Mobile devices are facing a growing number of threats, particularly from bot attacks. The surge in mobile usage has led to an increase in cyberattacks that exploit vulnerabilities specific to mobile operating systems. These attacks use tactics like malicious apps, app-based vulnerabilities, and SMS messages.
Mobile attacks aim to compromise data, track user activities, or gain unauthorized access to sensitive information on mobile devices. As technology evolves, the distinction between mobile and traditional computing capabilities is blurring. But recognizing the impact of mobile attacks on digital businesses and their customers is crucial, especially given the vital role mobile devices play in digital transactions and interactions.
The rich data pulled from our recent industry report, Bot Abuse Analysis and Other Fraud Benchmarks, reveals the growing prevalence and sophistication of mobile cyber threats. Insights are drawn from the Arkose Labs Global Intelligence Network, which includes major corporations and category leaders. These organizations, highly susceptible to online threats, offer a distinctive vantage point for the observation and analysis of cyber activities. The information underscores the growing importance of addressing mobile security and the need for robust bot security to safeguard digital enterprises and consumers.
Global Threat Intelligence on Mobile Bot Attacks
According to our research, the threat landscape for bot attacks has witnessed a significant surge on mobile devices, marking a 106% increase in all attacks originating from these platforms. Mobile devices have become a primary target, representing 44% of all bot attacks. Fraud farm attacks on mobile devices have seen a notable increase of 63%, which highlights the vulnerability of these platforms to criminal activities.

Simultaneously, the prevalence of intelligent bot attacks has skyrocketed by over 3000%, demonstrating an alarming trend of cybercriminals exploiting vulnerabilities inherent in mobile operating systems. While 56% of bot attacks still occur on PCs or laptops, the substantial rise in mobile-centric attacks calls for heightened vigilance and tailored defense strategies.

The Geographics of Mobile Bot Attacks
Mobile threats often originate from regions where mobile devices are more widespread than laptops, creating large segments of the population with smartphones but no personal computers. As a result, the widespread use of mobile devices makes it easier for attackers to blend in with regular users, creating a disguise that helps them go unnoticed.
The impact of mobile threats extends beyond just the prevalence of these devices; it also raises concerns about the potential for large-scale cyber incidents and their socio-economic consequences. With the majority of the population relying heavily on smartphones for various daily activities, from communication to financial transactions, the vulnerability of these devices amplifies the potential fallout from successful cyber attacks. Just last year, it was reported that 43% of all compromised mobile devices were fully exploited, not just jailbroken or rooted, an increase of 187% YOY.
How does a mobile attack work?
In a mobile banking scenario, an employee unwittingly downloads a seemingly harmless app that contains malicious code. Once installed, the app breaches the smartphone's security, granting unauthorized access to sensitive financial data. The attacker then exploits this information in a phishing campaign, tricking customers into revealing login credentials. As a result, unauthorized access to customer accounts leads to fraudulent transactions, causing financial losses, reputational damage, and regulatory scrutiny.
Top 5 Mobile Attack Types
Based on our threat analysis, five prominent attack types stand out, each posing distinct challenges and risks. From in-product abuse to payment fraud, these threats demand a closer look at the strategies cybercriminals are now using to target the mobile landscape.


- For businesses, fake account creation can lead to skewed user metrics, diminished user trust, and increased operational costs for managing and verifying accounts. Additionally, fake accounts can be used to manipulate reviews, ratings, or engagement metrics, influencing the perceived credibility of a platform. According to our analysis, in Q2 2023, there was a 202% increase in bots trying to take over accounts in financial institutions, and a 164% jump in bots attempting to create fake new bank accounts.

- As one of the top four attack types, fake account creation affects businesses and customers in myriad ways. Scams, phishing attempts, or deceptive information spread by malicious actors using fake accounts are some examples. The presence of fake accounts can also compromise the overall user experience, as they may interact with bogus profiles, thereby impacting the integrity of online communities.


- For businesses, ATO can lead to financial losses, reputational damage, and legal consequences. Cybercriminals may exploit the compromised accounts to perform fraudulent transactions, access proprietary information, or disrupt business operations. The trust and credibility of the business may be compromised, resulting in a loss of customer confidence.Customers, on the other hand, face risks such as unauthorized access to personal information, financial losses, and potential identity theft. ATO attacks can undermine the trust users place in digital platforms and lead to a negative user experience.






