An overlay attack is a mobile attack in which a malicious app draws a fake or transparent interface on top of a legitimate one. The user believes they are interacting with the real app, but input is captured or redirected by the attacker-controlled layer.
Expanded Definition
An overlay attack is a user-interface deception technique that exploits a device’s ability to render one app above another. In mobile environments, the attacker-controlled layer can imitate a login prompt, payment screen, permission dialog, or session timeout, then capture keystrokes, taps, or approval actions meant for the legitimate app.
In NHI and IAM contexts, the risk is not limited to stolen personal credentials. Overlay attacks can also trick users into approving access requests, revealing one-time codes, or re-entering credentials that grant access to service consoles, admin portals, and agent control planes. Guidance varies across vendors on whether overlay behavior should be treated primarily as malware, phishing, or a form of credential interception, but the security outcome is the same: the user authenticates into the attacker’s flow instead of the real one. For broader NHI governance, this becomes especially relevant when mobile endpoints are used to approve privileged actions or manage secrets, as discussed in the Ultimate Guide to NHIs — Key Challenges and Risks and the Top 10 NHI Issues. The most common misapplication is treating overlay attacks as ordinary phishing, which occurs when defenders overlook malware on the endpoint creating the fake prompt.
Examples and Use Cases
Implementing protections against overlay attacks rigorously often introduces friction, requiring organisations to balance user convenience against stronger app and device hardening.
- A malicious banking-style app overlays a fake MFA screen and captures a user’s PIN before forwarding the real session to the legitimate service.
- A device enrolled in mobile device management displays a permission overlay that imitates a corporate sign-in prompt, leading the employee to approve a high-risk login.
- An attacker uses a transparent layer to intercept taps inside a secrets-management app, then exfiltrates tokens, API keys, or recovery codes.
- In a remote-work scenario, a compromised phone overlays a spoofed SSO page during access approval, redirecting the user into attacker-controlled authentication.
- Mobile threat reports from CISA cyber threat advisories and ATT&CK-style mapping help defenders recognise this as an interaction hijack rather than a simple credential replay, while 52 NHI Breaches Analysis shows how quickly weak identity controls can cascade once an initial access path is compromised.
Why It Matters in NHI Security
Overlay attacks matter in NHI security because they can turn a trusted human approval step into an attacker-controlled identity event. When a user is deceived into entering credentials, approving device trust, or confirming a privileged action, the downstream impact often reaches service accounts, API keys, automation pipelines, and other NHIs that depend on that approval chain. This is why mobile trust boundaries must be treated as part of identity governance, not as a separate usability issue.
NHIMG research shows that 79% of organisations have experienced secrets leaks and 80% of identity breaches involved compromised non-human identities, which means a single deceptive mobile prompt can contribute to a much larger compromise path. The Ultimate Guide to NHIs — Why NHI Security Matters Now and OWASP NHI Top 10 both reinforce that identity compromise is usually a chain, not a single event. Organisations typically encounter the privilege escalation, token theft, or automated misuse only after an unusual approval or account takeover has already occurred, at which point overlay attack analysis becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 | Overlay abuse can expose secrets, tokens, and approval flows tied to NHI credentials. |
| NIST CSF 2.0 | PR.AC-7 | Identity proofing and authentication integrity are undermined when users are tricked by fake overlays. |
| NIST SP 800-63 | The digital identity model depends on authentic, user-intended authentication events. | |
| NIST Zero Trust (SP 800-207) | IA-2 | Zero Trust assumes each access event is verified, even when the endpoint UI is deceptive. |
| NIST AI RMF | AI systems with mobile approval or agent-control interfaces need risk controls against deceptive interactions. |
Harden mobile approval paths and remove secret exposure from any workflow reachable through deceptive UI layers.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org