Zimperium has released new findings highlighting how agentic AI is facilitating the development and proliferation of sophisticated mobile app attacks. Capable of planning and executing tasks autonomously, agentic AI systems can learn from failures and refine their strategies until goals are achieved.
In the realm of mobile security, these AI capabilities enable threat actors to automate complex tasks such as analysing app defences, bypassing security controls, and scaling successful attacks across multiple devices more efficiently.
Impact on mobile security
Agentic AI is changing the landscape of mobile attacks, turning sophisticated operations into repeatable processes that can be launched using simple, natural-language commands. According to Pat Shueh, VP of Product Management, MAPS, at Zimperium, “The concern is not that AI has created an entirely new vulnerability class. It has removed many of the technical barriers that once limited who could execute these attacks and how quickly they could scale.”
The adoption of agentic AI frameworks could potentially offer attackers increased autonomy and speed
The recent investigation by Zimperium into RatHat, an AI-driven mobile malware targeting credentials and financial accounts, illustrates the growing integration of AI into the mobile threat landscape. The adoption of agentic AI frameworks could potentially offer attackers increased autonomy and speed.
Agentic AI frameworks in action
When an agent identifies an effective attack path, it can convert this process into a script for deployment across numerous devices or emulators. This capability allows the attack to be adjusted and renewed when applications change, cutting down the cost and effort needed to sustain mobile fraud activities.
This evolution in attack methods necessitates robust mobile app security that can endure both static and dynamic assessments, as well as tampering and modification during runtime. Organisations are urged to strengthen the protection of their apps across the entire lifecycle, from initial development and distribution through to execution on end-user devices.
