Executive Summary
In June 2025, cybersecurity firm ESET uncovered targeted Android spyware campaigns, dubbed ProSpy and ToSpy, which impersonated upgrades and plugins for the popular messaging apps Signal and ToTok. Threat actors distributed malicious APK files via websites masquerading as official app sites and third-party stores, luring users primarily in the United Arab Emirates. Once installed, these spyware variants harvested sensitive data including device information, contacts, SMS, files, and backups, using sophisticated persistence mechanisms and disguising themselves as legitimate apps. Data exfiltration was conducted using encrypted channels to evade detection.
This incident underscores the increasing threat of mobile malware leveraging convincing social engineering tactics and fake branding. It highlights a macro trend of attackers exploiting trust in widely used apps to infiltrate user devices, reflecting rising complexity in mobile threat landscapes and growing regulatory pressure on app distributors.
Why This Matters Now
The prevalence of advanced Android spyware disguised as legitimate messenger apps represents a growing threat to individual privacy and enterprise data security. The urgency is driven by attackers' ability to evade security controls and exploit user trust amid the explosive growth of mobile-first communications.
Attack Path Analysis
Attackers lured Android users to download malicious APKs disguised as Signal and ToTok apps from fraudulent websites. After installation, the malware requested sensitive permissions and established persistence on the device. While not explicitly detailed, privilege escalation was likely attempted by abusing Android permissions and APIs. Lateral movement within the cloud or enterprise environment was probably limited; however, attackers could potentially leverage exfiltrated credentials or tokens for further access. Malware connected to command-and-control infrastructure to receive instructions and transmit stolen data. Sensitive information (SMS, contacts, files) was exfiltrated over encrypted channels, and the ultimate impact involved significant data breach and loss of user privacy.
Kill Chain Progression
Initial Compromise
Description
Victims were socially engineered to download and install trojanized APKs from phishing sites impersonating Signal and ToTok stores.
MITRE ATT&CK® Techniques
User Execution: Malicious Link
Masquerading
Access Sensitive Data or Credentials in Files
Exfiltration Over C2 Channel
Obfuscated Files or Information
Create or Modify System Process
Download, Install, or Execute Malicious App
Account Access Removal
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Security Awareness Training
Control ID: 12.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 5
CISA ZTMM 2.0 – Continuous Assessment of Device Security Posture
Control ID: Mobile Devices - Device Posture Assessment
NIS2 Directive – Incident Handling Capabilities
Control ID: Art. 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Mobile spyware targeting Signal and ToTok messaging apps threatens encrypted communications infrastructure, requiring enhanced east-west traffic security and threat detection capabilities.
Government Administration
UAE-targeted Android spyware campaigns exploiting messaging platforms pose significant risks to government communications, demanding zero trust segmentation and multicloud visibility controls.
Computer/Network Security
Sophisticated mobile spyware impersonating legitimate messaging apps exposes security firms to client data breaches, necessitating enhanced egress security and anomaly detection systems.
Financial Services
Mobile spyware targeting encrypted messaging threatens sensitive financial communications and data exfiltration, requiring comprehensive threat detection and encrypted traffic protection measures.
Sources
- Android spyware campaigns impersonate Signal and ToTok messengershttps://www.bleepingcomputer.com/news/security/android-spyware-campaigns-impersonate-signal-and-totok-messengers/Verified
- ESET Research discovers new spyware posing as messaging apps targeting users in the UAEhttps://www.eset.com/us/about/newsroom/research/eset-research-new-spyware-messaging-apps-users-uae/Verified
- ESET Research discovers eXotic Visit campaign, targeted attack via fake messaging apps, available on web and Google Playhttps://www.eset.com/us/about/newsroom/research/eset-research-discovers-exotic-visit-campaign-targeted-attack-via-fake-messaging-apps-available-on-web-and-google-play/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust and CNSF controls—such as microsegmentation, egress policy enforcement, encrypted traffic inspection, and anomaly detection—could have detected, limited, or prevented key stages of this mobile spyware campaign, particularly by restricting outbound malicious communications and exfiltration. Enhanced visibility and segmentation of cloud workloads help detect unusual mobile-to-cloud activity and enforce least privilege and data loss controls.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of anomalous access or installation patterns.
Control: Zero Trust Segmentation
Mitigation: Limits scope of access and isolates workloads/services.
Control: East-West Traffic Security
Mitigation: Blocks or detects unauthorized internal lateral movements.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized outbound connections to malicious domains.
Control: Encrypted Traffic (HPE)
Mitigation: Detects and controls outbound encrypted data flows.
Continuous visibility into data flows and post-incident impact detection.
Impact at a Glance
Affected Business Functions
- User Data Management
- Customer Trust
Estimated downtime: N/A
Estimated loss: N/A
The ProSpy and ToSpy campaigns led to unauthorized access and exfiltration of sensitive user data, including contacts, SMS messages, and media files. This breach could result in identity theft, financial fraud, and erosion of customer trust.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict workload access and prevent abuse of permissions by malicious apps.
- • Enforce strong egress security and policy filtering to block unauthorized outbound C2 and data exfiltration attempts, particularly to suspicious FQDNs.
- • Deploy encrypted traffic inspection and high-performance encryption to monitor and control sensitive data flows, even when attackers use in-transit encryption.
- • Leverage anomaly detection, baselining, and continuous visibility to identify unusual device or access behavior that could signal compromise.
- • Ensure all mobile and cloud services are protected using centralized, consistent CNSF policy controls across all multi-cloud and hybrid environments.



