Luxembourg officials said malware infected the mobile device management system used by the State Centre for Information Technology (CTIE), affecting thousands of government-owned smartphones and tablets. Digitalisation minister Stéphanie Obertin said the malware was discovered on 26 February and publicly confirmed the next day after investigators found it had been active since late January, remaining undetected for nearly a month.
Authorities said the malware was memory-resident and appears to have compromised the management platform just hours before the service provider updated the system at the end of January. The incident exposed an inventory of state-managed mobile devices and associated user and device data, but officials said it did not access content stored on the phones and tablets such as messages, calendars, or photos; the affected systems have since been updated and secured.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Following the discovery, Luxembourg authorities updated and secured the affected systems to contain the incident. The response came after the compromise of the state mobile device management environment was identified.
Luxembourg publicly confirmed the breach on 27 February after identifying malware on the CTIE mobile device management system. Officials said messages, calendars, and photos stored on devices were not affected.
Authorities discovered the malware on 26 February on the system used to manage smartphones and tablets for the public sector. The incident was found to have exposed the list of state-managed devices and related user and device data.
A memory-resident malware infected the mobile device management system used by Luxembourg's State Centre for Information Technology (CTIE) a few hours before the provider updated that system at the end of January. The compromise affected the platform used to manage thousands of government-owned smartphones and tablets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.