SecurityWorldMarket

Agentic AI accelerates attacks on mobile apps

Dallas, Tx

Zimperium has released new analysis warning that agentic AI is making sophisticated mobile app attacks easier to develop, adapt and scale.

Agentic AI systems can independently plan and execute tasks, learn from unsuccessful attempts and adjust their approach until an objective is achieved. Applied to mobile attacks, these capabilities allow threat actors to automate work that previously required extensive time and specialised expertise, including analysing app defences, identifying ways to bypass security controls and replicating successful attacks across multiple devices.

“Agentic AI is transforming complex mobile attacks into repeatable operations that can be initiated with simple, natural-language instructions,” said Pat Shueh, VP of Product Management, MAPS, at Zimperium. “The concern is not that AI has created an entirely new vulnerability class. It has removed many of the technical barriers that once limited who could execute these attacks and how quickly they could scale.”

The warning follows Zimperium’s recent analysis of Rathat, an AI-powered mobile malware targeting credentials and financial accounts. Rathat provides evidence that AI is already becoming part of the mobile threat landscape, while emerging agentic AI frameworks could give attackers even greater autonomy and speed.

Once an agent identifies a successful attack path, it can translate that process into a reusable script and deploy it across fleets of devices or emulators. It can also reassess and regenerate the attack when an application changes, reducing the cost and effort required to maintain mobile fraud operations.

This shift increases the need for mobile app security that can withstand both static and dynamic analysis, tampering and manipulation at runtime. Organisations must protect applications throughout their lifecycle, from development and app store distribution through execution on end-user devices.


Tags
Back to top