The employee's corporate Android phone receives an SMS from an unknown number claiming to be from the IT department, with urgent language about a security vulnerability and a link to download a security patch APK.
An employee receives a text message: "Your IT department has detected a security risk. Install this security update immediately: [link]". The link goes to an APK download. What is this attack and what should the employee do?
- A.A) This is a smishing attack distributing malware under the guise of a security update; the employee should not click the link, should forward the message to the IT security team for analysis, and should delete the message. Legitimate IT departments distribute updates via MDM/EMM systems (which push updates silently) or through the official device OS update mechanism, not via SMS links to APK downloads.
- B.B) The employee should install the update immediately because security patches are time-sensitive and any delay increases the device's vulnerability window.
- C.C) This is a legitimate IT communication; corporate SMS security update channels are standard enterprise practice for urgent patches.
- D.D) The employee should click the link but scan the APK with a mobile antivirus before installing to ensure it is safe.