How Spyware Can Hide in Everyday Mobile Apps
Question: Zimperium’s 2026 Global Mobile Threat Report says spyware is now present on nearly 1 in 10 devices. It also says that mobile phishing events detected on employee devices increased 380% since January 2025. How can employees detect and remove spyware from their devices? Can employees and security teams work together on this concern without exposing the employee’s private data?
Krishna Vishnubhotla, Vice President, Product Strategy at Zimperium
Nearly 1 in 10 mobile devices now carries spyware. Employees aren't seeking it out. Nobody downloads something labeled malicious. They download a flashlight app, a PDF converter, a QR scanner, something that solves a five-second annoyance. The app does exactly what it promises on the surface. Whatever it's doing underneath, reading contacts, tracking location, harvesting credentials, runs invisibly, unrelated to the advertised function. That's exactly why it works.
Security teams spend most of their phishing budget on email gateways and inbox simulations. That's no longer the most vulnerable entry point, mobile is. Most mobile phishing arrives through SMS, personal email, messaging apps, and social platforms, channels security teams can't see and usually can't touch.
Security teams are watching the front door while the side windows stay wide open. Industry research shows text and voice phishing get 40% more clicks and are more effective than email phishing.
Simulation programs are mature for email, nearly nonexistent for SMS and messaging apps. And even where they exist, they train people to spot old tells, bad grammar, awkward phrasing, that AI-generated phishing no longer has. The message reads clean and personalized. Simulations still help. They're just not enough anymore.
What should change immediately: Give employees a way to check a personal app's actual behavior before they install it, since spyware most often arrives disguised as a utility app. Require security teams to vet work apps for hidden permissions and exploitable weaknesses before pushing them to the fleet. And extend phishing detection beyond email to SMS, messaging, and social apps, where most mobile phishing actually happens now.




