Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Screen Overlay Attack
Cyber Security

Screen Overlay Attack

← Back to Glossary
By NHI Mgmt Group Updated September 8, 2026 Domain: Cyber Security

A screen overlay attack uses a fake interface layered over a legitimate mobile app to capture credentials or other sensitive input. It is often aimed at banking and payment applications, where users expect to enter high-value information. The deception works because the fake screen closely matches the real app experience.

Expanded Definition

A screen overlay attack is a deceptive mobile technique that places a fake interface above a legitimate app so the user believes they are interacting with the real service. The attack is most effective when the overlay imitates the visual language, prompts, and timing of high-trust apps such as banking, wallet, or payment screens.

The boundary matters. A simple phishing page is delivered before the app opens; an overlay attack occurs during or after the legitimate app is already in use, which makes it harder for users to detect. It also differs from ordinary pop-up abuse because the goal is not just annoyance or redirection, but capture of PINs, passwords, one-time codes, or payment details. In mobile security discussions, this is usually treated as a user-interface deception and input interception problem rather than a network-layer attack.

Practitioners should note a common misunderstanding: the overlay itself may not need to look perfect if it appears at the exact moment the user expects to authenticate or approve a transaction. Timing and context often matter as much as visual fidelity.

Examples and Use Cases

  • A counterfeit login panel appears on top of a genuine banking app and harvests credentials when the user attempts to sign in.
  • A fake transaction-confirmation screen overlays a payment app and captures approval details or authentication input before the real app resumes.
  • An attacker uses malicious mobile software with overlay capability to intercept one-time passcodes or recovery codes entered into a trusted service.
  • A fraud workflow mimics a device upgrade or security check, then overlays the legitimate app to obtain sensitive account data at the moment of trust.

These attacks are especially effective in mobile environments where users are accustomed to rapid approval prompts and short authentication flows. The tradeoff for defenders is that stronger friction, such as step-up verification or app hardening, can reduce convenience while lowering the chance that a user accepts a forged screen.

For a broader view of how mobile deception and credential theft map to adversary behaviour, MITRE ATT&CK Enterprise Matrix provides a useful threat-model lens.

Security Implications

Screen overlay attacks undermine the trust boundary between the user and the application. When the overlay is convincing enough, the victim may disclose credentials, approve a fraudulent payment, or reveal a session-bypass code that lets the attacker continue without further interaction. The immediate consequence is account compromise, but the wider impact can include unauthorised transfers, identity takeover, and fraud against downstream payment or banking controls.

These attacks also create visibility problems. Because the user believes they interacted with the real app, support teams may see only normal-looking login attempts or transaction approvals, not the moment of deception. That makes the attack difficult to distinguish from routine user error unless the organisation has strong device telemetry, authentication anomaly detection, or mobile-risk signals.

The practical failure mode is not just stolen input. It is the collapse of assurance at the exact point where the organisation assumes the user is making a deliberate, informed choice.

Domain and Governance Relevance

In mobile security governance, screen overlay attacks sit at the intersection of application integrity, transaction trust, and anti-fraud design. The issue is not simply malware presence, but whether the organisation can still trust what the user saw when they approved access or payment. That makes the term relevant to authentication design, mobile app hardening, and customer protection controls.

Where the workflow involves financial authorisation or sensitive identity actions, the attack has direct governance impact because a forged screen can defeat otherwise sound credential policy. Organisations that rely on mobile approvals need to treat the user interface as part of the trust chain, not just the transport or backend systems.

For teams assessing emerging mobile fraud patterns, CISA cyber threat advisories can help contextualise broader abuse trends, while the MITRE ATT&CK Enterprise Matrix helps relate overlay-based credential capture to recognised adversary behaviour. In NHI-heavy environments, the same concern extends to mobile approval flows used to authorise access for service accounts, admin workflows, or delegated devices.

Risk and Threat Considerations

Screen overlay attacks create a material credential-theft and transaction-fraud risk because they exploit the user’s trust in a legitimate app session. The threat is strongest where high-value authentication or payment input can be captured without the user noticing the switch in interface.

Failure mechanism: Malicious software or a deceptive mobile layer is presented above the real application, intercepting input at the point of entry and harvesting secrets, codes, or approvals before the genuine app receives them.

Impact: Attackers can obtain account access, authorise fraudulent actions, bypass step-up checks, and trigger downstream fraud, support burden, and loss of trust in mobile approval workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, CIS Controls v8 and NIST CSF 2.0 set the technical controls, and PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1518.001 — Security Software DiscoveryOverlay malware often depends on mobile abuse patterns and defence bypass behavior.
Recommendation — Map overlay-enabled fraud to attacker technique patterns and hunt for suspicious app-layer abuse.
CIS Controls v816 — Application Software SecurityScreen overlays exploit weak mobile app trust and insecure interaction handling.
Recommendation — Harden mobile app interactions so sensitive prompts cannot be trivially spoofed or intercepted.
NIST CSF 2.0PR.AC — Access ControlThe attack bypasses assurance at the authentication and approval boundary.
DE.CM — Security Continuous MonitoringOverlay attacks are often visible only through device and authentication telemetry.
Recommendation — Strengthen access control assurance around mobile sign-in and transaction approval points. Monitor mobile telemetry for anomalous overlay behavior and suspicious authentication patterns.
PCI DSS v4.06 — Develop and Maintain Secure Systems and SoftwarePayment-app overlay fraud threatens trusted payment entry and approval flows.
Recommendation — Protect payment interfaces against spoofing that could capture cardholder or approval data.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org