Zscaler's report reveals a surge in cyberattacks across energy, mobile, and IoT sectors, highlighting escalating threats.
Quiver AI Summary
Zscaler, Inc. has released its 2025 Mobile, IoT, and OT Threat Report, revealing alarming increases in cyber threats, particularly in the energy sector, which saw a 387% rise in attacks compared to last year. The report identifies India as the leading target for mobile attacks, accounting for 26% of the activity, while the United States is the top target for IoT attacks at 54%. Malicious applications on the Google Play Store have been downloaded over 40 million times, with a significant focus on targeting users in hybrid work environments. The report highlights a 67% year-over-year increase in Android malware transactions, especially spyware and banking malware. It underscores the need for a comprehensive security approach through Zscaler's Zero Trust architecture to address evolving threats across mobile and IoT environments.
Potential Positives
- Zscaler's 2025 Threat Report reveals a significant 387% increase in attacks on the energy sector, highlighting the critical need for robust security solutions, which positions Zscaler as a key player in addressing this escalating threat.
- The report exposes hundreds of malicious apps on the Google Play Store, showcasing Zscaler's capabilities in threat detection and providing valuable insights for enterprises to safeguard their mobile environments.
- With the identification of new malware and significant findings, Zscaler reinforces its commitment to innovation in security, which may enhance its reputation and attract more customers seeking advanced protection against emerging threats.
- The increased focus on Zero Trust security solutions across branches and IoT environments highlights Zscaler's strategic direction in addressing modern cybersecurity challenges, solidifying its leadership in the cloud security market.
Potential Negatives
- The 387% increase in attacks on the energy sector suggests a significant vulnerability in critical infrastructure, which could raise concerns about the effectiveness of Zscaler's security solutions.
- The report highlights the discovery of hundreds of malicious apps in the Google Play Store, downloaded over 40 million times, indicating a potential failure in safeguarding users from significant security threats.
- The increase in Android malware transactions by 67% year-over-year reflects a growing threat landscape that could undermine confidence in the company's mobile security capabilities.
FAQ
What are the key findings of the 2025 Threat Report?
The report indicates a 387% rise in attacks on the energy sector and highlights significant mobile and IoT threats targeting critical infrastructure.
Which country is the top target for mobile attacks?
India is the leading target for mobile attacks, accounting for 26% of all mobile threat activity.
What sectors are most frequently targeted by IoT attacks?
The Manufacturing and Transportation sectors are the most frequently targeted by IoT attacks, each making up 20.2% of incidents.
How has Android malware activity changed?
There has been a 67% year-over-year increase in Android malware transactions, with hundreds of malicious apps identified in the Google Play Store.
What security measures does Zscaler recommend?
Zscaler suggests a Zero Trust approach combined with AI-powered threat detection to safeguard against evolving cyber threats.
Disclaimer: This is an AI-generated summary of a press release distributed by GlobeNewswire. The model used to summarize this release may make mistakes. See the full release here.
$ZS Insider Trading Activity
$ZS insiders have traded $ZS stock on the open market 54 times in the past 6 months. Of those trades, 0 have been purchases and 54 have been sales.
Here’s a breakdown of recent trading of $ZS stock by insiders over the last 6 months:
- AJAY MANGAL has made 0 purchases and 12 sales selling 120,000 shares for an estimated $36,106,497.
- CHARLES H GIANCARLO has made 0 purchases and 8 sales selling 67,824 shares for an estimated $20,416,445.
- ROBERT SCHLOSSMAN (Chief Legal Officer) has made 0 purchases and 14 sales selling 29,010 shares for an estimated $8,597,970.
- SYAM NAIR (CTO) has made 0 purchases and 2 sales selling 33,011 shares for an estimated $8,470,995.
- ADAM GELLER (Chief Product Officer) has made 0 purchases and 9 sales selling 28,328 shares for an estimated $8,153,294.
- MICHAEL J. RICH (CRO and President of WW Sales) has made 0 purchases and 3 sales selling 25,996 shares for an estimated $7,617,249.
- ANDREW WILLIAM FRASER BROWN has made 0 purchases and 2 sales selling 20,333 shares for an estimated $6,033,118.
- RAJ JUDGE (EVP, Corp. Strategy & Ventures) has made 0 purchases and 2 sales selling 7,481 shares for an estimated $2,167,927.
- JAGTAR SINGH CHAUDHRY (CEO & Chairman) has made 0 purchases and 2 sales selling 5,714 shares for an estimated $1,669,445.
To track insider transactions, check out Quiver Quantitative's insider trading dashboard.
$ZS Hedge Fund Activity
We have seen 536 institutional investors add shares of $ZS stock to their portfolio, and 337 decrease their positions in their most recent quarter.
Here are some of the largest recent moves:
- D. E. SHAW & CO., INC. added 1,879,992 shares (+76546.9%) to their portfolio in Q2 2025, for an estimated $590,204,688
- FMR LLC added 1,639,111 shares (+88.0%) to their portfolio in Q2 2025, for an estimated $514,582,507
- NOMURA HOLDINGS INC removed 1,397,481 shares (-99.7%) from their portfolio in Q2 2025, for an estimated $438,725,185
- DEUTSCHE BANK AG\ removed 1,387,512 shares (-76.8%) from their portfolio in Q2 2025, for an estimated $435,595,517
- HSBC HOLDINGS PLC removed 1,332,637 shares (-95.2%) from their portfolio in Q2 2025, for an estimated $418,368,059
- MARSHALL WACE, LLP removed 1,291,369 shares (-89.0%) from their portfolio in Q2 2025, for an estimated $405,412,383
- GOLDMAN SACHS GROUP INC removed 1,289,378 shares (-42.3%) from their portfolio in Q2 2025, for an estimated $404,787,329
To track hedge funds' stock portfolios, check out Quiver Quantitative's institutional holdings dashboard.
$ZS Analyst Ratings
Wall Street analysts have issued reports on $ZS in the last several months. We have seen 24 firms issue buy ratings on the stock, and 0 firms issue sell ratings.
Here are some recent analyst ratings:
- RBC Capital issued a "Outperform" rating on 10/02/2025
- Barclays issued a "Overweight" rating on 09/03/2025
- Wedbush issued a "Outperform" rating on 09/03/2025
- JP Morgan issued a "Overweight" rating on 09/03/2025
- Needham issued a "Buy" rating on 09/03/2025
- Rosenblatt issued a "Buy" rating on 09/03/2025
- Baird issued a "Outperform" rating on 09/03/2025
To track analyst ratings and price targets for $ZS, check out Quiver Quantitative's $ZS forecast page.
$ZS Price Targets
Multiple analysts have issued price targets for $ZS recently. We have seen 29 analysts offer price targets for $ZS in the last 6 months, with a median target of $334.0.
Here are some recent targets:
- Steve Koenig from Macquarie set a target price of $390.0 on 10/31/2025
- Matthew Hedberg from RBC Capital set a target price of $350.0 on 10/02/2025
- Kingsley Crane from Canaccord Genuity set a target price of $340.0 on 09/04/2025
- Brian Essex from JP Morgan set a target price of $351.0 on 09/03/2025
- Saket Kalia from Barclays set a target price of $320.0 on 09/03/2025
- Catharine Trebnick from Rosenblatt set a target price of $330.0 on 09/03/2025
- Mike Cikos from Needham set a target price of $350.0 on 09/03/2025
Full Release
Key Findings:
- Critical infrastructure in the energy sector experienced a 387% increase in attacks compared to the previous year
- India continues to be the top target for mobile attacks, with 26% of activity
-
The US remains the top target for IoT attacks, with 54% of activity
SAN JOSE, Calif., Nov. 05, 2025 (GLOBE NEWSWIRE) -- Zscaler, Inc. (NASDAQ: ZS), the leader in cloud security, today published the findings of its Zscaler ThreatLabz 2025 Mobile, IoT, and OT Threat Report, outlining how threat actors are leveraging malware attacks and constantly evolving their tactics. The report uncovered hundreds of malicious apps in the Google Play Store that have been downloaded over 40 million times, targeting users that are searching for productivity and workflow apps. Based on Zscaler's mobile telemetry dataset, the ThreatLabz team identified several emerging mobile threats and new malicious activity, providing valuable insights to help enterprises stay ahead of attackers in a mobile-first world.
Hundreds of malicious apps downloaded over 40 million times
Similar to last year, this year we again saw threat actors developing and releasing malicious applications targeting trusted marketplaces and hybrid work environments. The result, which the report reveals is a 67% year-over-year increase in Android malware transactions, reflects the continued risks of spyware and banking malware. ThreatLabz researchers identified 239 such applications hosted on the Google Play Store, which were collectively downloaded 42 million times.
A key distribution channel for this malware was the "Tools" category, disguising malicious applications as productivity and workflow tools. This tactic capitalizes on users' trust in functionality-driven applications–a trust that is particularly strong in hybrid and remote work settings where mobile devices are integral to professional tasks.
Manufacturing remains a top target for mobile and IoT attacks
ThreatLabz's analysis of Android attack volumes reveals that the Manufacturing and Energy sectors remain prime targets for cybercriminals due to the potential for significant returns. Notably, the energy sector experienced a substantial 387% increase in attacks compared to the previous year, highlighting an escalating threat to critical infrastructure and greater exploitation of vulnerabilities within these essential industries.
In the IoT landscape, the Manufacturing and Transportation sectors continue to be the most frequently targeted verticals. This year, each sector accounted for 20.2% of all observed IoT malware attacks, collectively representing over 40% of total incidents. This marks a shift from 2024, when Manufacturing alone represented 36% of total incidents, followed by Transportation at 14%. This suggests that while Manufacturing remains a critical target, threat actors are increasingly diversifying their efforts across other high-dependency IoT industries.
Most prevalent IoT malware
Roughly 40% of blocked transactions are linked to the Mirai family alone, and Mozi has overtaken Gafgyt as the second highest malware family. Together, Mirai, Mozi, and Gafgyt account for roughly 75% of all malicious payloads in IoT environments.
Mobile attacks cluster in India, US and Canada; US is the IoT threat epicenter at 54 percent
Worldwide, mobile threats have surged, with many of these attacks concentrated in three key regions: India, accounting for 26% of all mobile attacks, the United States at 15%, and Canada at 14%. India, in particular, experienced a significant 38% increase in mobile threat attacks compared to the previous year.
The top five countries that receive the most mobile malware traffic are:
- India (26%)
- United States (15%)
- Canada (14%)
- Mexico (5%)
-
South Africa (4%)
The report also revealed that the US is both a hub for IoT activity (54.1%) and a primary target for malware attacks. The top five countries that receive the most IoT malware traffic are:
- United States (54%)
- Hong Kong (15.%)
- Germany (6%)
- India (5%)
-
China (4%)
“Attackers are pivoting to areas with maximum impact. We’re seeing a YoY rise of 67% in malware targeting mobile devices and 387% in IoT/OT attacks on energy sectors often hosting critical infrastructure, which is a massive swing,” said Deepen Desai, EVP and Chief Security Officer at Zscaler. “A Zero Trust everywhere approach, combined with AI-powered threat detection, is imperative to reducing the attack surface, limit lateral movement, and provide organizations the defense they need against ever-evolving attacks.”
Additional highlights and new findings this year
- A new backdoor called Android Void malware has infected 1.6 million Android-based TV boxes, primarily in India and Brazil
- New Remote Access Trojan (RAT), Xnotice, was identified for targeting job seekers in the oil and gas industry, particularly in MENA
- Adware overtook the Joker malware family as the top mobile threat, with a leading 69% of cases, while Joker dropped to 23% of cases, from 38% last year
-
Threat actors are abandoning card-focused fraud in favor of mobile payments
Defending against growing IoT, OT and Mobile threats
Zscaler Zero Trust Branch delivers comprehensive security and operational efficiency for branch offices, remote sites, and distributed networks, designed for environments that rely heavily on mobile, IoT, cellular IoT, and OT technologies. Using a cloud-native and AI-driven Zero Trust architecture, Zscaler aims to ensure all users, devices, and applications are safeguarded with continuous real-time verification and robust policy enforcement, regardless of their location relative to the traditional network perimeter.
Zscaler Cellular offers secure, scalable, and efficient connectivity as a service for IoT and mobile devices that rely on cellular connections. This solution, powered by the Zscaler Zero Trust Exchange™ platform, addresses the growing security challenges posed by billions of IoT devices and mobile endpoints, which traditional security methods often fail to secure effectively. It achieves this by enforcing granular policies, providing centralized visibility, and eliminating attack surfaces for all cellular traffic.
Download your copy
The 2025 Mobile, IoT, and OT Threat Report highlights the critical importance of securing mobile endpoints, IoT devices, and OT systems. Access the full report at https://www.zscaler.com/campaign/threatlabz-mobile-iot-ot-report .
Research Methodology
Mobile
The research methodology for this report includes analysis of mobile transactions and associated cyberthreats based on data collected from the Zscaler cloud between June 2024 and May 2025. The dataset comprises more than 20 million threat-related mobile transactions.
IoT/OT
The team focused their research on understanding the distinct attributes and activity of IoT devices via device fingerprinting (DFP) and analyzing the IoT malware threat landscape.
Device fingerprinting data from March 2025 to May 2025 included:
- A complete inventory of devices, including device types and manufacturers
- The volume and source of IoT device transactions
-
The industries and geographies contributing to IoT traffic
IoT malware threat data from June 2024 to May 2025 included:
- The most active malware families
- The industries and geographies most targeted by IoT attacks
-
The top attacked devices
About Zscaler
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across more than 160 data centers globally, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
Media Contact
Taylor Dunton, Senior Director, Public Relations,
[email protected]
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/a9909238-c36f-4286-a7b6-5916db8e5847