Overview
On Android the dominant techniques are sideloaded APKs, trojanised apps in third-party stores, and abuse of accessibility services to read every screen.\nBecause so many accounts use SMS one-time codes, SMS-reading malware effectively defeats second-factor authentication.\niOS is not immune: malicious profiles and enterprise certificates have carried working spyware.
Indicators of Compromise
Signals that suggest this is present on a system.
- Sideloaded applications from unknown sources
- Accessibility permission granted to an unknown app
- Unexplained SMS or premium-rate charges