Ukraine's SSSCIP said this week that Russian actors are targeting Ukrainian military and government phones with malicious Android apps and the DarkSword iPhone exploit kit. The campaign uses watering-hole sites, so the victim gets hit by visiting a legitimate-looking page rather than by installing an obvious app.
On iPhone, DarkSword abuses Safari and iOS flaws through a compromised website; on Android, the lures deliver malicious apps from decoy sites. In both cases, the point is fast collection: once the phone is compromised, attackers can pull credentials, messages, contacts, and call history, then drop traces instead of staying resident.
For teams that rely on mobile devices for sensitive communications, the trust boundary is the browser as much as the app store. A site visit can now be enough to expose operational communications, even when no suspicious install ever happened.