April 23, 2015 By Shane Schick 2 min read

Most people would probably agree getting struck by lightning is worse than downloading mobile malware, but security researchers say the statistical likelihood of either happening is about the same.

Unveiled at the recent RSA Conference in San Francisco, Damballa Inc. presented detailed results from a two-year study of more than 2 million unique hosts contacted by mobile devices across North America. The research concludes that mobile malware was contacting only 0.0077 percent of devices, based on a blacklist it had compiled. That means the average mobile user has only a 0.01 percent chance of being hit by a cybercriminal attack on his or her smartphone or tablet.

Damballa isn’t the only firm downplaying the extent of mobile malware issues. Verizon recently published a report of its own that said much of the same thing and even questioned the way organizations calculate the true cost of stolen data.

Besides suggesting many threats to mobile users may be wildly overblown, there were other surprises in Damballa’s research. As CSO Online noted, the report showed mobile malware infection rates were twice as high two years ago, the last time the company conducted a similar study. While that could be a credit to app stores that fend off the apps that pose the biggest risks, it could also be the increased sophistication of software tools to fight off cybercriminals.

A story on TechTarget pointed out that there is a direct relationship between mobile malware and the propensity for users to jailbreak phones in a given region. Unlocking devices can provide smartphone users the possibility of more choices in terms of apps, but it also means cybercriminals may have an easier way to target their potential victims.

Naturally, the statistics from Damballa aren’t intended to suggest chief information security officers and their teams should ignore the various Trojans, ransomware and other similar threats; when cybercriminals strike, the results can be disastrous. Ultimately, the numbers could mean IT departments will spend less time fending off cybercriminals directly. Rather, they may concentrate their efforts on educating their co-workers about phishing schemes and other techniques that might get them into trouble. It’s a matter of not leaving yourself exposed and vulnerable to unexpected danger — not unlike taking shelter during a thunderstorm to avoid lightning.

Image Source: iStock

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today