Sanitise your phone

Issue 4 2021 Information Security

Imagine if your mobile phone could be used to spy on you, listen to your conversations and send information and images from your device to a third party?


Anna Collard.

This is not an imagined, dystopian future, it is the story of the Pegasus spyware put on mobile devices by clients of Israeli spyware software firm NSO. Although the Pegasus spyware is meant to be used by law enforcement only and is targeted at high-value individuals, this story provides some food for thought as, according to Anna Collard, SVP Content Strategy and Evangelist at KnowBe4 Africa, mobile malware and spyware are not only aimed at the wealthy and the important – they can have a serious impact on anyone’s life.

[Readers can find out about another company doing similar ‘work’ in the article Hooking Candiru: Another Mercenary Spyware Vendor Comes into Focus -Ed.]

“Other mobile threats such as banking malware, for example, use a similar process to the Pegasus spyware to get to users’ devices. “For example, many of these types of malware get installed by people clicking on a link that they received via SMS or WhatsApp and end up downloading a malicious app that could result in advertising click fraud, mobile ransomware, banking trojans or in some cases, even roots or jailbreaks their phone to obtain full remote control over the device. The malware then allows for the criminals to listen to calls, take screenshots and see what the user types – catching passwords and banking details.”

Criminals use social engineering tools and approaches to lull users into a false sense of security. Pretending to be anything from a parcel tracking link to a banking confirmation link, these malware messages are designed to provoke people to make impulsive mistakes. And these mistakes can lead to your device being completely compromised, putting you and your financial security at risk.

“These smart malware infiltrations are designed to get past people’s defences,” says Collard. “Another form of distribution is taking advantage of devices that have not been updated or exploiting vulnerabilities on the phone or in apps that do not yet have patches. It is really important to ensure that your mobile devices are updated, and to ensure that you minimise risk by removing unnecessary apps, only downloading apps from official apps stores and by avoiding clicking on suspicious links from your mobile device.”

“Unfortunately, people are more likely to click on a link using their mobile device because they think they are safer than a computer. You need to be cautious and ensure that if you do not know the sender, you do not download anything or click on anything. Do not believe an SMS message that tells you to update your WhatsApp software or a link that tells you to update an app that comes through a social media platform.

“Always update from the App Store or Google Play.” Also, be aware of clickjacking, which is a form of mobile phishing that comes with an invisible link, which is covered by a ‘bothersome’ graphic element that is made to look like a small hair or a speck of dust. This tricks the user into wiping the hair or dust off the mobile’s screen, which activates the link and launches a connection to the phishing site.

Keeping your mobile device free from infection means that you watch what you click, you do not trust unexpected links from unknown sources, do not share information with anyone – especially if they call and pretend they are from your mobile phone provider or bank – and do not provide people with your OTPs unless you have initiated the transaction with a trusted agent yourself. Mobile devices are as much at risk as computers, so stay aware, stay alert and stay secure.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Cybersecurity in South Africa
Information Security
According to the Allianz Risk Barometer 2025, cyber incidents, including ransomware attacks, data breaches and IT outages, are now the top global business risk, marking their fourth year at the top.

Read more...
Are AI agents a game-changer?
Information Security
While AI-powered chatbots have been around for a while, AI agents go beyond simple assistants, functioning as self-learning digital operatives that plan, execute, and adapt in real time. These advancements do not just enhance cybercriminal tactics, they may fundamentally change the battlefield.

Read more...
Disaster recovery vs cyber recovery
Information Security
Disaster recovery centres on restoring IT operations following events like natural disasters, hardware failures or accidents, while cyber recovery is specifically tailored to address intentional cyberthreats such as ransomware and data breaches.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
The deepfake crisis is here and now
Information Security Training & Education
Deepfakes are a growing cybersecurity threat that blur the line between reality and fiction. These AI-generated synthetic media have evolved from technological curiosities to sophisticated weapons of digital deception, costing companies upwards of $600 000 each.

Read more...
What does Agentic AI mean for cybersecurity?
Information Security AI & Data Analytics
AI agents will change how we work by scheduling meetings on our behalf and even managing supply chain items. However, without adequate protection, they become soft targets for criminals.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...