
3 September 2026
Why Mobile Security Is the Weakest Link for Southeast Asian Enterprises

Every other layer of the enterprise got hardened over the last decade. Endpoints are monitored, networks are segmented, email is filtered. Mobile didn’t get the same treatment, and that gap is now the one attackers are walking through.
Zimperium’s 2026 Global Mobile Threat Report puts numbers behind what many security teams have suspected for a while. Mobile is not one attack surface, it’s four. The operating system, the apps, the network a device connects to, and the person holding it. None of these four stay still. New apps get installed daily. New WiFi networks get joined without a second thought. Updates get pushed overnight and ignored for days or weeks.
In this article, we break down what the report found, why it matters for enterprises across Malaysia and Southeast Asia specifically, and what CISOs, CTOs and CEOs should be asking their security teams this quarter.
Executive Summary
- Employees now use an average of nine work apps daily, and 46% of frontline workers in the US cannot complete their core job without a mobile device.
- Mobile devices hold the keys to identity and authentication, yet most live entirely outside the enterprise security perimeter.
- Zimperium’s zLabs detected over 2.5 million phishing attacks on employee devices in the last 12 months, with mobile phishing succeeding at a rate 40% higher than email.
- Riskware is now installed on more than 1 in 4 devices, and spyware on nearly 1 in 10, both up sharply year over year.
- Southeast Asia, including Malaysia, is already flagged by Zimperium as one of the regions seeing the highest mobile malware volumes globally.
- Mobile malware-driven fraud is now a mature criminal industry, with 34 active malware families tracked targeting more than 1,200 financial brands across 90 countries.
Why Mobile Is Different From Every Other Attack Surface
A laptop gets patched by IT. A mobile device gets patched when the user feels like it, or not at all. A laptop connects to networks IT approves. A mobile device connects to whatever WiFi is nearest, home, café, hotel lobby, without anyone asking permission.
That difference matters because mobile devices are also where identity lives. Authentication apps, one-time passcodes, corporate email, single sign on, all of it increasingly routes through a phone. Compromise the phone, and you don’t just lose a device, you lose the thing that was supposed to prove who someone is.
The Four Fronts Attackers Are Already Exploiting
Mishing (Mobile Phishing)
Zimperium’s zLabs detected over 2.5 million phishing attacks on employee mobile devices in the past 12 months. Phishing events on employee devices grew 380% since January 2025, and mobile phishing already succeeds 40% more often than the same attack delivered by email. AI is a large part of why: 86% of phishing campaigns are now AI-generated, producing content estimated to be 4.5 times more convincing than anything written by a person.
Malware
Riskware, apps with broad permissions and weak data handling, is now installed on more than 1 in 4 devices, nearly three times higher than a year ago. Spyware sits on nearly 1 in 10 devices, up over 4x year over year, and is now sold commercially by more than 500 vendor entities worldwide. This is no longer a niche capability aimed at high-value targets. Google’s Threat Intelligence Group found that in 2025, more zero day exploits were attributed to commercial spyware vendors than to traditional nation state groups for the first time. It’s a supplied, commercialised product reaching ordinary employee devices.
Shadow AI
A growing share of employees are using AI tools on corporate devices, often through personal accounts the enterprise cannot see. We cover this in detail in a separate article, but it’s worth flagging here because it’s part of the same underlying problem: visibility. If your team can’t see it, your team can’t govern it.
Vulnerable Business Apps
Even the apps your organisation formally approved carry risk. Zimperium’s assessment of top business apps found that 63% of Android and 52% of iOS business apps make network connections without proper encryption or certificate validation, meaning they may send data over plain HTTP or accept invalid certificates without complaint. A meaningful share also leak personally identifiable information or call APIs hosted in sanctioned or trade restricted countries.

What This Means for Malaysia and Southeast Asia
Zimperium’s own regional threat data has separately named Malaysia, Vietnam and the Philippines among the highest mobile malware infection regions globally. That’s not a coincidence. High mobile penetration, strong e-commerce adoption, and widespread BYOD culture across the region create exactly the conditions this report describes: a large, always connected, largely unmonitored device population sitting right next to enterprise data.
For Malaysian organisations, this isn’t a future problem to plan for. It’s a current gap most security programmes were never built to close, because mobile was never treated as seriously as the laptop or the server.
Fraud Has Already Moved Past Stealing Passwords
This isn’t a future risk. Zimperium’s own Mobile Banking Heist research tracked 34 active malware families already targeting more than 1,200 financial brands across 90 countries, sold as ready-made kits so fraudsters don’t even need technical skills to use them. Three families alone, TsarBot, CopyBara and Hook, were behind attacks on over 60% of the banking and fintech apps Zimperium analysed.
The bigger shift is what this malware does once it’s on a phone. It used to just steal a password. Now, with AI doing much of the work, it can copy a legitimate banking app, quietly work around common safeguards like one-time passcodes and biometric logins, and carry out the fraudulent transaction itself. The security measures most businesses already trust, MFA, biometrics, device checks, were built for an older kind of threat. This one gets around them from inside the device, which is exactly why it’s so hard to catch with the tools most organisations already have.
Malware That Changes Faster Than Defences Can Keep Up
Traditional antivirus and security tools work by recognising known threats, like matching a fingerprint. The problem is that today’s malware doesn’t keep the same fingerprint. Zimperium’s report highlights real examples already in use: one campaign uses AI to rewrite its own code every single time it runs, so no two infections look alike. Another is described as the first ransomware built almost entirely by AI, with no human developer involved at any stage.
Zimperium also points to Verizon’s 2026 Data Breach Investigations Report, which found that the typical attacker now uses AI across 15 different attack techniques, and some use as many as 50. In short, the tools built to catch “known bad” threats are struggling against threats that never look the same way twice. Staying protected now means watching for suspicious behaviour as it happens, not just checking against a list of known dangers.
What a CISO Should Be Asking This Quarter
- Do we have any visibility into personal apps installed on BYOD devices that also access corporate email or systems
- If a business app we approved a year ago quietly added an AI feature since then, would we know?
- Are we treating mobile with the same rigour as endpoint security, or is it still an afterthought in our risk register?
- Would our incident response plan actually cover a mobile compromise scenario, including lateral movement into corporate systems?
Conclusion
Mobile isn’t a side channel anymore, it’s where identity, data and daily work all converge. Zimperium’s 2026 findings make clear that attackers already know this. The organisations that close the visibility gap first will be the ones that aren’t caught off guard by it.
If you’d like to understand where your organisation stands on mobile risk, contact us for a conversation.


