Mobile targeted phishing — called mishing — is becoming better understood for the sophisticated threat environment it creates for businesses, according to a new report from Zimperium, “zLabs Mishing Report: The Evolution of Mobile-Specific Phishing Attack.”

The report said there is evidence that attackers are shifting to a “mobile-first” strategy to penetrate corporate networks and obtain sensitive data. Zimperium said its research emphasizes the “urgent need” for organizations to implement mobile-specific security tactics.

The pairing of social engineering with mobile devices is the attack vector drawing cybercriminals to launch mobile attacks. Mishing exploits mobile platform-specific features, vulnerabilities, and user behavior, the report said, which makes mobile attacks more difficult to detect and analyze than desktop or laptop phishing.

Mishing campaigns go beyond banking fraud, deploying malware that hijacks OTPs, mimics interfaces, and steals enterprise credentials. A notable case is zLabs’ discovery of an Android-targeted SMS stealer, spreading 100,000 malware samples across 113 countries. Attackers use misleading ads and Telegram bots to fool users into installing apps that capture SMS messages, compromising accounts on more than 600 services globally.

“Mishing is not just an evolution of traditional mobile phishing tactics — it is an entirely new category of attack engineered to exploit the specific capabilities and vulnerabilities of mobile devices, such as cameras,” said Zimperium Chief Scientist Nico Chiaraviglio.

“Our research shows that attackers are increasingly leveraging multiple mobile-specific channels — including SMS, email, QR codes, and voice phishing (vishing) — to exploit user behaviors and expand their attack surface.”

The report detailed an alphabet soup of labels for the primary attack vectors in the mobile environment:

Mobile-targeted email phishing: A standard email attack that only executes from a mobile device.
Smishing: A targeted phishing attack that is delivered by text/SMS.
Quishing: Using QR codes, which obfuscate the destination.
Vishing: Voice call-based phishing attacks using social engineering through phone communication to manipulate targets into taking unsafe actions, such as clicking on an SMS link or divulging sensitive information such as credentials or OTP codes

Smishing was found by Zimperium’s research to be the most common mobile phishing vector. As many as 16% of smishing attacks globally occur within the U.S.

Mishing activity peaked in August 2024, when there were more than 1,000 daily attack records, the research showed.

The mishing report acknowledged “a continuous evolution in attack sophistication and scale” and said organizations must evolve their security frameworks — specifically, by continuing to update their mobile-specific security controls — to address the threats.