New Spyware Threats Pose as Secure Messaging Apps

02 Oct 2025

Cybersecurity experts at ESET have spotlighted two significant spyware campaigns, spotlighting how attackers disguise malware as reputable messaging apps. The research identifies two distinct spyware families that exploit the demand for secure messaging services.

Deceptive Distribution Channels

The spyware, identified as Android/Spy.ProSpy and Android/Spy.ToSpy, is ingeniously masked, with ProSpy posing as an upgrade for apps like Signal and the now out-of-service ToTok app, while ToSpy directly impersonates the ToTok app. Unlike legitimate applications, these malicious counterparts are unavailable on official app stores, instead distributed via counterfeit websites that appear authentic.

One such deceit involves a website mimicking the Samsung Galaxy Store, tricking users into downloading what they believe to be a legitimate ToTok app. This strategy, combined with phishing practices, suggests a concentrated effort that could be region-specific, with confirmed activities notably observed in the UAE.

A Timeline of Threats

The ProSpy campaign can be traced back to 2024, indicating a sustained effort over time, while evidence for the ToSpy campaign points towards activity beginning around mid-2022. Despite the differing timelines, both spyware variants are unified in their methodology, requesting unfettered access to sensitive data upon installation.

Intrusive Capabilities

Upon gaining the required permissions, these applications operate stealthily, gathering an array of user information including contact lists, SMS, and multimedia files. This data is relayed back to their command-and-control servers, which are still operational, particularly in the case of ToSpy.

The continuity of the ToSpy campaign highlights the persistence of these threats, underlining the importance for users to exercise caution, especially when downloading from unofficial sources. The red flags include requests for extensive permissions from unknown apps.

Security Precautions

ESET's researcher, Štefanko, stresses the necessity for users to remain vigilant, advising against downloading apps from third-party app stores, and to disable features that allow installations from unknown origins. This proactive stance is crucial in safeguarding against such threats.

In an ever-evolving digital landscape, maintaining a guarded approach towards app installations is paramount, as threats like ProSpy and ToSpy showcase the sophisticated lengths to which attackers will go to exploit unsuspecting users.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5964130
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1093024
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
445558
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
387424
downloads

News and reviews for Mobile Android

New Spyware Disguises as Messaging Apps in UAE

Researchers discover Android spyware, ProSpy and ToSpy, posing as Signal and ToTok in UAE. These disfuised apps target sensitive personal data through third-party installations.

Read more

New Spyware Threats Pose as Secure Messaging Apps

ESET identified two new Android spyware families exploiting secure app demand. Spyware campaigns target apps like Signal and ToTok, using fake websites for distribution.

Read more

T-Mobile Expands T-Satellite App Access for Off-Grid Use

T-Satellite opens access to apps like WhatsApp, X, and more off-grid. Available to Android and iOS users, T-Mobile expands its app list to enhance connectivity when cellular signals are absent.

Read more

Spyware Impersonating Secure Apps Raises Concerns

Researchers discovered new Android spyware campaigns posing as secure messaging apps, such as Signal and ToTok. Distributed through fake websites, these spyware families exfiltrate sensitive data from compromised devices, focusing on users in the UAE.

Read more

Sideloading on Android to Continue Amid New Google Changes

Google confirms Android sideloading will remain, with new developer verification aimed at enhancing user and developer security.

Read more

ElephTV Introduces Innovative Streaming Solutions in South Africa

ElephTV, a new South African Android streaming app, targets high data costs and unreliable internet. With a data-saving feature and diverse content, it offers a 3-day free VIP pass and a referral program for users.

Read more

Meta Elevates Android Apps with Baseline Profiles

Meta enhances Android app performance using Baseline Profiles, addressing startup and journey challenges, achieving up to 40% metric improvements.

Read more

MyPB App to Require Android 12, iOS 16 for Continued Use

Public Bank announces minimum OS updates for MyPB, aiming to enhance security and performance. Customers should ensure their devices have Android 12 or iOS 16 to maintain access.

Read more

Sideloading to Continue on Android Amid New Developer Verification

Google affirms sideloading on Android remains as new developer verification aims for safety. Concerns rise about its impact on independent app stores.

Read more

Pixel Launcher Test Aims to Improve App Opening Efficiency

Google experiments with a Pixel Launcher tweak to streamline app access by transforming the search bar's enter key function, offering users smoother app launch capabilities.

Read more