Middle East Espionage Attack Uses Fake Secure Messaging Apps to Deliver ProSpy
ID: 3216f803-c858-5db5-946f-ef97d949adfb
STIX ID: report--3216f803-c858-5db5-946f-ef97d949adfb
Feed Name: GBHackers
ProSpy is an Android spyware family masquerading as “pro” versions of trusted messaging apps (e.g., Signal, ToTok, Botim) used since at least 2022 in a hack‑for‑hire campaign targeting journalists, activists, and political figures across the Middle East. Operators use tailored social engineering, fake single‑page sites that deliver APKs outside official stores, and modular worker components to collect and exfiltrate contacts, SMS, call metadata, files and backups to identified C2 domains; Lookout links the campaign with moderate confidence to the BITTER APT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
