Executive Summary
In June 2024, ESET researchers uncovered two Android spyware campaigns—ProSpy and ToSpy—masquerading as popular messaging apps Signal and ToTok, specifically targeting residents in the United Arab Emirates. The malware was distributed via third-party websites impersonating legitimate app stores, such as the Samsung Galaxy Store, and required users to manually install them. Upon installation, the spyware requested extensive permissions, gaining access to contacts, messages, stored files, audio, images, and more, enabling extensive data exfiltration. The campaigns utilized regional delivery tactics to focus on UAE users, exploiting trusted local app brands.
These findings highlight a persistent threat trend: attackers disguising malware as legitimate communication apps to bypass official channels and exploit regional trust. With increased scrutiny on privacy and secure messaging, such campaigns pose heightened operational and compliance risks for organizations and individuals alike, underscoring the urgent need for enhanced mobile security measures and user awareness.
Why This Matters Now
This incident demonstrates the growing sophistication of mobile spyware targeting specific regions and user demographics. The use of trusted app brands and fake app stores increases the risk of data compromise for both individuals and organizations, especially as remote work and BYOD adoption remain high. Immediate action is needed to prevent similar attacks and protect sensitive information.
Attack Path Analysis
The attacker initiated compromise by tricking users into manually downloading malicious messaging apps from spoofed third-party websites. After gaining permissions, the spyware escalated privileges to access sensitive files and communication. Although movement beyond the initial device is not confirmed, access to device data may facilitate additional lateral spread. The malware then established command and control channels to receive instructions and persist. Data was exfiltrated, including contacts, messages, audio, images, and potentially backups. The ultimate impact was the covert loss of user privacy and exposure of sensitive information for targets in the UAE.
Kill Chain Progression
Initial Compromise
Description
Victims were lured via phishing and fake app stores to manually install spyware disguised as legitimate messaging apps.
MITRE ATT&CK® Techniques
Deliver Malicious App via Other Means
Masquerade as Legitimate Application
Automated Exfiltration
Access Sensitive Data or Credentials in Files
Obtain Device Administrator Permissions
Data from Local System
Disguise Malicious Files/Information
Access Stored Application Data
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Risk Assessment Process
Control ID: 12.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Adaptive policy enforcement for apps and devices
Control ID: Identity Pillar: Resource Access Policies
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Mobile spyware targeting messaging apps creates critical risks for telecom infrastructure, requiring enhanced egress security and encrypted traffic capabilities for customer protection.
Government Administration
UAE-targeted Android spyware poses national security risks, necessitating zero trust segmentation and threat detection capabilities to prevent data exfiltration from government systems.
Computer/Network Security
Sophisticated mobile spyware campaigns demonstrate need for enhanced threat detection, anomaly response, and multicloud visibility to protect security industry clients and infrastructure.
Information Technology/IT
Fake messaging app distribution through compromised stores requires IT sectors to implement comprehensive egress filtering and cloud native security fabric solutions.
Sources
- Android spyware disguised as legitimate messaging apps targets UAE victims, researchers revealhttps://cyberscoop.com/android-spyware-disguised-as-legitimate-messaging-apps-targets-uae-victims-researchers-reveal/Verified
- ESET Research discovers new spyware posing as messaging apps targeting users in the UAEhttps://www.eset.com/us/about/newsroom/research/eset-research-new-spyware-messaging-apps-users-uae/Verified
- ESET Research uncovers APT-C-23 group’s new Android spyware masked as Threema and Telegramhttps://www.eset.com/us/about/newsroom/press-releases/eset-research-uncovers-apt-c-23-groups-new-android-spyware-masked-as-threema-and-telegram-1/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, strong egress controls, and real-time threat detection could have contained spyware activity, blocked outbound exfiltration, and alerted security teams to anomalous communication patterns indicative of compromise.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous application install attempts and sideloading could be detected and alerted.
Control: Multicloud Visibility & Control
Mitigation: Monitoring and visibility over access patterns would detect abnormal permission requests.
Control: Zero Trust Segmentation
Mitigation: Lateral movement attempts limited by strict network and service segmentation.
Control: Cloud Firewall (ACF)
Mitigation: Outbound connections to unapproved C2 destinations blocked by egress policy.
Control: Egress Security & Policy Enforcement
Mitigation: Exfiltration channels disrupted and data loss prevented.
Early detection and automated response minimize operational and privacy impact.
Impact at a Glance
Affected Business Functions
- User Data Management
- Communication Services
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive user data, including contacts, messages, and media files, due to unauthorized access by spyware.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce comprehensive egress filtering and application-layer visibility to detect and block outbound data exfiltration from compromised devices.
- • Implement Zero Trust segmentation and least-privilege network policies to prevent lateral movement and restrict unnecessary intra-cloud communication.
- • Leverage threat detection and anomaly response capabilities to rapidly identify suspicious app installations and unusual outbound traffic patterns.
- • Centralize multicloud traffic observability and maintain real-time visibility into application behaviors and user/device interactions.
- • Regularly validate security baselines and educate users on risks associated with sideloading apps from unofficial sources.



