New Spyware Disguises as Messaging Apps in UAE

02 Oct 2025

In a concerning revelation for the digital security landscape, cybersecurity researchers have identified two Android spyware families impersonating the popular messaging applications Signal and ToTok. The recently uncovered cyber-espionage operations appear to primarily target users within the United Arab Emirates. The findings, revealed by ESET in June, suggest that these spyware campaigns may have commenced as far back as last year.

The campaigns, which the researchers have named ProSpy and ToSpy, exploit the guise of legitimate communication apps to infiltrate users' devices. ProSpy masquerades as both Signal and ToTok, while ToSpy emulates the now-defunct ToTok, shuttered in 2020 after being linked to the UAE government. Despite ToTok's official discontinuation, the cybercriminals introduced an upgraded version named ToTok Pro, offering it surreptitiously online.

Dangers Hidden in Plain Sight

The spyware-laden apps are not available via official app stores like Google Play. Instead, they require users to conduct manual installations from third-party sites designed to appear like legitimate app distributors. In one notable instance, a phishing site cleverly mimicked the Samsung Galaxy Store, potentially duping unsuspecting users with its semblance of authenticity. Upon installation, these applications solicit various permissions from the user, including access to contacts, text messages, and stored files. Once authorized, the spyware has the capability to extract an array of sensitive data, such as device information, audio recordings, video, images, and chat backups.

Analyzing the nuances of these campaigns revealed a sophisticated method of targeting and collection aimed at residents of the UAE. Confirmed detections in the region, coupled with the presence of phishing sites and domains featuring the country code "ae," have led researchers to posit a highly localized focus for these malevolent applications.

Implications and Response

In response to these discoveries, digital security experts emphasize the importance of vigilance among users, particularly in vulnerable regions. It is crucial for individuals to remain cautious about the sources from which they download applications and to restrict application permissions to only those that are absolutely necessary for functionality.

These unfolding developments underscore the persistent evolution of cyber threats and the ongoing battle between cybersecurity specialists and malicious entities. With mobile devices playing an ever-increasing role in our daily lives, the urgency for heightened security measures becomes more pressing.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6290780
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1234036
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
485154
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
452029
downloads

News and reviews for Mobile Android

Google Opens Play Store to External Payments in U.S.

Starting 2025-10-29, Android users in the U.S. can access external app info and payments in the Play Store, following a court order.

Read more

Google Play Store Opens to External Payments in U.S.

Starting 2025-10-29, U.S. Play Store users can access external payments, easing app pricing and support.

Read more

Google Expands Developer Verification to All Android Apps

Google's expanded developer verification for Android apps begins in 2026, challenging innovation and increasing scrutiny.

Read more

Android Tracker Recovers Lost Luggage at Airport

Android Bluetooth tracker helps retrieve lost luggage at Athens airport, easing travel stress. Demonstrates accuracy and privacy features.

Read more

Android Auto Tests New Multi-Card Media Interface

Android Auto is testing a swipeable multi-card media interface in v15.6.154404 beta to streamline audio app use in cars.

Read more

Xsolla Empowers Android Developers with New Revenue Options

Xsolla enables U.S. Google Play developers to use external purchase links, diversifying revenue options as of 2025-10-29.

Read more

Google Home 4.2 App Enhances User Experience

Google Home 4.2 updates optimize camera functions and Nest lock features on Android and iOS.

Read more

Herodotus Malware Evades Detection on Android Devices

Herodotus, a new Android malware, mimics human typing to bypass security, impacting users in Italy and Brazil.

Read more

Android Deals: Major App Discounts on 2025-10-29

Discover today's significant Android deals, featuring discounts on popular games like Thimbleweed Park and The Last Roman Village.

Read more

Google App Testing 'Search Live' Interrupt Feature

Google app tests 'Interrupt Live responses' toggle for Search Live. Expanded AI features in beta point towards future possibilities.

Read more