Zscaler ThreatLabz Reveals 67% Jump in Android Malware and 40% of IoT Attacks Target Critical Industries and Hybrid Work
Zscaler (NASDAQ: ZS) published its 2025 Mobile, IoT, and OT Threat Report on Nov 5, 2025, finding a 67% YoY increase in Android malware transactions and 239 malicious Google Play apps downloaded 42 million times.
The report notes a 387% rise in attacks on the energy sector, IoT attacks concentrated in Manufacturing and Transportation (each 20.2%), and the US accounting for 54% of IoT malware traffic. Additional findings: Adware leads mobile cases at 69%, Mirai/Mozi/Gafgyt comprise ~75% of IoT payloads, and new threats include Android Void, Xnotice RAT, and widespread infected TV boxes.
Zscaler (NASDAQ: ZS) ha pubblicato il suo Rapporto 2025 sulle minacce mobili, IoT e OT il 5 novembre 2025, rilevando un aumento del 67% su base annua delle transazioni di malware Android e 239 app malevole di Google Play scaricate 42 milioni di volte.
Il rapporto segnala un incremento del 387% degli attacchi al settore energetico, attacchi IoT concentrati in Manufacturing e Transportation (entrambi 20,2%), e gli USA che rappresentano il 54% del traffico IoT malware. Ulteriori risultati: Adware guida i casi mobili al 69%, Mirai/Mozi/Gafgyt costituiscono circa 75% delle payload IoT, e nuove minacce includono Android Void, Xnotice RAT e diffusione diffusa di box TV infette.
Zscaler (NASDAQ: ZS) publicó su Informe de amenazas 2025 para móviles, IoT y OT el 5 de noviembre de 2025, encontrando un aumento interanual del 67% en transacciones de malware Android y 239 apps maliciosas de Google Play descargadas 42 millones de veces.
El informe señala un incremento del 387% en ataques al sector energético, ataques IoT concentrados en Manufactura y Transporte (ambos 20,2%), y EE. UU. representando el 54% del tráfico de malware IoT. Otros hallazgos: Adware lidera los casos móviles con un 69%, Mirai/Mozi/Gafgyt comprenden aproximadamente el 75% de las cargas útiles de IoT, y nuevas amenazas incluyen Android Void, Xnotice RAT y cajas de TV infectadas masivamente.
Zscaler (NASDAQ: ZS)는 2025년 11월 5일 2025년 모바일, IoT 및 OT 위협 보고서를 발표했고, Android 맬웨어 거래의 전년 동기 대비 67% 증가와 Google Play에서 악성 앱 239개가 4200만 회 다운로드되었다고 밝혔습니다.
보고서는 에너지 부문 공격이 387% 증가했고 IoT 공격은 제조와 운송에 집중되며 각각 20.2%를 차지한다는 점, 그리고 미국이 IoT 맬웨어 트래픽의 54%를 차지한다고 적었습니다. 추가 발견으로 모바일 케이스의 69%가 애드웨어가 차지하고, Mirai/Mozi/Gafgyt가 IoT 페이로드의 약 75%를 구성하며, Android Void, Xnotice RAT, 광범위하게 감염된 TV 박스가 새로운 위협으로 포함됩니다.
Zscaler (NASDAQ : ZS) a publié son Rapport sur les menaces mobiles, IoT et OT 2025 le 5 novembre 2025, constatant une augmentation de 67% d'une année sur l'autre des transactions de malwares Android et 239 applications Google Play malveillantes téléchargées 42 millions de fois.
Le rapport note une augmentation de 387% des attaques contre le secteur de l'énergie, des attaques IoT concentrées dans la Fabrication et le Transport (chacune 20,2%), et les États-Unis représentant 54% du trafic IoT malveillant. Autres constats : l'adware domine les cas mobiles avec 69%, Mirai/Mozi/Gafgyt représentent environ 75% des charges utiles IoT, et de nouvelles menaces incluent Android Void, Xnotice RAT et des boîtiers TV infectés largement répandus.
Zscaler (NASDAQ: ZS) hat seinen 2025er Bericht zu bedrohten Mobilgeräten, IoT und OT am 5. November 2025 veröffentlicht und dabei einen Anstieg der Android-Malware-Transaktionen um 67% gegenüber dem Vorjahr sowie 239 schädliche Google Play-Apps, die 42 Millionen Mal heruntergeladen wurden, festgestellt.
Der Bericht vermerkt einen Anstieg der Angriffe auf den Energiesektor um 387%, IoT-Angriffe konzentrierten sich auf Fertigung und Transport (je 20,2%), und die USA machen 54% des IoT-Malware-Traffics aus. Weitere Ergebnisse: Adware führt mobile Fälle mit 69% an, Mirai/Mozi/Gafgyt machen ca. 75% der IoT-Payloads aus, und neue Bedrohungen umfassen Android Void, Xnotice RAT und weit verbreitete infizierte Set-Top-Boxen.
Zscaler (NASDAQ: ZS) نشر تقريره عن تهديدات 2025 للهواتف المحمولة وإنترنت الأشياء وOT في 5 نوفمبر 2025، مُشيراً إلى زيادة بنسبة 67% سنويًا في معاملات برمجيات Android الخبيثة ووجود 239 تطبيقاً Google Play خبيثاً تم تحميلها 42 مليون مرة.
يُشير التقرير إلى ارتفاع بنسبة 387% في الهجمات على قطاع الطاقة، وهجمات IoT مركزة في التصنيع والنقل (كلاهما 20.2%)، وأن الولايات المتحدة تشكل 54% من حركة مرور برمجيات IoT الخبيثة. نتائج إضافية: الإعلانات (Adware) تقود الحالات المحمولة بنسبة 69%، وتشكّل Mirai/Mozi/Gafgyt نحو 75% من حمولات IoT، وتوجد تهديدات جديدة تشمل Android Void وXnotice RAT وأجهزة التلفزيون الذكية المصابة على نطاق واسع.
- Android malware transactions up 67% YoY
- 239 malicious Play Store apps with 42M installs
- Energy sector attacks rose 387% YoY
- Mirai, Mozi, Gafgyt comprise ~75% of IoT payloads
- Adware accounts for 69% of mobile threat cases
- Manufacturing and Transportation each represent 20.2% of IoT attacks
- US receives 54% of IoT malware traffic
- Android Void infected 1.6M TV boxes
Insights
Rising mobile and IoT attacks concentrate risk on critical industries and validate demand for cloud Zero Trust security.
The report documents a 67% year‑over‑year jump in Android malware transactions and a striking 387% increase in attacks on the energy sector, plus 239 malicious Play Store apps with 42 million installs, which together describe a clear mechanism: threat actors exploit popular app categories and widely deployed IoT/OT endpoints to gain high-impact access. These facts show attackers target high-dependency systems and trusted distribution channels, increasing the volume and potential impact of incidents.
Key dependencies and risks include heavy concentration of IoT malware families (Mirai, Mozi, Gafgyt ~75% combined) and geographic clustering of activity (mobile: India
Watch for three concrete, monitorable signals over the next 3–12 months: wider industry uptake or procurement notices referencing Zero Trust or cloud‑native IoT security, follow‑on telemetry showing whether Mirai/Mozi share of blocked transactions rises or falls, and any reported incidents in the energy, manufacturing, or transportation verticals tied to mobile/IoT compromises. These metrics will indicate whether the threat surge translates into sustained demand for the defensive offerings described.
The Report Reveals 239 Malicious Play Apps with Over 42M User Installs
Key Findings:
- Critical infrastructure in the energy sector experienced a
387% increase in attacks compared to the previous year - India continues to be the top target for mobile attacks, with
26% of activity - The US remains the top target for IoT attacks, with
54% of activity
SAN JOSE, Calif., Nov. 05, 2025 (GLOBE NEWSWIRE) -- Zscaler, Inc. (NASDAQ: ZS), the leader in cloud security, today published the findings of its Zscaler ThreatLabz 2025 Mobile, IoT, and OT Threat Report, outlining how threat actors are leveraging malware attacks and constantly evolving their tactics. The report uncovered hundreds of malicious apps in the Google Play Store that have been downloaded over 40 million times, targeting users that are searching for productivity and workflow apps. Based on Zscaler's mobile telemetry dataset, the ThreatLabz team identified several emerging mobile threats and new malicious activity, providing valuable insights to help enterprises stay ahead of attackers in a mobile-first world.
Hundreds of malicious apps downloaded over 40 million times
Similar to last year, this year we again saw threat actors developing and releasing malicious applications targeting trusted marketplaces and hybrid work environments. The result, which the report reveals is a
A key distribution channel for this malware was the "Tools" category, disguising malicious applications as productivity and workflow tools. This tactic capitalizes on users' trust in functionality-driven applications–a trust that is particularly strong in hybrid and remote work settings where mobile devices are integral to professional tasks.
Manufacturing remains a top target for mobile and IoT attacks
ThreatLabz's analysis of Android attack volumes reveals that the Manufacturing and Energy sectors remain prime targets for cybercriminals due to the potential for significant returns. Notably, the energy sector experienced a substantial
In the IoT landscape, the Manufacturing and Transportation sectors continue to be the most frequently targeted verticals. This year, each sector accounted for
Most prevalent IoT malware
Roughly
Mobile attacks cluster in India, US and Canada; US is the IoT threat epicenter at 54 percent
Worldwide, mobile threats have surged, with many of these attacks concentrated in three key regions: India, accounting for
The top five countries that receive the most mobile malware traffic are:
- India (
26% ) - United States (
15% ) - Canada (
14% ) - Mexico (
5% ) - South Africa (
4% )
The report also revealed that the US is both a hub for IoT activity (
- United States (
54% ) - Hong Kong (
15.% ) - Germany (
6% ) - India (
5% ) - China (
4% )
“Attackers are pivoting to areas with maximum impact. We’re seeing a YoY rise of
Additional highlights and new findings this year
- A new backdoor called Android Void malware has infected 1.6 million Android-based TV boxes, primarily in India and Brazil
- New Remote Access Trojan (RAT), Xnotice, was identified for targeting job seekers in the oil and gas industry, particularly in MENA
- Adware overtook the Joker malware family as the top mobile threat, with a leading
69% of cases, while Joker dropped to23% of cases, from38% last year - Threat actors are abandoning card-focused fraud in favor of mobile payments
Defending against growing IoT, OT and Mobile threats
Zscaler Zero Trust Branch delivers comprehensive security and operational efficiency for branch offices, remote sites, and distributed networks, designed for environments that rely heavily on mobile, IoT, cellular IoT, and OT technologies. Using a cloud-native and AI-driven Zero Trust architecture, Zscaler aims to ensure all users, devices, and applications are safeguarded with continuous real-time verification and robust policy enforcement, regardless of their location relative to the traditional network perimeter.
Zscaler Cellular offers secure, scalable, and efficient connectivity as a service for IoT and mobile devices that rely on cellular connections. This solution, powered by the Zscaler Zero Trust Exchange™ platform, addresses the growing security challenges posed by billions of IoT devices and mobile endpoints, which traditional security methods often fail to secure effectively. It achieves this by enforcing granular policies, providing centralized visibility, and eliminating attack surfaces for all cellular traffic.
Download your copy
The 2025 Mobile, IoT, and OT Threat Report highlights the critical importance of securing mobile endpoints, IoT devices, and OT systems. Access the full report at https://www.zscaler.com/campaign/threatlabz-mobile-iot-ot-report.
Research Methodology
Mobile
The research methodology for this report includes analysis of mobile transactions and associated cyberthreats based on data collected from the Zscaler cloud between June 2024 and May 2025. The dataset comprises more than 20 million threat-related mobile transactions.
IoT/OT
The team focused their research on understanding the distinct attributes and activity of IoT devices via device fingerprinting (DFP) and analyzing the IoT malware threat landscape.
Device fingerprinting data from March 2025 to May 2025 included:
- A complete inventory of devices, including device types and manufacturers
- The volume and source of IoT device transactions
- The industries and geographies contributing to IoT traffic
IoT malware threat data from June 2024 to May 2025 included:
- The most active malware families
- The industries and geographies most targeted by IoT attacks
- The top attacked devices
About Zscaler
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across more than 160 data centers globally, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
Media Contact
Taylor Dunton, Senior Director, Public Relations, press@zscaler.com
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/a9909238-c36f-4286-a7b6-5916db8e5847