logo

Android spyware campaigns impersonate Signal and ToTok messengers

ID: 64cd5abe-7cd0-5c3e-a530-aff17b655fd0

STIX ID: report--64cd5abe-7cd0-5c3e-a530-aff17b655fd0

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-02

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

ESET researchers identified two Android spyware campaigns — ProSpy and ToSpy — that impersonate Signal and ToTok to trick users into installing malicious APKs which request permissions and exfiltrate contacts, SMS, media, ToTok backups and device information; both families implement persistence (AlarmManager restarts, foreground services, BOOT_COMPLETED) and use active C2 infrastructure and encrypted exfiltration, with IoCs published but attribution unresolved.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.