cyber security
18
MICA MESSENGER
the primary vulnerability, new attacks 
are more likely to target you by SMS 
or messaging app. This shift follows 
increased nervousness when opening 
attachments or clicking links in email. 
All made worse by AI advances, that 
make it even harder to detect a threat 
on a small screen before tapping.
Not only does SMS carry text-based 
phishing risks, but it’s also vulnerable to 
on-device malware hijacking 2FA codes 
in real time. The U.S. government warns 
users to stop using SMS codes for 2FA, 
and in recent days we have seen SMS 
codes intercepted to hijack Gmail and 
Outlook accounts. Zimperium highlights 
“SMS Stealer” malware, that is now 
“compromising accounts on more than 
600 global services.”
The FBI, meanwhile, has warned 
users to delete all smishing texts 
given the alarming ramp-up in SMS 
attacks mimicking brands and local 
government agencies. As we have seen 
with recent FBI and police warnings 
into toll and disaster relief fraud, the 
ease of masking a sender ID, using brief 
text and a shortened link to mask a non-
typical URL makes it all too easy to lure 
a user into clicking.
Zimperium also notes the geographical 
targeting of mobile attacks, again as 
seen with fake toll messages focusing 
on specific cities and states. “Modern 
mishing campaigns frequently employ 
geolocation-based redirection at 
country or even at the city level, 
allowing for highly targeted attacks. 
This enables precise targeting of 
specific regions or organizations, 
complicates detection by security 
The FBI, meanwhile, has 
warned users to delete 
all smishing 
texts given 
the alarming 
ramp-up in SMS attacks 
mimicking brands 
and local government 
agencies.

View this content as a flipbook by clicking here.