7 Aug 2025

Zimperium, the global pioneer in mobile security, issued a stark warning to organisations worldwide: mobile-based credential theft is accelerating, and the wave is far from over. 

Looking back over the past year, Zimperium’s global telemetry revealed more than 2,400 variants of mobile malware specifically engineered to steal login credentials and intercept multi-factor authentication (MFA) codes. These attacks are powered by mishing (mobile focused phishing) campaigns and sideloaded apps that silently harvest access keys from the very devices employees rely on every day.