logo

Hackers Impersonate Secure Messaging Apps to Deploy ProSpy in Middle East Espionage Attacks

ID: 238b7d7c-1d71-5400-9bcc-f8afd9afc9e0

STIX ID: report--238b7d7c-1d71-5400-9bcc-f8afd9afc9e0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** A covert mobile espionage campaign dating back to at least 2022 uses fake versions of trusted messaging apps to distribute ProSpy Android spyware via spearphishing and trojanized APKs; the malware harvests contacts, SMS, media, documents and communicates with attacker-controlled C2 servers. Lookout links the operation with moderate confidence to a hack-for-hire actor tied to BITTER APT and documents targeting of journalists, activists, and civil society across multiple countries in the Middle East and beyond.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.