V-Key

V-Key

V-Key

Mobile Malware Landscape in 2024: Why App Security Is Critical for Businesses

 

Mobile malware attacks are rising as mobile banking, digital payments, and remote authentication become mainstream. In 2024, over 33.3 million mobile malware attacks were recorded globally, according to a report by a security firm, underscoring the urgent need for stronger mobile security. Another study found that Trojan banking malware attacks nearly tripled this year, surging by 196% worldwide. 

Cybercriminals are constantly refining their tactics, exploiting vulnerabilities in mobile devices to target industries such as banking, e-commerce, digital payments, and government services. The most prominent mobile malware threats in 2024 include: 

 

Banking Trojans 

Industries affected: Financial Services, Digital Banking, Fintech 

These malicious programs disguise themselves as legitimate banking apps, tricking users into entering their login credentials. Once infected, attackers can intercept transactions, steal funds, and even manipulate banking sessions in real time. With mobile banking adoption on the rise, banks, digital wallet providers, and financial services platforms remain prime targets. 

 

Spyware 

Industries affected: Government, Enterprises, Legal, Healthcare 
Operating silently in the background, spyware collects sensitive data such as keystrokes, GPS locations, call logs, and microphone recordings. In corporate environments, it enables espionage, stealing confidential business data or financial records. Governments handling classified information and enterprises managing trade secrets are especially vulnerable. 

 

Smishing (SMS Phishing) 

Industries affected: E-commerce, Telecommunications, Logistics, Banking 
Cybercriminals exploit users’ trust in text messages by sending fraudulent links disguised as official communication from banks, delivery services, or digital platforms. Clicking these links can expose credentials or install malware. The growing reliance on OTP-based authentication in banking and e-commerce increases exposure to these attacks. 

 

Malvertising (Malicious Advertising) 

Industries affected: Advertising, Media, Mobile Gaming, e-Commerce

Compromised online ads even on legitimate websites redirect users to infected pages that download malware. Since mobile users frequently engage with ads via apps and browsers, ad-tech companies and e-commerce platforms face increasing security challenges. 

 

Rogue Apps 

Industries affected: App Marketplaces, Fintech, Banking, Crypto 

Fraudulent applications often found in third-party app stores or mimicking legitimate ones trick users into installing malware. These apps request excessive permissions, allowing attackers to access sensitive data or deploy ransomware. Fintech and cryptocurrency platforms are frequent targets of fake apps designed to steal user funds. 

 

Mobile Security Risks Enabling These Threats 

Beyond malware itself, underlying security gaps provide cybercriminals with opportunities to compromise mobile environments. Businesses must address these vulnerabilities to prevent exploitation:  

  • Device Fragmentation: The diversity of operating systems and device manufacturers makes it difficult to enforce uniform security policies. 
  • Shadow IT: Employees using unauthorized mobile apps or personal devices for work increase exposure to unverified software and data leaks. 
  • Weak Endpoint Security: Mobile devices often lack the same level of security as desktops, making them easier targets for attackers. 
  • Man-in-the-Middle (MitM) Attacks: Cybercriminals exploit unsecured Wi-Fi networks to intercept communications and steal credentials. 
  • Rogue Applications: Fraudulent or cloned apps disguised as legitimate ones are a growing vector for malware infection. 

 

The Business Impact of Mobile Malware 

For enterprises, mobile malware can lead to severe financial, operational, and reputational damage: 

Impact Area  Description  Example Scenarios 
Financial Losses  Direct losses from fraud and breach-related expenses.  Refunds due to fraudulent transactions. 
Regulatory Fines  Penalties for non-compliance with data protection laws.  GDPR fines for compromised user data. 
Operational Disruption  Downtime caused by malware affecting critical systems.  Ransomware locking access to mobile applications. 
Customer Trust & Reputation  Loss of user confidence due to security incidents.  Customers switching to competitors with better security. 
Supply Chain Risks  Attackers targeting vendors and partners.  Compromised third-party app integrations. 

 

Beyond individual business impacts, some regions are experiencing higher attack rates due to increasing mobile adoption and evolving cybercriminal tactics. 

 

2024 Mobile Malware Incidents Across Key Regions 

Recent reports indicate that Vietnam, Indonesia, and Thailand are among the most affected in Southeast Asia, with millions of recorded on-device threats. These regions are seeing a rise in malware incidents due to increasing mobile payment adoption and evolving cybercriminal tactics. Australia and the United States have also reported significant increases in mobile-based cyberattacks, particularly targeting financial services and government sectors. 

 

Country  Number of On-Device Threats  Notes 
United States  783,000+  Significant rise in phishing and mobile malware attacks. 
Australia  1,100+ cybersecurity incidents  Surge in cyber threats, including mobile malware. Data breaches also increased, exposing 47 million records. 
Vietnam  10,531,086  Highest in Southeast Asia. 
Indonesia  7,954,823  Significant increase in threats. 
Thailand  2,650,007  Notable rise in incidents. 
Malaysia  1,965,270  Growing number of attacks. 
Philippines  687,567  Moderate threat level. 
Singapore  501,148  Lowest in the region. 

 

As mobile threats continue evolving, businesses must adopt stronger security measures to mitigate risks. 

 

Strengthening Mobile Security with V-Key’s Solutions 

Many mobile malware attacks exploit weak app security, allowing attackers to steal data, inject malicious code, or manipulate transactions. These vulnerabilities put user privacy and business operations at risk if left unaddressed. 

V-Key fortifies mobile applications, APIs, and digital identity with V-OS, our patented Virtual Secure Element, ensuring protection against malware, unauthorized access, and credential theft. The chart below highlights common mobile security weaknesses and how V-Key solutions mitigates them. 

 

Mobile App Vulnerability  Challenges  V-Key Solution 
Weak or No App Integrity Protection  Apps are vulnerable to reverse engineering, modification, and injection of malicious code.  V-OS Mobile App Protection provides code obfuscation, anti-tampering, and runtime self-protection (RASP) to prevent unauthorized modifications and malware injections. 
Unsecured APIs  Attackers exploit weak API security to access sensitive data, manipulate transactions, or bypass authentication.  V-OS App Identity secures API communications with mutual authentication, dynamic encryption, and cryptographic tokenization, ensuring only legitimate requests are processed. 
Inadequate Data Encryption  Storing sensitive data in plaintext or using weak encryption makes it easier for attackers to extract confidential information.  V-OS Virtual Secure Element provides hardware-grade encryption and secure storage for credentials, cryptographic keys, and sensitive data. 
Lack of Secure App Updates  Apps without secure update mechanisms are vulnerable to version rollback attacks, where attackers exploit outdated versions.  V-OS Mobile App Protection ensures only authorized app updates are installed and prevents attackers from forcing older, vulnerable versions. 
Compromised Digital Identity Credentials  Weak app security exposes stored credentials, allowing attackers to hijack user identities and gain unauthorized access.  V-Key ID enables passwordless authentication with cryptographic key-based authentication, reducing reliance on static credentials and mitigating credential theft risks. 
Keylogging to capture user information  Compromised keyboard captures the keystroke which may contain sensitive information  V-OS Mobile App Protection provides secure keyboard effectively protect users from keylogging attacks 
Unauthorized screen recording  Malicious application shares the mobile phone screen to expose all sensitive information to the remote attacker  V-OS Mobile App Protection detects unauthorized screen capturing to prevent remote sniffing of sensitive information 

 

As mobile threats continue to grow in scale and sophistication, businesses must take a proactive approach to securing their applications and digital ecosystems. Reactive security measures are no longer enough—organizations need robust, built-in protections that defend against evolving attack tactics without compromising user experience or operational efficiency. 

V-Key’s advanced security solutions empower businesses to stay ahead of cybercriminals, ensuring secure mobile transactions, seamless authentication, and protection against malware-driven fraud. By integrating V-OS, our patented Virtual Secure Element, organizations can enhance their security posture, meet regulatory requirements, and build lasting trust with users as cyber threats continue to evolve. 

 

[References: Wired, Kaspersky, News AU, The Australian, Nation Thailand, Business Today, GBHackers, Lookout, Cyber Security Australia, Cyber Daily] 

 

BSSN Common Criteria Compliance for Stronger Security

BSSN Common Criteria Compliance for Stronger Security

Indonesia’s digital economy is expanding rapidly, with financial services, telecoms, and government agencies increasingly reliant on secure digital platforms. To…
Securing Banking Through APRA Compliance with V-Key

Securing Banking Through APRA Compliance with V-Key

In Australia’s financial services sector, regulatory compliance is inseparable from trust and resilience. The Australian Prudential Regulation Authority (APRA) plays…
V-Key at COBA 2025: Strengthening Digital Identity and Compliance in Australia

V-Key at COBA 2025: Strengthening Digital Identity and Compliance in Australia

AUGUST, 2025 — The COBA 2025 Conference once again proved to be the premier gathering for Australia’s customer-owned banking sector.…

Shield in Minutes and Keep Your Mobile App Fast and Secure

Mobile apps have become the primary gateway for users to browse, purchase, book, track, earn rewards, and engage in real…

Modern Authentication in ANZ: Finding the Balance Between Security and User Experience

In Australia and New Zealand, authentication has reached a turning point.  Banking apps, telco platforms, superannuation portals, and digital health…

How to Choose the Right Authenticator

Authentication is essential for ensuring that only authorized individuals gain access while keeping unauthorized users out.

Navigating Business, Technology and Trust: V-Key at AIBP Malaysia 2025

The AIBP Conference & Exhibition 2025 in Kuala Lumpur brought together decision-makers from across the financial services, enterprise, and technology…
V-Key Expands to Japan, Enhancing Mobile App and Digital Identity Security

V-Key Expands to Japan, Enhancing Mobile App and Digital Identity Security

2025 June — V-Key is expanding into Japan, bringing trusted digital identity and mobile app protection to one of the…
Built for RMiT, Securing Malaysia’s Financial Future with V-Key

Built for RMiT, Securing Malaysia’s Financial Future with V-Key

More than just a requirement, compliance is what helps businesses stay strong and keep customer trust intact. This is especially…
How V-Key ID Enhances Banking Security

How V-Key ID Enhances Banking Security

In Australia’s highly regulated financial environment, robust digital identity and authentication controls aren’t just best practice, they’re a compliance imperative.…
Why Developers Shouldn’t Have to Choose Between Speed and Security

Why Developers Shouldn’t Have to Choose Between Speed and Security

Mobile development moves fast. There are always new features to launch, bugs to fix, and deadlines to meet—and developers are…
The Real Cost of Mobile App Breaches and How to Stay Ahead of Threats

The Real Cost of Mobile App Breaches and How to Stay Ahead of Threats

Mobile apps have become the primary engagement channel for modern businesses. Whether it’s a healthcare portal, an e-commerce platform, a…
The Fake SMS That Looks Real

The Fake SMS That Looks Real

Why Indonesia needs to talk about digital trust—now.  It usually begins with a simple SMS. You’re going about your day,…
Building Digital Trust with V-Key at the State Bank of Vietnam Event 

Building Digital Trust with V-Key at the State Bank of Vietnam Event 

2025 April, Vietnam –  V-Key had the privilege of participating in the State Bank of Vietnam (SBV) CIO Roundtable event…
Journey to  Passwordless Authentication

Journey to Passwordless Authentication

Is it the Beginning of the End of Passwords?  In the wake of cyber-attacks at some of the biggest Superannuation…
Vietnam’s New Digital Security Regulations: Strengthening Mobile and Biometric Protections

Vietnam’s New Digital Security Regulations: Strengthening Mobile and Biometric Protections

Vietnam is rapidly enhancing its digital security landscape. In just the past six months, two major regulations—Decision 2345 (effective July…
Strengthening Australia’s Digital Identity Future 

Strengthening Australia’s Digital Identity Future 

Australia is making significant progress in digital identity adoption, with the federal government leading efforts through its national Digital ID…
Beyond OTPs: The Shift to Passwordless Authentication in Banking

Beyond OTPs: The Shift to Passwordless Authentication in Banking

The Bangko Sentral ng Pilipinas (BSP) is considering phasing out one-time passwords (OTPs) for digital banking transactions, citing the growing…
V-Key Continues to Expand in Australia to Strengthen Digital Identity and Authentication

V-Key Continues to Expand in Australia to Strengthen Digital Identity and Authentication

V-Key strengthens its presence in Australia by participating in the FIDO Alliance events in Melbourne, reinforcing its commitment to digital…
Why Passwordless Authentication is the Future of Security

Why Passwordless Authentication is the Future of Security

Managing passwords can be challenging. They can be difficult to remember, and often, people reuse them across multiple sites, which…
Protect Your Business All Year with V-Key ID and FIDO2

Protect Your Business All Year with V-Key ID and FIDO2

Lunar New Year is a time for celebration for many people around the world, but it’s also a good opportunity…
V-Key’s 2024 Journey in Advancing Digital Security and Empowering Seamless Digital Experiences

V-Key’s 2024 Journey in Advancing Digital Security and Empowering Seamless Digital Experiences

As we reflect on 2024, V-Key is proud of the milestones we’ve achieved and the innovations we’ve introduced in the…
5 Simple and Effective Ways to Secure Your Mobile App with V-OS App Shield

5 Simple and Effective Ways to Secure Your Mobile App with V-OS App Shield

For businesses, especially those handling sensitive data or financial transactions, ensuring app security is no longer optional. The risk is…
Securing Mobile Apps and Why It’s Critical for Businesses

Securing Mobile Apps and Why It’s Critical for Businesses

Mobile devices continue to become indispensable, with the average smartphone user spending around 88% of their day interacting with apps.…
Introducing V-OS App Shield: Connect, Deploy and Protect your App in Minutes

Introducing V-OS App Shield: Connect, Deploy and Protect your App in Minutes

Mobile applications are key to daily business operations, customer engagement, and overall functionality. According to Google, the average smartphone user…
V-Key partners with Bridge Alliance to build a Safer Digital Ecosystem

V-Key partners with Bridge Alliance to build a Safer Digital Ecosystem

V-Key, renowned for its advanced security solutions has proudly joined Bridge Alliance as their technology Partner,  solidifying their commitment to…
Making 2FA/MFA robust against smishing and related attacks

Making 2FA/MFA robust against smishing and related attacks

2FA/MFA was introduced to make it harder for attackers, by requiring two or more proofs of identity – also known…
How do we determine the effectiveness of mobile apps’ security systems?

How do we determine the effectiveness of mobile apps’ security systems?

With the spate of remote working regime due to Coronavirus pandemic, the reliance and growth for video conferencing platform has…
Is the detection of jailbroken/rooted phone sufficient against threats?

Is the detection of jailbroken/rooted phone sufficient against threats?

Functions that detect jailbroken/rooted devices are most commonly added to transactional mobile applications, serving as the most basic defense against…
Three steps to fight the Mobile Security status quo

Three steps to fight the Mobile Security status quo

Have financial institutions accepted a status quo that sacrifices user experience for increased security? With mobile digital identity quickly becoming…
V-OS Protection against Android Plugin malware

V-OS Protection against Android Plugin malware

There has been a recent surge in Android malware abusing Android Plugin Frameworks for malicious behavior. DroidPlugin, Parallel Space and…

V-OS Protection against CPU vulnerabilities

Virtually every computing device in the world is made unsafe by the latest disclosures on Central Processing Unit (CPU) vulnerabilities.…
The next wave of Finance: Singapore’s growing Fintech market

The next wave of Finance: Singapore’s growing Fintech market

With global cumulative investment in financial technology (fintech) forecast to exceed US$150 billion in three to five years, economies around…
Infographic: The next frontier in Banking transformation

Infographic: The next frontier in Banking transformation

As technology evolves, banks and financial institutions have no choice but to innovate. However, when it comes to security, many…
Is software-based Biometrics Authentication the solution to ASEAN’s regulatory challenges?

Is software-based Biometrics Authentication the solution to ASEAN’s regulatory challenges?

Banks in Southeast Asia should look towards software-based biometrics as the way forward to navigate the regulatory differences in the…
How does a Virtual Smart card protect a customer if they lose or change their mobile phone?

How does a Virtual Smart card protect a customer if they lose or change their mobile phone?

From banks to government agencies, many organisations are intrigued by and exploring software security solutions such as mobile tokens and…
Building V-OS with HSM

Building V-OS with HSM

V-OS is the world’s first virtual secure element, a software solution with security built into the firmware code. These include…
Cryptography in V-OS

Cryptography in V-OS

V-OS is the world’s first virtual secure element. Cryptography plays a dual-role in these; to secure and manage the secrets…

Why Existing Mobile Software Protections are Insufficient

Recognizing that existing mobile software protections are insufficient against today’s cyber threat landscape, we take a closer look at the main…
Mobile Security that works for everyone

Mobile Security that works for everyone

Safe, convenient and simple.