats

Zimperium, the world pioneer in mobile security, now released new threat research exposing a growing wave of mobile-targeted phishing attacks that weaponise PDF documents delivered via SMS and MMS. The findings reveal how threat actors are exploiting user trust in PDFs and gaps in mobile security controls to harvest credentials and sensitive data at scale. Zimperium’s zLabs research team According to Zimperium’s zLabs research team, attackers are increasingly using PDFs as a deli...

Zimperium's zLabs reveals advanced DroidLock ransomware

Zimperium, the pioneer in mobile security, today announced new research from its zLabs team uncovering DroidLock, a rapidly evolving Android malware campaign targeting users in Spain. Unlike traditional mobile malware, DroidLock behaves more like full-scale ransomware, enabling complete device takeover through screen-locking overlays, credential theft, and remote control capabilities. Android safeguards zLabs researchers found that DroidLock is distributed through phishing websites and begin...

Zimperium's ClayRat Android Spyware evolution

Building on earlier research published in October 2025, Zimperium announced that its zLabs team has uncovered a significantly enhanced variant of ClayRat, an Android spyware family first detailed in the technical brief “ClayRat: A New Android Spyware Targeting Russia”. While the original ClayRat strain was able to exfiltrate SMS messages, call logs, notifications, device data, take photos, and send mass SMS or place calls, effectively allowing infected devices to become distribution...

Zimperium expands with new CFO Alistaire Davidson

Zimperium, the world's pioneer in mobile security, now announced that Alistaire Davidson has joined the company as Chief Financial Officer, reporting directly to CEO Shridhar Mittal. Alistaire brings more than 20 years of finance leadership experience across private equity–backed and public software companies. Alistaire most recently served as Regional CFO, Americas at The Access Group, where he led the post-acquisition integration of two strategic business units. Prior to The Access Grou...

Zimperium's findings on Android app security risks

Zimperium, the global pioneer in mobile security, revealed findings from its zLabs team showing that thousands of popular Android applications — including top travel, airline, and weather apps — are still using an outdated mapping component that could put users and enterprises at risk. The investigation, titled “Follow the Map to Enterprise Risk: What’s Inside Popular Android Apps,” found that a legacy library known as libmapbox-gl.so, once part of Mapbox GL Native...

Mobile threats spike: Zimperium's holiday season report

Zimperium, the global pioneer in mobile security, released new research from its zLabs team revealing a sharp rise in mobile threats tied to the holiday shopping season. The Mobile Shopping Report: From Carts to Credentials highlights how cybercriminals are exploiting the seasonal surge in e-commerce and mobile app activity to target both consumers and enterprises. According to zLabs’ analysis, mishing (mobile phishing) remains the most widespread and effective mobile attack vector. Smis...

zLabs uncovers fantasy hub android RAT threat

zLabs researchers have uncovered Fantasy Hub, an Android Remote Access Trojan (RAT) sold on Russian-language channels as a Malware-as-a-Service (MaaS) subscription.  The spyware offers a full suite of espionage and device-control features, including SMS, contact, and call-log theft; live audio/video streaming; and fake banking windows designed to steal credentials. Unlike isolated malware kits, Fantasy Hub is a turnkey service complete with seller documentation, how-to videos, and a Teleg...

Zimperium highlights rising mobile bot threats

Zimperium, the world pioneer in mobile security, highlighted the growing threat of mobile bots operating inside trusted apps. These bots represent a new form of automation that bypasses traditional defences, such as CAPTCHAs, rate limits, and MFA, making them nearly impossible to distinguish from legitimate users and enabling fraud at scale. Unlike web-driven bots that flood networks with suspicious traffic, mobile bots run on the client side, inside the app itself. By exploiting APIs, ses...

Zimperium reveals surge in NFC relay malware

Zimperium zLabs published new findings showing a rapid, global increase in NFC relay malware that abuses Android’s Host Card Emulation (HCE) to harvest payment data and complete fraudulent “tap-to-pay” transactions. First observed in April 2024 as isolated samples, this campaign family has expanded to more than 760 malicious apps, leveraging 70+ command-and-control servers, dozens of Telegram bots/channels, and localised impersonation of banks and government services across R...

Zimperium uncovers ClayRat spyware shaking mobile security

Zimperium, the world's pioneer in mobile security, announced new research from its zLabs team exposing ClayRat, a rapidly expanding Android spyware campaign targeting Russian users. Disguised as popular apps, such as WhatsApp, TikTok, Google Photos, and YouTube, ClayRat steals sensitive information, including SMS, call logs, device data, and front-camera photos. New obfuscation layers While exploiting Android’s default SMS handler role to bypass security prompts While exploiting Androi...

Zimperium exposes VPN flaws - protect enterprise data

Zimperium, the pioneer in mobile security, releases new research from its zLabs team revealing alarming weaknesses in mobile Virtual Private Network (VPN) applications. While VPNs are marketed as essential privacy tools, Zimperium’s analysis of 800 free Android and iOS apps shows that many actually put users, and the enterprises they work for at greater risk. Among the findings: 25% of iOS VPN apps lacked a valid privacy manifest, violating Apple requirements and leaving users in the...

Zimperium's mobile security insights

Zimperium, the world pioneer in mobile security, is warning organisations about the growing risks posed by rooting and jailbreaking tools, which continue to expose mobile devices to severe security vulnerabilities. These tools, often developed by independent developers without proper security oversight, enable unauthorised access to mobile systems and can be exploited by cybercriminals. Zimperium’s research Zimperium’s research has highlighted how modern rooting frameworks, such...