Spyware Impersonating Secure Apps Raises Concerns

02 Oct 2025

ESET researchers have unearthed two unprecedented Android spyware campaigns targeting individuals searching for secure messaging applications like Signal and ToTok. By exploiting fake websites and social engineering, attackers have managed to spread these malevolent tools effectively.

Two distinct spyware families were identified in the ESET research: Android/Spy.ProSpy and Android/Spy.ToSpy. The former masquerades as updates or enhancements for the Signal app and the now-defunct ToTok app, whereas the latter is a direct pretender of the ToTok app itself. This ToSpy campaign is strikingly active, sustained by operational command-and-control servers.

Distribution Through Deceptive Online Channels

Intriguingly, neither of the spyware-laden apps could be found in official app stores, necessitating manual installation from bogus third-party sites. ESET researcher Štefanko explained how one such site mimicked the Samsung Galaxy Store, tricking users into downloading a compromised version of the ToTok app. Once installed, both spyware variants persist behind the scenes, continually siphoning off sensitive data from affected Android devices.

Campaign investigations revealed a pattern of phishing and counterfeit app stores, indicative of regionally focused operations, specifically targeting users in the United Arab Emirates. The ProSpy campaign, first unearthed in June 2025, suggests activity dating back to 2024. Its distribution method via forged websites mimicking Signal and ToTok highlights a sophisticated layer of maliciousness, further evidenced by the domain suffix ae.net, pointing to a likely UAE-centric focus.

Pervasive Data Exfiltration

When initiated, these spyware apps solicit access to contacts, SMS messages, and local files. If successful, ProSpy clandestinely transmits this data in the background. Additional payloads like the Signal Encryption Plugin compile and abscond with extensive device details, stored messages, contact lists, and even chat backups, including multimedia content.

In a concerning observation dated June 2025, ESET telemetry picked up activity from the Android/Spy.ToSpy family on a device within the UAE. Investigators unearthed four fraudulent distribution platforms purporting to host the ToTok app. Silent yet efficient, the ToSpy spyware covertly amasses and relays contacts, device information, chat histories, multimedia files, and sensitive documents.

Precautionary Measures and Recommendations

The research underscores a critical piece of advice: users must exercise caution when downloading applications from unofficial portals. Avoid enabling installations from unknown sources or apps falsely promising to enhance trusted services, as more often than not, they conceal a sinister agenda. Such caution is especially crucial for widely trusted applications and services, advises ESET researcher Štefanko.

This developing situation serves as a stark reminder of the intricate web of cyber threats lurking in the digital realm, emphasizing the perennial necessity for vigilance and adherence to safe online practices.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508589
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735533
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746751
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
496426
downloads

News and reviews for Mobile Android

Top Coin Apps Enhance Coin Valuation and Identification

Coin apps improve currency valuation and identification, aiding collectors and investors in the U.S. as of 2026. Key apps include CoinKnow and PCGS CoinFacts.

Read more

Optimize Android Apps Beyond Frontend with Backend Focus

Android apps need robust architecture and backend integration for high performance. Developers should focus beyond the UI to address backend challenges.

Read more

Explore Alternatives as Android Auto Exits Vehicles

Automakers shift from Android Auto, prompting tech users to adapt with alternatives.

Read more

WeChat Faces Potential U.S. Ban Amid Security Concerns

WeChat, a Tencent-owned app, may face a U.S. ban due to alleged ties with Chinese criminal networks, impacting national security.

Read more

Discounted Android App Deals for Gamers and Users

Discover top Android app deals available now, featuring discounted games for 2026-01-27.

Read more

iA Writer Boosts Focus for Writing-First Users

iA Writer helps reclaim focus for writers with distraction-free design. Notion users may prefer its simplicity for dedicated writing tasks.

Read more

Android Deals: Price Drops on Top Apps and Games

Check out the latest Android deals featuring popular games like D&D Lords of Waterdeep and Beastie Bay DX.

Read more

Today's Top App Deals: Lords of Waterdeep & More

Discover the latest app deals on Android with price drops for top games including Lords of Waterdeep and Legends of Heropolis.

Read more

Warframe Expands to Android with Cross Play, Save Features

Warframe launches on Android 2025-02-18, offering Cross Play and Save. Players gain rewards for early participation.

Read more

Waze Enhances Features for Android Auto Users

Waze adds improved navigation and alerts on Android Auto. Users in the US, Canada, Mexico, and France will see changes soon.

Read more