Video summary
The integration of artificial intelligence has fundamentally altered the economic landscape for cyber attackers targeting mobile devices, effectively removing traditional barriers to entry that once required specialized skills or extensive resources. As highlighted in Zimperium's Global Mobile Threat Report, AI allows malicious actors to execute attacks at a much lower cost while significantly increasing their speed and scale. This technological shift is particularly dangerous because mobile devices have become the primary interface for critical organizational functions such as work execution, banking, healthcare management, and customer engagement. Consequently, these devices hold the "keys to the kingdom" regarding digital identity, making them prime targets. Attackers are now leveraging AI to create highly convincing phishing campaigns that render exclusively on mobile platforms through QR codes or PDF links, bypassing traditional email-based security controls, while also utilizing social engineering tactics via consumer messaging apps like WhatsApp and WeChat where corporate defenses often lag behind.
The sophistication of these threats is further amplified by the widespread use of AI-generated content in phishing attempts, which are estimated to be four and a half times more convincing than those written by humans alone. This advancement renders traditional user-centric advice, such as looking for grammatical errors or awkward phrasing, largely obsolete because modern AI tools can craft contextually perfect messages that mimic professional communication styles. Additionally, the adoption of third-party AI within mobile applications has surged dramatically on both Android and iOS platforms over the last year, introducing significant risks related to data privacy and intellectual property leakage. These models are inherently "data hungry," often unintentionally exposing sensitive employee information or sending it to regions where governance policies may not apply. The report notes that nearly one in ten devices is now infected with spyware, a figure four times higher than the previous year, demonstrating how AI has democratized advanced exploitation techniques like weaponizing zero-day vulnerabilities such as Dark Sword, which were previously accessible only to nation-state level actors or those with PhD-level expertise.
To counter these evolving threats, organizations must adopt an operational approach that utilizes "firefighting fire" by deploying mobile-specific AI defenses capable of understanding the unique nuances of consumer devices where personal and professional data blur together. Zimperium's new tool, Deep Insights, exemplifies this strategy by enabling on-demand forensic scans that can identify attack narratives and compromise levels within minutes rather than months, effectively shrinking the critical response time gap for CISOs. Security postures must evolve from simple link-blocking to deep content analysis of messages with user permission to detect social engineering intent, alongside robust runtime protections that safeguard code and cryptographic keys against AI-enabled attacks in the wild. Furthermore, governance frameworks need to be rethought to gain visibility into both sanctioned third-party applications and unauthorized open-source components, ensuring that data flows comply with regulations like GDPR while protecting intellectual property from leakage through unvetted models or SDKs.
Ultimately, mobile security must be recognized as an indispensable cog in modern business operations rather than a secondary concern often overlooked by organizations focused on endpoint, cloud, or identity protection alone. As CISOs prepare for the upcoming Black Hat conference and beyond, they are urged to reassess their architecture with the understanding that mobile devices and apps frequently represent the weakest link in security chains despite being central to daily business functions. The path forward requires a holistic defense-in-depth strategy that combines advanced AI-driven detection tools with operational capabilities to investigate incidents rapidly without violating user privacy or relying on physical device shipping for analysis. By embracing these comprehensive solutions, organizations can better defend against the rapid escalation of threats where attackers use AI not only to build malware but also to discover and weaponize vulnerabilities faster than ever before, ensuring resilience in an increasingly automated threat environment.
Read the full video transcript
Hello and welcome to the Cub's coverage
of Black Hat 2026. This is a special um
actually a pre- edition of our coverage
um ahead of the Black Hat conference
next week. Um we've got a really
important topic for you today. We're
going to be talking about how AI is
changing the economics of attacking
mobile devices and why that's, you know,
so important and such a threat these
days. Um, I have the pleasure today of
being joined by Kern Smith. Kerna is the
VP of global solutions at Zmpirium.
Kern, thank you so much for joining
today.
>> Thank you for having me, Christa.
Looking forward to the conversation.
>> Absolutely. I am as well because I know
Zirium um has just um introduced some
really interesting research that we're
going to get into.
>> But before we do, I wanted to take a
minute to set some context to again
really underscore why this is so
important today. So we're seeing that AI
is um changing the game for attackers.
So attackers can move faster. Um they
can operate much more cheaply. They can
execute attacks much more cheaply. And
when it comes to things like fishing,
um, they can become much more convincing
at scale and really have these targeted,
um, attacks. And I know that Zurium
spends a lot of time looking at kind of
the mobile sphere. And I think that's
really interesting because mobile
devices have become the primary
interface for things like work, banking,
healthcare, and customer engagement. And
so therefore, um, attackers are
beginning to follow suit and really
execute these campaigns that are
targeted at mobile devices. Um, but you
know, one one potential challenge there
is that oftent times the industry tends
to focus more on areas such as endpoint,
identity, cloud security versus mobile.
Um, so this is really exposing a
potential gap. So Kern, I wonder if you
could comment on that through the lens
of this global mobile threat report that
Zarium just introduced. Maybe start
looking at the intention behind the
research and um some of the key
findings.
>> No, appreciate that Chris. Yeah, so for
us when we look at the global mobile
threat report and the data, it's very
much what you said. AI has effectively
removed the barrier to entry for bad
actors to do bad things against mobile
devices because before it used to be a
very specially skill set uh there were
certain barriers of entry you know
people didn't have the training on it
but AI has been has no shock to anybody
had been a seismic change in the
industry especially around mobile
security and that makes sense because
ultimately these devices in the context
of organizations are central to how work
gets done. Our data shows over 46%
almost half of frontline workers in the
US rely on a mobile device to accomplish
their job. And when you think about how
digital identity is maintained, this is
where the keys to the kingdom exists.
This is how people log in. All those
items are critical. And that's why
mobile is a target.
>> Yeah, absolutely, Kern. Um, and when I
was digging into this report, one of the
stats that really jumped out to me right
away was, um, Zarium found that fishing
events detected on employees mobile
devices increased 380%
since January 2025.
Um, and I'm curious, so is this simply a
matter of we're seeing more attacks
emerging that are targeting mobile
devices or is it maybe simply because
attackers really are becoming that much
more efficient with the use of AI?
>> It it's both honestly. Um, first off, it
is attackers are realizing that mobile
is a relatively uninvested area when it
comes to security. Uh a lot of
organizations they may have a management
tool of sorts but they don't have actual
defense against fishing threats or
social engineering much less what's the
risk of a third party app or is the
device compromised. Attackers have
realized that. They also have realized
that it's pretty child's pretty trivial
to attack or target a user either with a
fishing link or a missing link that if
you target it on mobile. And we see over
half of the fishing links out there will
only render on a mobile device, right?
They won't render on a um email server
or a traditional web web blocking
gateway. It's QR codes. It's PDF links.
It's all these things that will only ren
the these websites that will only render
if they're accessed from a mobile
device. And the other side of it is
social engineering because these
attackers realize these devices are in
the end they're communication devices.
They're consumer devices. And there's
multiple ways to social engineer the
user that do not go through official
corporate communications. Think of
messaging apps, WhatsApp, WeChat, you
know, text messages. So you combine that
with these devices are the key to the
kingdom from an identity perspective.
Just that alone, they are the target for
attackers and AI has unlocked that
capability for attackers, bad guys to do
bad things on these against these mobile
devices.
>> Yeah, absolutely, Kern. Um, and I know
your report actually found that 86% of
fishing attacks
>> that today they now include content that
is AI generated. Um, in that to your
point, this AI generated fishing, um,
your report found that it is estimated
to be 4.5 times more convincing than
human written fishing. So, you know, for
your typical employee or your typical
user, the long-standing advice has been
to look for things like bad grammar or
awkward phrasing that would indicate
that this was potentially suspicious or
nefarious, but now with AI really upping
that game, you know, I guess what's the
advice that you would give today?
Because it seems to me like this
traditional advice might not be
sufficient anymore. 100% relying on the
user um is
not optimal because these tools have
gotten so advanced. They've gotten so
dynamic where they can interact with the
user. They can take information from
other sources and present a message that
makes sense in the context for the user
at that point. So it really when you
think about it, it's trying to get the
an action from the user, convince them
to do something. So, it's not just
about, hey, looking for somebody trying
to be, you know, Microsoft instead of
Microsoft or something like that.com.
It's think about how you use AI on a
daily basis. People are using AI to
polish up their own professional
messages. Attackers are doing the same
thing and this is their profession. This
is what they're good at. So it's
imperative that to defend against these
AI powered threats, you have AI powered
defense that is focused on the mobile
problem because the problem on mobile is
different than it is on an endpoint than
it is on a cloud server than it is on
other assets because of its uniqueness
of that being a consumer device that has
a very blurry line between personal and
private data and the level of
communications that go on from there.
So it really grown as a matter of sort
of fighting fire with fire, right? And
sort of utilizing AI to then combat
these AIdriven threats. On the subject
of AI,
>> so your report also looked at how AI is
being used inside mobile applications.
>> And what I found interesting was that
both on Android and iOS devices, um
there was some pretty significant growth
um in just the last year. on a Android
devices it was 14fold over the last um
year and then on iOS it was sevenfold.
So I'm curious your perspective on why
this matters from a security perspective
and why we should be paying attention to
this.
>> Absolutely. So if you think about it, AI
is a fantastic tool and you know we've
been using AI since the start of our
company almost 15 years ago to create a
mobile mobile specific AI to defend
against these threats and identify these
risks. Um, but now AI has become such a
great tool for people who may not have
had the technical skill before to take
great ideas and craft apps or craft
software. Or for people who do have the
technical skills, it helps them really
automate tasks and kind of deliver
things quicker uh to accomplish job
functions or get the app out the door at
that point. The challenge though is very
similar to any other third party code
that you introduce into your app. Do you
understand the risk of it? Was there
unintentional risk introduced into that
app that you're developing? The other
side of it though is for apps that you
were deploying to employees. What's the
use of thirdparty AI within that app
itself? Because a lot of the times you
see unintentional usage or unintentional
data gathering. And that's the core
challenge when you're using thirdparty
AI is that these AI tools by nature are
going to be data hungry. they're trying
to capture whatever they can to help
with their models to help their training
etc. And so you need to understand what
is the data that you are either exposing
within your own app or that you are expo
what is the employee data that you're
exposing to these third party apps and
where is it sending that data to. So
there's a very big difference between
sanctioned AI that your organization has
gone through done the CISO signed off on
it. We have data governance versus hey
it's a third party open open model
that's sending data to a region or a
country that you may not be comfortable
with potential IP leaking out to.
>> It sounds to me Karn like it's a kind of
a twofold problem. So as you're
mentioning number one, organizations are
really struggling to keep track of how
AI is being introduced in their
applications. And then the second part
is that they're having a lot of trouble
really um keeping a pulse on like you're
mentioning what data is being sent where
and how it's being used by that
application. So it sounds to me like
it's becoming really a governance issue
um and that maybe we need to start
rethinking the way we're governing our
applications. Would you agree with that?
>> 100%. It it's a governance aspect. It's
gaining visibility into what's going on
in these applications. Um it it
absolutely is because what we're seeing
is that the compliance regimes around
this are just they're they're catching
up to this. They're they're they're it's
constantly adapting based on what the
market is finding out. So the demands of
the of the organization are going to be
having tools or mechanisms in place that
can adapt to this rapidly evolving
ecosystem of third party AI usage. Uh
the other thing I'd add to that on the
third party AI usage is that we're not
just seeing it being used to code the
apps or being injected in the apps but
we're seeing it being used also by
attackers to target these applications
and find vulnerabilities with them
within them. So that is a rapid
exponential increase in the
vulnerabilities of apps that you may
have secured them but what can an
attacker divine from them if you don't
have adequate protections in place of
your IP or your code once it's deployed
out there.
>> Yes. Yeah. I'm glad you brought that up
Karin because um I know your report
looked about you know these third party
SDKs and sort of this kind of open
versus closed components and and I
wanted to double click on that with you.
Um I believe the stat was that 60% of
third party SDKs inside enterprise
developed apps are closed source. And so
um you know pulling on this thread a
little bit if the organization can't see
what's inside those components how do
they then have context into what AI
capabilities they're then introducing
into their environment? Well, you have
to have the right tooling in place and
it has to be part of a larger security
posture and how you're securing these
apps through their entire life cycle
from development kind of what we term
from development to deployment. So, it
starts off with without getting too deep
into into process weeds, assessing the
app as it after it's being built. So,
using tooling to understand, hey, what
is in the app? Does it meet policy?
Right, as a baseline thing. Then being
able to understand once you've deploy
being able to then apply protections to
protect your IP within the app be it
crypto keys be it code be it any number
of things authentication chains those
type things how do I statically and
dynamically protect that app both at
rest and at runtime and then ultimately
once the app is deployed in the wild how
can you get signals so that the app can
a defend itself against these AI enabled
attacks that are going on because
attackers are using AI. We see it every
single day just in pin testing alone
where people are using these AI tools to
try to break these apps and obtain
secrets even, you know, even though they
may have applied what I would call
legacy protections around it. That's why
runtime protection is so essential on
this. And then being able to allow the
app to defend itself locally and then
send a signal back to a uh to the
organization so it understands what's
going on in context out there. you know,
is this a thirdparty SDK that's run a
muck or is it a bad actor that's just
kind of analyzing the app, seeing what
they can do, but maybe there's something
there or is it a instrument of broad
campaign enabled by AI that is taking us
for a sizable amount of money and
impacting our customer base.
>> Absolutely. And that that brings me to
um another topic that I wanted to get
your thoughts on and sort of you know
you were mentioning okay malicious
actors you know sort of you know
observing in and gathering information
um and I know that you know spyware um
is something that your report dug into
found that it's installed on nearly one
in 10 devices um which I found scary
>> um and that was I guess four times
higher than than you know what Zarium
found a year ago.
So um what's driving that increase and
sort of you know I guess what's the
takeaway for you know those
organizations that are looking to
protect against spyware? Yeah, it it
boils down to AI has remove has reduced
if not completely removed a barrier to
entry to for attackers to do some really
bad stuff using advanced techniques that
used to be reserved for you know almost
nation state level type of attacks. Now
it's become a commodity. Um a good
example of this is there was a iOS
exploit called Dark Sword that was
disclosed earlier this earlier this
year. um it had been used in the wild.
Uh you know there's different elements
that you know we have indicators that we
were seeing it uh before it was even
disclosed. Uh and what what it shows is
that when you combine the explosion of
these the use of these devices the focus
of attackers realizing that they're
relatively unprotected both on the app
and the device side and tools like u I'm
not saying this was used but as an
example mythos has been in the news
recently.
AI tools allow attackers to discover
vulnerabilities quicker than they ever
had before with less technical skill
sets. That's on a zero day side or
weaponize existing known vulnerabilities
right after disclosure. And that's a big
concern because our data says over a
quarter of devices now are still exposed
to known exploits like Dark Sword. And
anecdotally, I'll give an example of
this. uh my team and you know some
members of my team have different coding
skills but some like myself don't have
deep you know R&D skills. We are able to
take these zero day disclosures and
within a matter of days turn them right
around and weaponize them for
demonstration purposes. Before it used
to take serious people with almost PhD
level experience to do that and months
of effort. Now you're getting people
with just a little bit of knowledge and
a lot of AI tokens. They can weaponize
this in a rapid amount of time.
>> Absolutely, Kern. I'm really glad you
brought that up because I think we're
going to be hearing a ton about it next
week at Black Hat. I think it's going to
be a major focus because I'm seeing
practitioners no matter their
particular, you know, area of expertise
within the cyber security tool chain. I
think they're all looking at as you
mentioned mythos and these frontier
models and how do they make sure that
they can you know try to prevent and be
resilient when you know their time to
respond just continues to shrink because
as you mentioned you know these
attackers can move more quickly at
greater scale and with greater
sophistication too. You know you were
kind of alluding to they can potentially
um you know kind of tool some of these
um different vulnerabilities together.
So um you know it's going to be I think
a big area of focus and I guess you know
what's maybe your reaction to that in
terms of from the practitioner
perspective um being able to sort of you
know respond more quickly to these
vulnerabilities.
>> It it's a great question. Um I think it
demands you AI is a general tool set but
not all AI is created equal right
especially in the mobile ecosystem you
have to have mobile specific AI from a
security perspective to defend against
these mobile threats but it's not just
enough to have that you have to be able
to operationalize it and get it deployed
in a way that works within the
environment works within your use cases
and solves the problems that you're that
the other thing I'd say is you have to
have layers of defense in depth, right?
And so that's where, for example, we
just released um some major enhancements
around our our social engineering
capabilities where we don't just look at
links or web traffic. It's also we can
look at the content of the message with
user permission, etc., not violating
privacy to say, hey, they're trying to
social engineer you. So not just taking
a technical approach of was it a link
but actually is there intent around
this. Uh we are going to be releasing
announcing at black hat giving you an
early preview a tool that we call deep
insights that will allow for users to
initiate forensic scans of their device
on demand and do deep inspections of
that device. That used to take
organizations months to obtain that
level of information and that level of
assurance. We're doing it in minutes and
we're doing it at scale in the field. So
that's what I mean by you have to have
defense in depth and a comprehensive
approach around this. And with mobile in
particular, you have to have a tool
designed to address the problem on
mobile.
>> Absolutely, Karen. And I'm I'm glad you
brought up deep insights because I think
the forensic side of things and really
kind of reconstructing and understanding
what happened in an attack is going to
be even more important as we, you know,
adapt to and learn from these new types
of attacks.
Um I'm wondering if you could comment on
the announcement sort of um what drove
Imperium um to you know to announce deep
insight
>> and through the lens of sort of I guess
the analyst and what information has the
analyst typically been missing um that
now you know as empirium is sort of
filling in with deep insight. No,
totally. It's really part of our
holistic approach. As I mentioned
earlier, we've been AI native for 15
years back when it was called machine
learning. Now it's, you know, kind of
morphed into AI and whatnot. Um, but for
us, it's been about how can we help
customers defend against these emerging
threats while covering kind of the
normal oper while getting it
operational, right? Because you can have
the best technology in the world, but if
you don't get it operational, it's not
really worth anything at that point. So
part of our strategy has been to bring
tooling to the table that offers immense
value to our customers and solves
significant problems. So an example of
that is we recently uh released our sock
AI capability that um really allows
organizations to investigate these
mobile instance without having to have
specialy training or specialy background
and again giving them visibility they
otherwise didn't have or reducing the
amount of time to investigate these
threats from it used to be 8 hours to
now it's minutes basically that deep
insights is that next step on this
journey on this AI journey where based
on feedback for customers. They really
have kind of what I would call a couple
core use cases. One is um pre-travel,
post-t travel inspection. I took my
device on a trip to an area that u maybe
there's some industrial espionage going
on. Maybe not. I want to know what it
looked like before, what it looked like
that when I came came back and ensure
that there wasn't anything weird when it
going on if I left it in the hotel room
as an example pre-post trip. The other
one is um general incident response.
Hey, Zurium said something is going on
here. I need to do a deeper inspection
and gain some deeper insights into what
the kill chain was on this. Was it
because a WhatsApp message was sent that
contained a JavaScript exploit that
then, you know, triggered a a kernel
panic and then etc etc. All of a sudden,
the device is compromised. What what was
actually forensically going on? And then
ultimately what could have potentially
been removed from the device from a risk
or a threat perspective. Um then the
last thing is just programmatically hey
I have VIP users they are going all over
the place just as a measure of assurance
no different than I do with all my
endpoints for VIP executive users. I
want to do an ondemand deep scan of that
device just to ensure we didn't miss
anything. Right? Because the risk of
that time gap of something happening and
us not being aware, the more you can
shrink that, especially especially on
mobile, the better off you are from an
overall security perspective. And most
organizations have never had that
capability of shrinking that gap or even
getting visibility in the first place on
that side.
>> Yeah. And I think so as you mentioned
sort of you know shrinking that time gap
and allowing that response to happen
more quickly um is is very critical and
it makes me think her about sort of this
um conversation that I'm tending to have
a lot these days which is sort of okay
the two sides of the coin between you
know the investigation side of things
and um the detection side of things and
so um with the deep insights
announcement I'm wondering if you can
kind of comment on why the quality of
the investigation matters even just as
much if not more as the quality of your
detection capabilities these days.
>> 100%. I I view them as linked together.
You have to have all of them to be
effective from a security perspective.
And they all have to kind of
interconnect and work work together with
each other. So if you think of it, it's
you ultimately have to have something on
the device to defend against the
exposure, identify the risk and defend
against the threat where it occurs. That
has been our what we call MTD or mobile
threat defense without getting too deep
into product terminology. Um but it it
it's effectively hey defend against the
fishing threat, defend against the risky
Wi-Fi, defend, you know, identify, hey,
you've got malware or spyware, something
bad going on there. Then you go into
other advanced capabilities like okay
now I need to defend against social
engineering. Well how do I do that and
also balance user privacy? Well that you
need to use some AI classifiers that can
do that in a way that apply protections
in a way that can also be leveraged for
organizations. Okay. Then you get into
now I'm getting telemetry from the
device. How do I absorb that within my
sock within my ecosystem? So, it's not
just enough to get a stream of threats
and whatnot. Anybody can do that. It's
are the forensics relevant? Do they
apply GDPR protections? Are they, you
know, do you have different levels of
threats and responses based off of
groups? And then it goes into taking
that information using mobile specific
expertise and AI tools have been trained
on that expertise to do an analysis to
say to the sock, this is an incident you
really should pay attention to and
here's why. Here's the attack narrative.
Here's what's going on. And oh by the
way do that deep inspection so because
as an app you only have visibility is so
much but if you do a deep in forensic
inspection of the device you can get
much better attribution on what happened
within the kill chain what the exposures
were etc etc etc. So let's do that and
let's do it in a way where you don't
have to physically ship the device from
one place to another wait for a third
party to do an analysis spend months
waiting for the result. let's do it in a
way that allows the user to initiate it
and you get a response in minutes at
that point with really no loss in
fidelity at that point. So that's part
of you know balancing both you have to
have top-of-the-line emerging approaches
to defend against the threat and
identify the risk and use AI to defend
against that right right tool for the
right job but then you have to have the
operational capabilities and kind of the
experience on okay great to have this in
theory how do you operationalize it to
show to give value to your customers and
that's ultimately what we're doing on
both sides best of breed raw
capabilities but also trying to do best
to breed. How do you get this off the
shelf and get value out of this?
>> Absolutely. Because it doesn't have
value if it's not operational at the end
of the day.
>> Exactly.
>> Um, absolutely. And I know that's one
thing that, you know, CISOs in
particular are struggling with and Kern,
I'm sure you're going to be sitting down
having a number of conversations with
CISOs next week at Black Hat. Um, as we
start to wrap our conversation here
today, um, I'm curious if you, um, were
to encourage CISOs to maybe, um, you
know, make one change over the next
year. Um, what advice would you give
them or what convers?
>> Oh, one piece of advice. Oh, now now I
got to really think about think about
that. Um,
I I think the the piece of advice I
would say is think about where your
business is really run through. And what
I mean by that is
how does your organization interact with
its customers? How do your employees do
their job on a daily basis? And yes,
much like we're sitting talking on a
computer, there's still phones that
control identity. They control the keys
of the kingdom. The same level of access
are there. So, do you feel comfortable
with the visibility and the defense you
have on that asset? The same goes on uh
mobile applications or the customer
interaction. Increasingly, how customers
interact with organizations, they go to
a payment terminal, they sign in on a on
a tablet of some sort or it's go
download this app to do the transaction.
How is your business really running? And
what is one of the indispensable cogs in
that business? 99% of the time when I
talk to CISOs about that, regardless of
the organization type, public, private,
you know, public sector, private sector,
any of the any of the different
verticals, you start pulling back the
layers of the onion. It's like mobile,
be it a device or an app, is an
essential cog to how that organization
operates. And it is often the most
undefended. It is the weak point of any
security architecture with most
organizations.
>> Well, Karin, I couldn't think of any
better point um to conclude this
conversation on. I think that really
kind of hits the nail on the head in
terms of everything we've been talking
about how really mobile is that you know
that critical point um here in this
chain. So, I wanted to thank you so much
um for joining us today. Um I hope you
have a great event next week at Black
Hat. I hope we can find a few minutes to
catch up and um I'm sure that you're you
and the team are going to be very busy
um talking about this research um you
know and everything else. So um again
thank you so much for joining um and
thank you to our audience for joining as
well. Um again this is Christa Casease,
principal analyst with the cube. Um you
are listening to some of our pre-B black
hat coverage. Um and we're going to be
coming to you live um all next week from
the Mandalay Bay in Las Vegas. So, we
hope you'll join us and um we're looking
forward to it. Thanks so much.
>> Thank you. Take care.