Zimperium has issued a stark warning to organizations around the world: mobile-based credential theft is accelerating, and the wave is far from over.
Looking back over the past year, Zimperium’s global telemetry revealed more than 2,400 variants of mobile malware specifically engineered to steal login credentials and intercept multi-factor authentication (MFA) codes. These attacks are powered by mishing (mobile-focused phishing) campaigns and sideloaded apps that silently harvest access keys from the very devices employees rely on every day.
Massive breaches are no longer starting on desktops, they’re starting in your pocket. What we saw last year is only the beginning. Organizations must take mobile security seriously to stop credential-stealing malware before it compromises enterprise resources
Nicolás Chiaraviglio, Chief Scientist at Zimperium
Key trends from the past year:
- Credential theft was tied to 16% of cyberattacks in 2024, up from 10% in 2023.
- Attacks spread through mishing campaigns and sideloaded apps, often disguised as legitimate tools.
- Major hotspots include Southeast Asia, but detections are global in scope.
- Targeted industries are finance, retail, and software, where stolen credentials have immediate value.
The rise in mobile credential theft in 2024 is not an isolated spike; it signals a fundamental shift in how attackers operate. As mobile usage in the workforce continues to climb, these threats will only multiply, says Zimperium.






