siliconindia | | OCTOBER 202219By Sundar Balasubramanian, Managing Director - India & SAARC, Check Point Software TechnologiesWHY ARE CYBERCRIMINALS IN LOVE WITH YOUR MOBILE DEVICES?A survey carried out in the last year revealed that almost half (49 percent) of organizations worldwide are unable to detect an attack or breach on employee-owned devices. At a time when workforces across the world is increasingly dis-tributed, there's a genuine risk that the mobile arena could soon become the new corporate cyber security bat-tleground. From mobile spyware that can assume complete control of iOS and Android devices via zero-click exploits, to trojans deployed via ma-licious apps that can harvest users' credentials, organizations have never been more at risk from mobile threats. What is more, any notion that hybrid working, and a BYOD (bring your own device) culture were simply part of a temporary response to the COVID-19 pandemic can now also be laid to rest. In data published as recently as February 2022, Statista re-ported that 30 percent of the world's workforce now work exclusively from home. The same survey indicated that around 60 percent of companies are now actively facilitating hybrid working, giving their employees the freedom to choose where they log on. But how many of these organizations are fully prepared for the security de-mands of a truly mobile workforce?An organization in India is being attacked on average 1797 times per week in the last six months, compared to 1564 attacks per organization in APAC, as outlined in Check Point's Threat Intelligence report. Apart from this, in India, the average weekly im-pacted organizations by mobile mal-ware stood at 4.3 percent as compared to the APAC average of 2.6 percent. Far from being a coincidence, it's more likely that cyber criminals are simply taking advantage of the ex-panding mobile ecosystem that orga-nizations worldwide now occupy.THE EMERGING MOBILE THREATWe've seen some concerning devel-opments in the mobile threat land-scape throughout the past year. Our report referenced NSOs Pegasus, no-torious for its ability to gain full con-trol of iOS and Android devices via an elaborate zero-click exploit. NSO, the group responsible for the spyware, is currently one of the highest-pro-file vendors of `access-as-a-service' malware, selling packaged hacking solutions that enable affiliate threat actor groups to target mobile devices without the need for homegrown re-sources. In 2019, Pegasus was used to leverage WhatsApp and infect more than 1,400 user devices, from senior government officials to journalists and even human rights activists. More recently, in 2021, it was widely re-ported that Pegasus had been used to target the mobile devices of more than 50,000 devices around the world, in-cluding those of high-level business executives. Pegasus is noted for its so-phisticated infection and data exfiltra-tion capabilities, and as such we think it's likely to inspire similar malware threats. As mentioned in our report, a Macedonian-based group has already created the Predator spyware in Peg-asus' wake, designed to infect target devices via single-click links sent over WhatsApp.Both Pegasus and Predator are representative of a general shift to-ward social media and messaging apps to steal credentials and infiltrate corporate networks. In August 2021, an Android trojan known as FlyTrap was found to have compromised more With more than two decades of experience, Sundar is a seasoned and accomplished leader with diverse sales, business and partner leadership experience in the IT industry working with industry leaders like EMC/VMware, Microsoft and IBM.Sundar Balasubramanian, Managing DirectorCXOInSIGHTS
< Page 9 | Page 11 >