ZS Zscaler Inc.

Zscaler ThreatLabz Reveals 67% Jump in Android Malware and 40% of IoT Attacks Target Critical Industries and Hybrid Work

Zscaler ThreatLabz Reveals 67% Jump in Android Malware and 40% of IoT Attacks Target Critical Industries and Hybrid Work

The Report Reveals 239 Malicious Play Apps with Over 42M User Installs

Key Findings:

  • Critical infrastructure in the energy sector experienced a 387% increase in attacks compared to the previous year
  • India continues to be the top target for mobile attacks, with 26% of activity
  • The US remains the top target for IoT attacks, with 54% of activity



SAN JOSE, Calif., Nov. 05, 2025 (GLOBE NEWSWIRE) -- (NASDAQ: ZS), the leader in cloud security, today published the findings of its Zscaler ThreatLabz 2025 Mobile, IoT, and OT Threat Report, outlining how threat actors are leveraging malware attacks and constantly evolving their tactics. The report uncovered hundreds of malicious apps in the Google Play Store that have been downloaded over 40 million times, targeting users that are searching for productivity and workflow apps. Based on Zscaler's mobile telemetry dataset, the ThreatLabz team identified several emerging mobile threats and new malicious activity, providing valuable insights to help enterprises stay ahead of attackers in a mobile-first world.

Hundreds of malicious apps downloaded over 40 million times

Similar to last year, this year we again saw threat actors developing and releasing malicious applications targeting trusted marketplaces and hybrid work environments. The result, which the report reveals is a 67% year-over-year increase in Android malware transactions, reflects the continued risks of spyware and banking malware. ThreatLabz researchers identified 239 such applications hosted on the Google Play Store, which were collectively downloaded 42 million times.

A key distribution channel for this malware was the "Tools" category, disguising malicious applications as productivity and workflow tools. This tactic capitalizes on users' trust in functionality-driven applications–a trust that is particularly strong in hybrid and remote work settings where mobile devices are integral to professional tasks.

Manufacturing remains a top target for mobile and IoT attacks

ThreatLabz's analysis of Android attack volumes reveals that the Manufacturing and Energy sectors remain prime targets for cybercriminals due to the potential for significant returns. Notably, the energy sector experienced a substantial 387% increase in attacks compared to the previous year, highlighting an escalating threat to critical infrastructure and greater exploitation of vulnerabilities within these essential industries.

In the IoT landscape, the Manufacturing and Transportation sectors continue to be the most frequently targeted verticals. This year, each sector accounted for 20.2% of all observed IoT malware attacks, collectively representing over 40% of total incidents. This marks a shift from 2024, when Manufacturing alone represented 36% of total incidents, followed by Transportation at 14%. This suggests that while Manufacturing remains a critical target, threat actors are increasingly diversifying their efforts across other high-dependency IoT industries.

Most prevalent IoT malware

Roughly 40% of blocked transactions are linked to the Mirai family alone, and Mozi has overtaken Gafgyt as the second highest malware family. Together, Mirai, Mozi, and Gafgyt account for roughly 75% of all malicious payloads in IoT environments.

Mobile attacks cluster in India, US and Canada; US is the IoT threat epicenter at 54 percent

Worldwide, mobile threats have surged, with many of these attacks concentrated in three key regions: India, accounting for 26% of all mobile attacks, the United States at 15%, and Canada at 14%. India, in particular, experienced a significant 38% increase in mobile threat attacks compared to the previous year.

The top five countries that receive the most mobile malware traffic are:

  • India (26%)
  • United States (15%)
  • Canada (14%)
  • Mexico (5%)
  • South Africa (4%)



The report also revealed that the US is both a hub for IoT activity (54.1%) and a primary target for malware attacks. The top five countries that receive the most IoT malware traffic are:

  • United States (54%)
  • Hong Kong (15.%)
  • Germany (6%)
  • India (5%)
  • China (4%)



“Attackers are pivoting to areas with maximum impact. We’re seeing a YoY rise of 67% in malware targeting mobile devices and 387% in IoT/OT attacks on energy sectors often hosting critical infrastructure, which is a massive swing,” said Deepen Desai, EVP and Chief Security Officer at Zscaler. “A Zero Trust everywhere approach, combined with AI-powered threat detection, is imperative to reducing the attack surface, limit lateral movement, and provide organizations the defense they need against ever-evolving attacks.”

Additional highlights and new findings this year

  • A new backdoor called Android Void malware has infected 1.6 million Android-based TV boxes, primarily in India and Brazil
  • New Remote Access Trojan (RAT), Xnotice, was identified for targeting job seekers in the oil and gas industry, particularly in MENA
  • Adware overtook the Joker malware family as the top mobile threat, with a leading 69% of cases, while Joker dropped to 23% of cases, from 38% last year
  • Threat actors are abandoning card-focused fraud in favor of mobile payments



Defending against growing IoT, OT and Mobile threats

Zscaler Zero Trust Branch delivers comprehensive security and operational efficiency for branch offices, remote sites, and distributed networks, designed for environments that rely heavily on mobile, IoT, cellular IoT, and OT technologies. Using a cloud-native and AI-driven Zero Trust architecture, Zscaler aims to ensure all users, devices, and applications are safeguarded with continuous real-time verification and robust policy enforcement, regardless of their location relative to the traditional network perimeter.

Zscaler Cellular offers secure, scalable, and efficient connectivity as a service for IoT and mobile devices that rely on cellular connections. This solution, powered by the Zscaler Zero Trust Exchange™ platform, addresses the growing security challenges posed by billions of IoT devices and mobile endpoints, which traditional security methods often fail to secure effectively. It achieves this by enforcing granular policies, providing centralized visibility, and eliminating attack surfaces for all cellular traffic.

Download your copy

The 2025 Mobile, IoT, and OT Threat Report highlights the critical importance of securing mobile endpoints, IoT devices, and OT systems. Access the full report at .

Research Methodology

Mobile

The research methodology for this report includes analysis of mobile transactions and associated cyberthreats based on data collected from the Zscaler cloud between June 2024 and May 2025. The dataset comprises more than 20 million threat-related mobile transactions.

IoT/OT

The team focused their research on understanding the distinct attributes and activity of IoT devices via device fingerprinting (DFP) and analyzing the IoT malware threat landscape.

Device fingerprinting data from March 2025 to May 2025 included:

  • A complete inventory of devices, including device types and manufacturers
  • The volume and source of IoT device transactions
  • The industries and geographies contributing to IoT traffic



IoT malware threat data from June 2024 to May 2025 included:

  • The most active malware families
  • The industries and geographies most targeted by IoT attacks
  • The top attacked devices



About Zscaler

Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across more than 160 data centers globally, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.

Media Contact

Taylor Dunton, Senior Director, Public Relations,

A photo accompanying this announcement is available at



EN
05/11/2025

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Zscaler Inc.

Michael Piccolo
  • Michael Piccolo

Daily Recap: GLEN/RIO, FRT, FLS, ZS, BDX/WAT, MPX/MCFT, WBD/NFLX, PATH...

Flowserve Corp. (FLS - $78.98)Announces $490 Million All-Cash Acquisition of Trillium Flow Technologies' Valves Division; Expected Close Mid-2026. FLS, a leading provider of flow control products and services for global infrastructure markets, announced on February 5, 2026, that it has signed a def

 PRESS RELEASE

Zscaler Acquires SquareX to Advance Zero Trust Browser Security for th...

Zscaler Acquires SquareX to Advance Zero Trust Browser Security for the AI Era Zscaler extends zero trust browser capabilities to secure any browser on any device SAN JOSE, Calif., Feb. 05, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: ZS), the leader in cloud security, today announced it has acquired SquareX, to further extend Zero Trust capabilities into the browser for the AI era. This acquisition will help redefine browser security, allowing organizations to embed lightweight extensions into any browser, providing increased security and eliminating the need for third-party browsers. Organizat...

 PRESS RELEASE

Zscaler to Host Second Quarter Fiscal Year 2026 Earnings Conference Ca...

Zscaler to Host Second Quarter Fiscal Year 2026 Earnings Conference Call Earnings Results to be Released on Thursday, February 26, After the Close of the Market SAN JOSE, Calif., Feb. 05, 2026 (GLOBE NEWSWIRE) -- Zscaler, Inc. (NASDAQ: ZS), the leader in cloud security, will release second quarter fiscal year 2026 earnings after the market closes on Thursday, February 26, 2026. The company will host an investor conference call that day at 1:30 p.m. Pacific time (4:30 p.m. Eastern time) to discuss the results. Date:Thursday, February 26, 2026Time:1:30 p.m. PTWebcast:Dial-in:To join by p...

 PRESS RELEASE

Zscaler Unveils New Innovations to Secure Enterprise AI Adoption

Zscaler Unveils New Innovations to Secure Enterprise AI Adoption New Capabilities Empower Organizations to Gain Visibility into, and Securely Build, Deploy, and Use AI Applications Across the Enterprise SAN JOSE, Calif., Jan. 27, 2026 (GLOBE NEWSWIRE) -- (NASDAQ: ZS), the leader in cloud security, today announced new AI security innovations designed to empower enterprises to secure the fast growing use of AI, while maintaining visibility, control, and governance. As organizations today adopt generative AI and prepare for the use of agentic AI, they face rising risk of cyberattacks and ...

 PRESS RELEASE

Zscaler 2026 AI Threat Report: 91% Year-over-Year Surge in AI Activity...

Zscaler 2026 AI Threat Report: 91% Year-over-Year Surge in AI Activity Creates Growing Oversight Gap for Global Enterprises Rapid AI adoption creates a critical security gap between innovation and security, requiring organizations to adopt an AI security platform built on Zero Trust News Highlights  AI adoption is accelerating faster than enterprise oversight. Despite 200% AI usage growth in key sectors, many organizations still lack a basic inventory of AI models and embedded AI features, elevating AI governance to a board-level priority.Enterprise AI systems are vulnerable at machine s...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch