New Spyware Threats Pose as Secure Messaging Apps

02 Oct 2025

Cybersecurity experts at ESET have spotlighted two significant spyware campaigns, spotlighting how attackers disguise malware as reputable messaging apps. The research identifies two distinct spyware families that exploit the demand for secure messaging services.

Deceptive Distribution Channels

The spyware, identified as Android/Spy.ProSpy and Android/Spy.ToSpy, is ingeniously masked, with ProSpy posing as an upgrade for apps like Signal and the now out-of-service ToTok app, while ToSpy directly impersonates the ToTok app. Unlike legitimate applications, these malicious counterparts are unavailable on official app stores, instead distributed via counterfeit websites that appear authentic.

One such deceit involves a website mimicking the Samsung Galaxy Store, tricking users into downloading what they believe to be a legitimate ToTok app. This strategy, combined with phishing practices, suggests a concentrated effort that could be region-specific, with confirmed activities notably observed in the UAE.

A Timeline of Threats

The ProSpy campaign can be traced back to 2024, indicating a sustained effort over time, while evidence for the ToSpy campaign points towards activity beginning around mid-2022. Despite the differing timelines, both spyware variants are unified in their methodology, requesting unfettered access to sensitive data upon installation.

Intrusive Capabilities

Upon gaining the required permissions, these applications operate stealthily, gathering an array of user information including contact lists, SMS, and multimedia files. This data is relayed back to their command-and-control servers, which are still operational, particularly in the case of ToSpy.

The continuity of the ToSpy campaign highlights the persistence of these threats, underlining the importance for users to exercise caution, especially when downloading from unofficial sources. The red flags include requests for extensive permissions from unknown apps.

Security Precautions

ESET's researcher, Štefanko, stresses the necessity for users to remain vigilant, advising against downloading apps from third-party app stores, and to disable features that allow installations from unknown origins. This proactive stance is crucial in safeguarding against such threats.

In an ever-evolving digital landscape, maintaining a guarded approach towards app installations is paramount, as threats like ProSpy and ToSpy showcase the sophisticated lengths to which attackers will go to exploit unsuspecting users.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508589
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735533
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746751
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
496426
downloads

News and reviews for Mobile Android

Top Coin Apps Enhance Coin Valuation and Identification

Coin apps improve currency valuation and identification, aiding collectors and investors in the U.S. as of 2026. Key apps include CoinKnow and PCGS CoinFacts.

Read more

Optimize Android Apps Beyond Frontend with Backend Focus

Android apps need robust architecture and backend integration for high performance. Developers should focus beyond the UI to address backend challenges.

Read more

Explore Alternatives as Android Auto Exits Vehicles

Automakers shift from Android Auto, prompting tech users to adapt with alternatives.

Read more

WeChat Faces Potential U.S. Ban Amid Security Concerns

WeChat, a Tencent-owned app, may face a U.S. ban due to alleged ties with Chinese criminal networks, impacting national security.

Read more

Discounted Android App Deals for Gamers and Users

Discover top Android app deals available now, featuring discounted games for 2026-01-27.

Read more

iA Writer Boosts Focus for Writing-First Users

iA Writer helps reclaim focus for writers with distraction-free design. Notion users may prefer its simplicity for dedicated writing tasks.

Read more

Android Deals: Price Drops on Top Apps and Games

Check out the latest Android deals featuring popular games like D&D Lords of Waterdeep and Beastie Bay DX.

Read more

Today's Top App Deals: Lords of Waterdeep & More

Discover the latest app deals on Android with price drops for top games including Lords of Waterdeep and Legends of Heropolis.

Read more

Warframe Expands to Android with Cross Play, Save Features

Warframe launches on Android 2025-02-18, offering Cross Play and Save. Players gain rewards for early participation.

Read more

Waze Enhances Features for Android Auto Users

Waze adds improved navigation and alerts on Android Auto. Users in the US, Canada, Mexico, and France will see changes soon.

Read more