The Containment Era is here. →Explore

Executive Summary

In June 2024, ESET researchers uncovered two Android spyware campaigns—ProSpy and ToSpy—masquerading as popular messaging apps Signal and ToTok, specifically targeting residents in the United Arab Emirates. The malware was distributed via third-party websites impersonating legitimate app stores, such as the Samsung Galaxy Store, and required users to manually install them. Upon installation, the spyware requested extensive permissions, gaining access to contacts, messages, stored files, audio, images, and more, enabling extensive data exfiltration. The campaigns utilized regional delivery tactics to focus on UAE users, exploiting trusted local app brands.

These findings highlight a persistent threat trend: attackers disguising malware as legitimate communication apps to bypass official channels and exploit regional trust. With increased scrutiny on privacy and secure messaging, such campaigns pose heightened operational and compliance risks for organizations and individuals alike, underscoring the urgent need for enhanced mobile security measures and user awareness.

Why This Matters Now

This incident demonstrates the growing sophistication of mobile spyware targeting specific regions and user demographics. The use of trusted app brands and fake app stores increases the risk of data compromise for both individuals and organizations, especially as remote work and BYOD adoption remain high. Immediate action is needed to prevent similar attacks and protect sensitive information.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaigns highlight risks to data privacy under frameworks like HIPAA, PCI DSS, and NIST, particularly regarding encrypted data in transit and unauthorized data exfiltration.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, strong egress controls, and real-time threat detection could have contained spyware activity, blocked outbound exfiltration, and alerted security teams to anomalous communication patterns indicative of compromise.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Anomalous application install attempts and sideloading could be detected and alerted.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Monitoring and visibility over access patterns would detect abnormal permission requests.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Lateral movement attempts limited by strict network and service segmentation.

Command & Control

Control: Cloud Firewall (ACF)

Mitigation: Outbound connections to unapproved C2 destinations blocked by egress policy.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Exfiltration channels disrupted and data loss prevented.

Impact (Mitigations)

Early detection and automated response minimize operational and privacy impact.

Impact at a Glance

Affected Business Functions

  • User Data Management
  • Communication Services
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive user data, including contacts, messages, and media files, due to unauthorized access by spyware.

Recommended Actions

  • Enforce comprehensive egress filtering and application-layer visibility to detect and block outbound data exfiltration from compromised devices.
  • Implement Zero Trust segmentation and least-privilege network policies to prevent lateral movement and restrict unnecessary intra-cloud communication.
  • Leverage threat detection and anomaly response capabilities to rapidly identify suspicious app installations and unusual outbound traffic patterns.
  • Centralize multicloud traffic observability and maintain real-time visibility into application behaviors and user/device interactions.
  • Regularly validate security baselines and educate users on risks associated with sideloading apps from unofficial sources.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image