logo

BITTER APT Uses Signal, Google, and Zoom Lures to Spread ProSpy Spyware

ID: 06f48809-8d7c-5443-b126-530da5451e7c

STIX ID: report--06f48809-8d7c-5443-b126-530da5451e7c

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers from Access Now and Lookout uncovered a multi-year (2022–2025) targeted espionage campaign against journalists and opposition politicians in the Middle East that leverages spearphishing (LinkedIn, iMessage), fake login pages and malicious Signal QR codes to deliver Android spyware (ProSpy/ToSpy). The spyware, developed in Kotlin and actively evolving, can exfiltrate photos, audio, video, SMS, contacts and documents; Lookout links the tooling and command structure to the South Asian APT known as BITTER, and investigators suspect the operation may have been conducted as hack-for-hire.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.