---
title: Mobile phone malware and the possible effects of hijackings
description: Our reliance on mobile phones has soared to unprecedented heights. We entrust them with everything; from banking to booking holidays, because of this the amount of personal data they hold can be frightening.
image: https://csacyber.com/hubfs/mobile-malware.jpg
---

[Skip to content](https://csacyber.com/blog/mobile-phone-malware-and-the-possible-effects-of-hijackings#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 July 7, 2023

 5 min read time

# Mobile phone malware and the possible effects of hijackings

![Patryk Przybocki](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Patryk Przybocki -](https://csacyber.com/blog/author/patryk-przybocki)

[Article](https://csacyber.com/blog/tag/article), [Security Operations](https://csacyber.com/blog/tag/security-operations) 

![](https://csacyber.com/hubfs/mobile-malware.jpg)

Our reliance on mobile phones has soared to unprecedented heights. We entrust them with everything; from banking to booking holidays, because of this the amount of personal data they hold can be frightening. In this blog post the profound effects of an attack on our devices is explored. Fortunately, the rise of full device encryption offers a glimmer of hope.

### Modus Operandi

Hardware backed data encryption has been increasingly relied upon due to its security and efficiency, it bases its workings on dedicated hardware modules like the Trusted Platform Modules (TPM’s) and Secure Enclave Processors (SEPs) to accelerate and fortify encryption algorithms \[4\]. These components are used in unison to encrypt and decrypt strings passed from software levels. The whole development of publicly accessible ‘unbreakable’ encryption has however been a major taking point for a while now \[6\], with the main argument against it being that it can be used for nefarious purposes. The idea being that criminals can use it to communicate with each other securely, making eavesdropping on these conversations much more difficulty for the authorities to do. However, being opposed to the free use of these strong encryptions opens the public to many possible privacy violations, apart from being an overreach into the personal lives of the public as reported by some \[5\].

The concept of complete security for mobile devices has previously been seen making headlines, likely for different reason than expected. ‘EncroChat’ was a communications network and service provider that sold modified phones to security conscious buyers, these devices were off the shelf phones running custom Android versions created for security. They were up taken mostly by criminals, of which many ran and coordinated multi-million-pound drug empires \[7\]. This empire fell apart when this supposedly secure communication network was taken down and completely compromised by a joint effort by Europol, French, Belgian and British Police \[8\]. The primary issues that helped take down the infrastructure was the poor operational security of the project- something that should be a critical consideration in any privacy focused venture. Especially one that based its entire operation and main selling point on it.

Another important consideration within the realm of security and privacy is that both IOS and Android are vulnerable to malware or other attacks. The concept of mobile phone malware is nothing new. In the early 2000’s Nokia phones running Symbian OS, were vulnerable to a worm-based Bluetooth attack \[1\] which was a large issue as Over-The-Air (OTA) software updates weren’t introduced until much later. These OTA software updates make it easy to push security patches to devices all over the world in seconds.

However as with any security issue there are always bugs that go unreported or hidden. This was something that NSO groups spyware project pivoted its operation on. Code word ‘Pegasus’, was a ‘spyware’/’remote access tool’ type malicious application that was able to completely compromise selected Apple IOS device through ‘clickless’ means (no user interaction needed). The malware has gone through multiple iterations utilizing different vectors of infection, as some versions analyzed used rogue cell towers to infect devices and others used malicious text messages that disappear. Both vectors are used to initialize a network injection, which redirects an unsuspecting user to domains which download part, or all of the payload silently. Work was performed to reverse engineer this suite of exploits that ‘Pegasus’ utilizes by Amnesty International who published their full findings \[3\] in the hopes to curb the use of malware to spy on journalists and other public figures, often putting their lives in danger with corrupt governments \[3\].

Successfully compromised devices are reported to run a process in the background called ‘bh’, this process is then likely used to gain persistence on the device, letting it stay on after rebooting. The vulnerability that was leveraged for one example of the malware exploited was a poorly integrated JavaScriptCore binary which allowed the malware to achieve code execution on the device. This was then likely used to download the rest of the malware or even potentially keep it updated. A device in this state can be fully controlled by the command-and-control center- every aspect of the device can be silently eavesdropped on. The software took to extreme lengths to be as stealthy as possible for example by disabling the upload of crash logs to Apple, truly creating a normal experience for the end user and tricking them into blindly trusting their now compromised device.

### Why does this matter?

This means that under a microscope mobile phones are no different from computers, with this come many vectors of exploitation that intersect between modern phones and computers. Meaning the same courtesy should be applied around their handling and usage, as at the end of the day they are only as secure as the person using them wants to be. This also helps to raise awareness for how secure our devices really are, likely much less than we really think.

### How to protect yourself

Unfortunately, there is little anyone can do to truly become secure, however using good cyber etiquette like backing up and not re using passwords should be enough \[9\]. There is little action that can be taken to prevent the likes of ‘Pegasus’, however keeping devices up to date and only installing from known sources like Google’s Play Store or Apples App Store can only help.

### Conclusion

In conclusion, mobile phones are likely underestimated in their power and thus, likely misused due to the amount of trust we place in them. Their security has been improving greatly but we still need to apply all the same principles and precautions we use when using conventional computer systems.

### Bibliography

\[1\]N. Bene, “10 years since the first smartphone malware – to the day.,” eugene.kaspersky.com, Jun. 15, 2014. [https://eugene.kaspersky.com/2014/06/15/10-years-since-the-first-smartphone-malware-to-the-minute/](https://eugene.kaspersky.com/2014/06/15/10-years-since-the-first-smartphone-malware-to-the-minute/)" (accessed Jun. 30, 2023).

\[2\]P. Morris, “This Text Message Can Crash, Reboot Any iPhone Instantly | Redmond Pie,” Redmond Pie, May 27, 2015. [https://www.redmondpie.com/this-text-message-can-crash-reboot-any-iphone-instantly/](https://www.redmondpie.com/this-text-message-can-crash-reboot-any-iphone-instantly/)" (accessed Jun. 30, 2023).

\[3\]Amnesty International, “Forensic Methodology Report: How to Catch NSO Group’s Pegasus,” www.amnesty.org, Jul. 18, 2021. [https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/](https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/)" (accessed Jun. 30, 2023).

\[4\]Dansimp, “How Windows uses the TPM - Windows security,” learn.microsoft.com, Feb. 27, 2023. [https://learn.microsoft.com/en-us/windows/security/information-protection/tpm/how-windows-uses-the-tpm](https://learn.microsoft.com/en-us/windows/security/information-protection/tpm/how-windows-uses-the-tpm) (accessed Jun. 30, 2023).

\[5\]L. Clark, “Proposed UK moves to break encryption draw anger of IT world,” www.theregister.com, Apr. 18, 2023. [https://www.theregister.com/2023/04/18/wrong\_time\_to\_weaken\_encryption/](https://www.theregister.com/2023/04/18/wrong_time_to_weaken_encryption/) (accessed Jun. 30, 2023).

\[6\]UK Parliament, “[https://bills.parliament.uk/bills/3137](https://bills.parliament.uk/bills/3137),” Jun. 22, 2023.

\[7\]R. Kennedy , “EU authorities penetrate phone network in huge organised crime sting,” euronews, Jul. 02, 2020. [https://www.euronews.com/my-europe/2020/07/02/encrochat-european-authorities-compromise-phone-network-to-arrest-untouchable-criminals-in](https://www.euronews.com/my-europe/2020/07/02/encrochat-european-authorities-compromise-phone-network-to-arrest-untouchable-criminals-in) (accessed Jun. 30, 2023).

\[8\]EuroPol, “Dismantling of an encrypted network sends shockwaves through organised crime groups across Europe,” Europol, May 01, 2020. [https://www.europol.europa.eu/media-press/newsroom/news/dismantling-of-encrypted-network-sends-shockwaves-through-organised-crime-groups-across-europe](https://www.europol.europa.eu/media-press/newsroom/news/dismantling-of-encrypted-network-sends-shockwaves-through-organised-crime-groups-across-europe) (accessed Jun. 30, 2023).

\[9\]National Cyber Security Centre, “Cyber Aware,” www.ncsc.gov.uk. [https://www.ncsc.gov.uk/cyberaware/home](https://www.ncsc.gov.uk/cyberaware/home) (accessed Jun. 30, 2023).

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Patryk Przybocki",
    "url" : "https://csacyber.com/blog/author/patryk-przybocki"
  },
  "dateModified" : "2024-12-06T12:48:11.713Z",
  "datePublished" : "2023-07-07T04:00:00.000Z",
  "headline" : "Mobile phone malware and the possible effects of hijackings",
  "image" : [ "https://csacyber.com/hubfs/mobile-malware.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/mobile-phone-malware-and-the-possible-effects-of-hijackings",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```