Security researchers have observed a significant increase in mobile malware and spyware activity affecting both Android and Apple devices in late September 2025. According to AhnLab’s ASEC Blog, the fourth week of September saw a notable rise in malicious Android APKs, with particular targeting in regions such as Indonesia and Vietnam. Attackers have been leveraging smishing campaigns to distribute malware, often disguising malicious applications as legitimate software, including those related to OnePlus OxygenOS. These campaigns aim to steal sensitive user data, credentials, and financial information from unsuspecting victims. Concurrently, a French government advisory highlighted a surge in sophisticated spyware attacks against Apple users, specifically those with iCloud-linked devices. The advisory, reported by Zimperium and originally covered by Dark Reading, revealed that attackers are exploiting zero-day vulnerabilities in Apple’s ecosystem. Victims often receive threat notifications from Apple months after the initial compromise, indicating a delay in detection and response. The French CERT-FR warned that these spyware campaigns are highly targeted and may involve advanced persistent threat actors. The exploitation of zero-day vulnerabilities allows attackers to bypass traditional security measures and gain persistent access to devices. Both Android and Apple users are at risk, with attackers employing a variety of social engineering tactics, including phishing and smishing, to lure victims into installing malicious payloads. The increase in mobile threats underscores the need for heightened vigilance among users and organizations, particularly in regions identified as hotspots for malware distribution. Security experts recommend regular software updates, the use of reputable security solutions, and user education to mitigate the risk of infection. The cross-platform nature of these attacks demonstrates the evolving sophistication of mobile threat actors. Organizations are advised to monitor for indicators of compromise and to respond swiftly to any signs of unauthorized access. The reports from both AhnLab and Zimperium highlight the global scale of the threat, with attackers adapting their techniques to exploit vulnerabilities in both major mobile operating systems. The ongoing campaigns serve as a reminder of the critical importance of mobile security in the current threat landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Zimperium published a report stating that a French advisory had revealed a surge in spyware activity targeting Apple devices. The supplied content does not include the advisory date or further incident specifics, so the publication date is used.
AhnLab ASEC released its 'Mobile Security & Malware Issue 4st Week of September, 2025' report summarizing mobile security and malware developments for the fourth week of September 2025. The reference does not provide specific underlying incident details in the supplied content.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.