cyber security 18 MICA MESSENGER the primary vulnerability, new attacks are more likely to target you by SMS or messaging app. This shift follows increased nervousness when opening attachments or clicking links in email. All made worse by AI advances, that make it even harder to detect a threat on a small screen before tapping. Not only does SMS carry text-based phishing risks, but it’s also vulnerable to on-device malware hijacking 2FA codes in real time. The U.S. government warns users to stop using SMS codes for 2FA, and in recent days we have seen SMS codes intercepted to hijack Gmail and Outlook accounts. Zimperium highlights “SMS Stealer” malware, that is now “compromising accounts on more than 600 global services.” The FBI, meanwhile, has warned users to delete all smishing texts given the alarming ramp-up in SMS attacks mimicking brands and local government agencies. As we have seen with recent FBI and police warnings into toll and disaster relief fraud, the ease of masking a sender ID, using brief text and a shortened link to mask a non- typical URL makes it all too easy to lure a user into clicking. Zimperium also notes the geographical targeting of mobile attacks, again as seen with fake toll messages focusing on specific cities and states. “Modern mishing campaigns frequently employ geolocation-based redirection at country or even at the city level, allowing for highly targeted attacks. This enables precise targeting of specific regions or organizations, complicates detection by security The FBI, meanwhile, has warned users to delete all smishing texts given the alarming ramp-up in SMS attacks mimicking brands and local government agencies.
View this content as a flipbook by clicking here.