The employee's corporate Android phone receives an SMS from an unknown number claiming to be from the IT department, with urgent language about a security vulnerability and a link to download a security patch APK.
An employee receives a text message: "Your IT department has detected a security risk. Install this security update immediately: [link]". The link goes to an APK download. What is this attack and what should the employee do?
- A.This is a smishing attack distributing malware under the guise of a security update; the employee should not click the link, should forward the message to the IT security team for analysis, and should delete the message. Legitimate IT departments distribute updates via MDM/EMM systems (which push updates silently) or through the official device OS update mechanism, not via SMS links to APK downloads.
- B.The employee should follow the link and download the archive, and then scan it with a mobile antivirus product before installing anything because a clean verdict establishes that the update is genuine (the scanner checks the package against a signature set): a corporate handset carries that protection already, and the reporting step can wait until the scan completes. IT will want the sample either way.