Mobile malware infections in Philippines exceed global average

MANILA, Philippines — Malware infection among Filipino mobile users has reached 16 percent, almost double the global average of nine percent, mobile app security firm Appdome warned, raising red flags over the country’s exposure to cybercrime.
In an interview with The STAR, Appdome mobile app security evangelist Jan Sysmans said the Philippines’ mobile-first economy has made it a prime target for cybercriminals exploiting the rapid shift to online banking and digital wallets.
“As a mobile-first country, the Philippines remains to be a prime target for cybercriminals, particularly with the increasing reliance on mobile banking and digital transactions,” Sysmans said.
According to Appdome’s 2024 Philippine Mobile Consumer Survey, 54.7 percent of Filipinos use mobile applications more than websites, while 61.6 percent rely on e-wallets for payments.
However, the same survey showed that 45.3 percent of consumers reported falling victim to cyberattacks or malware, while 36.4 percent had encountered social engineering scams.
Of the infections in the Philippines, 60 percent involve spyware attacks that record users’ keystrokes and login credentials.
Around 30 percent involve data harvesters stealing personal information like usernames, passwords and credit card information.
The remaining 10 percent are banking and payment Trojans designed to compromise transactions, Sysmans said.
He added that malware families such as Blankbot, Godfather, ToxicPanda and Sharkbot “continue to pose serious threats” in the country, using overlay attacks, key logging and remote desktop functions to bypass app security.
Sysmans also warned that cybercriminals are now leveraging artificial intelligence (AI) to supercharge their methods, particularly bots and biometric spoofing.
“One of the shifts we’ve seen is the use of AI to imitate real user behavior. These bots are capable of simulating human gestures with sophistication, such as taps, swipes, or scrolls, and can replicate natural timing and patterns to avoid detection,” he said.
Cybercriminals also take advantage of AI-powered techniques such as face cloning, liveness spoofing and deepfake images to bypass biometric security, while automating fraudulent account creation with synthetic identities and virtualized devices that evade standard know your customer checks.
“The sad reality is that no single biometric method can guarantee full protection. Criminal organizations have figured out a way to bypass each type of parametric indicator, undermining the integrity and destroying the trust,” Sysmans said.
- Latest
- Trending


























