PC-forged malware swamps iOS and Android
Intel Security reveals scale and scope of malware targeting mobile devices


Wearables, smartphones and tablets are facing an ever increasing barrage of security threats, according to Intel Security's annual Mobile Threat Report.
Intel identified several vectors of attack that have moved from the desktop to the mobile world, including bank fraud, ransomware and remote access tools (RATs), which are all on the rise, according to the report.
It also found a marked difference in the way iOS and Android are each targeted via their app stores. While the biggest threat to iOS devices was from apps with "overly aggressive" adware, Android is still largely the victim of malicious apps.
The report also pointed out that, for Android users, it can be difficult to follow the mantra of updating to the latest version of an OS as soon as it is released, because each handset vendor rolls out updates on their own time schedule.
However, Intel did say that both Apple and Google are quick to remove malicious apps from their respective app stores once identified.
It is not just malware that has evolved from PCs that is now targeting mobile device users, however. More traditional SMS phishing scams continue to persist, directing users to crafted web pages that can encourage users to enter personal information, allowing cyber criminals to steal this data or infect it with malware.
The report also highlights the new attack surfaces presented by the Internet of Things (IoT), which include wearables and domestic devices like smart TVs and fridges.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
From the perspective of wearables, cyber criminals could potentially use these as a gateway to access smartphones, while TVs with built-in microphones and cameras could have these features accessed remotely by hackers, allowing them to spy on the devices' owners.
Raj Samani, EMEA CTO of Intel Security, told IT Pro: "We're not trying to scare people, we're trying to make them aware that it is serious."
Individuals should be doing their own "due diligence" when buying devices and asking what security measures are in place, said Samani. He added, though, that there is "no excuse for companies to do nothing" anymore.

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Nvidia hails ‘another leap in the frontier of AI computing’ with Rubin GPU launch
News Set for general release in 2026, Rubin is here to solve the challenge of AI inference at scale
-
Tesco is taking Broadcom to court – here’s why
News The retailer is demanding £100 million in compensation following VMware pricing and licensing changes
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos
-
Google cyber researchers were tracking the ShinyHunters group’s Salesforce attacks – then realized they’d also fallen victim
News In an update to an investigation on the ShinyHunters group, Google revealed it had also been affected