The Power of Push Notification OTPs in Preventing Cyberattacks

The Growing Threat of Malware Apps and the Need for a Safer Authentication Method, More Secure User Experiences

Hafiq Iqmal
5 min readMay 24

--

Image by Freepik

In the ever-evolving world of cybersecurity, businesses and consumers are constantly playing catch-up with innovative and relentless cybercriminals. Recent cyberattacks have seen malicious software sneak onto customers’ mobile apps, reading incoming SMS messages, including those containing one-time passwords (OTPs). This alarming development has led to a drastic increase in unauthorized account takeovers, causing significant distress and financial losses.

As a developer with first-hand experience in these digital battlegrounds, I understand the urgency of addressing this issue. Fortunately, there’s a promising solution on the horizon: Push Notification OTPs. Let’s take a deep dive into this new technology, its advantages and how we can implement it effectively to safeguard our digital assets.

The Threat of Malware Apps

https://www.researchgate.net/publication/365617959_Vulnerabilities_of_the_SMS_Retriever_API_for_the_Automatic_Verification_of_SMS_OTP_Codes_in_the_Banking_Sector

First, let’s delve into the crux of the matter: the rise of malicious apps. These applications are designed to infiltrate a user’s mobile device and siphon off sensitive information, including OTPs. As two-factor authentication (2FA) has become more prevalent, cybercriminals have adapted their strategies to circumvent this additional layer of security. The OTPs, which are supposed to act as a second barrier, are being intercepted, leading to a surge in unauthorized account takeovers.

According to Securelist, in 2022, malware was used in most mobile attacks (67.78%). The shares of attacks that used Adware and RiskWare-type applications had increased to 26.91% from 16.92% in 2021 and to 5.31% from 2.38% in 2021, respectively.

This is not a hypothetical threat, but a real, tangible danger that requires immediate attention and action.

--

--

Hafiq Iqmal

Tech Lead Developer | Software Engineer | Laravel Enthusiasts | CTF Newbie | Medium writer | UiTM Alumni | Husband | Proud father of a beautiful daughter