Android Spyware Targets UAE Messaging Users
bankinfosecurityFake Messaging Apps Use Previously Undocumented Malware Prajeet Nair (@prajeetspeaks) • October 3, 2025

Two Android spyware campaigns using previously undocumented spyware masquerade as upgrades or plugins for secure messaging apps Signal and ToTok, warn researchers. The two campaigns appear to target residents of the United Arab Emirates.
See Also: When Identity Protection Fails: Rethinking Resilience for a Modern Threat Landscape
Eset researchers identified the two spyware families, which they dub "ProSpy" and "ToSpy." Once installed, they continually exfiltrate sensitive data. Eset said it discovered the ProSpy campaign in June but that data shows it's been ongoing since 2024.
Both campaigns trick users into side loading malicious apps by appearing to be a Signal or ToTok upgrade or by outright impersonating the ToTok app. One way they maintain legitimacy is having users download or interact with the ...
Copyright of this story solely belongs to bankinfosecurity . To see the full text click HERE