Enterprise mobile devices are now the front line of AI-assisted phishing, according to a new mobile threat report published today.
Zimperium detected more than 2.5 million phishing attacks on employee mobile devices over the last twelve months, with malicious link clicks up 400% and the number of devices where an employee clicked at least one up 151%.
Phishing events overall climbed 460% between early 2024 and May 2026, and mobile-targeted phishing succeeds around 40% more often than traditional email phishing.
Other research has linked AI with this spike. KnowBe4 recently found that 86% of phishing campaigns are now AI-generated, and Microsoft’s 2025 Digital Defense Report estimated AI-produced lures are 4.5 times more convincing than human-written equivalents.
Phishing channels are shifting to target areas outside of the enterprise security perimeter. SMS drives 39% of mobile threats, QR phishing (quishing) grew 146% Quarter over Quarter (QoQ) in Q1 2026, and malicious PDFs rose from 19% of payloads in January to 29% by March. Brand-identified targeting grew 5.4 times Year over Year (YoY).
AI-Assisted Malware Follows the Same Curve
Under the mobile phishing (mishing) surge sits a second trend: malware that generates its own code at runtime.
Zimperium’s report cited LAMEHUG, an APT28 campaign that relied on AI to design polymorphic malware on every execution.
The report also mentioned PromptLock, the first identified AI-powered ransomware, and VoidLink, a malware framework Verizon’s 2026 Data Breach Investigations Report calls a point of no return for automated threat development, built end-to-end by an AI-powered agent in six days without a human developer.
The banking ecosystem is being heavily targeted. Zimperium tracked 34 active malware families targeting 1,243 financial brands across 90 countries in 2025. Three of them (TsarBot, CopyBara and Hook) reached more than 60% of the banking and fintech apps in its mobile banking heist dataset.
Static signature detection cannot catch malware that rewrites itself each run. Zimperium’s remediation guidance is to implement layered runtime detection of each stage of the attack chain.