logo

New spyware campaigns target privacy-conscious Android users in the UAE

ID: 17df0fb4-ff2b-513b-9d1b-20d958c32006

STIX ID: report--17df0fb4-ff2b-513b-9d1b-20d958c32006

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2025-10-02

Date Updated: 2026-05-01

...
...

ESET researchers uncovered two ongoing Android spyware campaigns—ProSpy (impersonating Signal add-ons and ToTok Pro) and ToSpy (impersonating ToTok)—that distribute malicious APKs via phishing sites and fake app stores, primarily targeting users in the UAE; both families maintain persistence, exfiltrate contacts, SMS, media and app backups (including .ttkmbackup), use AES-encrypted HTTPS C2 channels, and have active C2/distribution domains and published IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.