logo

Android Spyware in the UAE Masquerades as ... Spyware

ID: c8df93f8-2edc-5acb-bdbe-79d7832a29e7

STIX ID: report--c8df93f8-2edc-5acb-bdbe-79d7832a29e7

Feed Name: Dark Reading

Threat Score
66/100

Date Published: 2025-10-02

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Researchers at ESET uncovered two families of Android spyware, “ToSpy” and “ProSpy,” being distributed in the UAE by masquerading as the ToTok app (and in ProSpy’s case sometimes mimicking Signal). The malware is sideloaded from phishing sites or third‑party stores, requests invasive permissions, exfiltrates contacts, SMS, device information and media files to attacker servers, and perpetuates the ruse by launching or redirecting victims to legitimate apps; campaigns have been active for years, and while technically simple they have been effective against users who sideload apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.