The Containment Era is here. →Explore

Executive Summary

In June 2025, cybersecurity firm ESET uncovered targeted Android spyware campaigns, dubbed ProSpy and ToSpy, which impersonated upgrades and plugins for the popular messaging apps Signal and ToTok. Threat actors distributed malicious APK files via websites masquerading as official app sites and third-party stores, luring users primarily in the United Arab Emirates. Once installed, these spyware variants harvested sensitive data including device information, contacts, SMS, files, and backups, using sophisticated persistence mechanisms and disguising themselves as legitimate apps. Data exfiltration was conducted using encrypted channels to evade detection.

This incident underscores the increasing threat of mobile malware leveraging convincing social engineering tactics and fake branding. It highlights a macro trend of attackers exploiting trust in widely used apps to infiltrate user devices, reflecting rising complexity in mobile threat landscapes and growing regulatory pressure on app distributors.

Why This Matters Now

The prevalence of advanced Android spyware disguised as legitimate messenger apps represents a growing threat to individual privacy and enterprise data security. The urgency is driven by attackers' ability to evade security controls and exploit user trust amid the explosive growth of mobile-first communications.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaigns exposed a need for stronger app store controls, improved detection of malicious APKs, and better encryption and access management in line with HIPAA, PCI DSS, and NIST requirements.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust and CNSF controls—such as microsegmentation, egress policy enforcement, encrypted traffic inspection, and anomaly detection—could have detected, limited, or prevented key stages of this mobile spyware campaign, particularly by restricting outbound malicious communications and exfiltration. Enhanced visibility and segmentation of cloud workloads help detect unusual mobile-to-cloud activity and enforce least privilege and data loss controls.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Early detection of anomalous access or installation patterns.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits scope of access and isolates workloads/services.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocks or detects unauthorized internal lateral movements.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Blocks unauthorized outbound connections to malicious domains.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Detects and controls outbound encrypted data flows.

Impact (Mitigations)

Continuous visibility into data flows and post-incident impact detection.

Impact at a Glance

Affected Business Functions

  • User Data Management
  • Customer Trust
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

The ProSpy and ToSpy campaigns led to unauthorized access and exfiltration of sensitive user data, including contacts, SMS messages, and media files. This breach could result in identity theft, financial fraud, and erosion of customer trust.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict workload access and prevent abuse of permissions by malicious apps.
  • Enforce strong egress security and policy filtering to block unauthorized outbound C2 and data exfiltration attempts, particularly to suspicious FQDNs.
  • Deploy encrypted traffic inspection and high-performance encryption to monitor and control sensitive data flows, even when attackers use in-transit encryption.
  • Leverage anomaly detection, baselining, and continuous visibility to identify unusual device or access behavior that could signal compromise.
  • Ensure all mobile and cloud services are protected using centralized, consistent CNSF policy controls across all multi-cloud and hybrid environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image