Executive Summary
In October 2025, cybersecurity researchers at ESET identified two sophisticated Android spyware campaigns, ProSpy and ToSpy, actively targeting users in the United Arab Emirates by masquerading as legitimate apps such as Signal Encryption Plugin and ToTok Pro. The spyware was disseminated through fake websites leveraging social engineering techniques, deceiving users into downloading malicious apps. Once installed, the malware secretly exfiltrated device data, tracked user communications, and introduced significant privacy and data security risks for both individuals and organizations. The campaigns indicate a growing trend of targeted mobile espionage in the region, significantly undermining user trust and operational safety.
This incident underscores the escalating threat from mobile spyware distributed via convincing social engineering and fake app storefronts. As more users move critical communications to mobile platforms, adversaries are rapidly advancing their techniques, prompting urgent calls for enhanced mobile threat detection, robust user education, and strict compliance with data protection frameworks.
Why This Matters Now
This campaign highlights the immediate danger of advanced spyware targeting mobile users through fake encrypted messaging apps. The sophistication of deception and technical capabilities increases the risk for organizations and governments in high-target geographies, necessitating rapid uplift in mobile security controls and user training before attacks spread further.
Attack Path Analysis
The attacker initiated their campaign through social engineering, luring users into installing trojanized versions of legitimate apps from fake websites. Following installation, the spyware likely leveraged permissions abuse to escalate access, gaining control over sensitive device data. Internally, the malware moved laterally within the compromised device to access additional data and potentially other apps or services. It established encrypted command and control channels to remote servers, covertly sending stolen data. Sensitive information was then exfiltrated via outbound internet connections likely hidden in normal device traffic. Finally, the spyware's impact included ongoing user surveillance, data theft, and privacy compromise.
Kill Chain Progression
Initial Compromise
Description
Users were tricked via social engineering into downloading malicious Android apps disguised as trusted communication platforms.
Related CVEs
CVE-2024-43093
CVSS 9A critical privilege escalation vulnerability in the Android Framework allows unauthorized access to sensitive directories, enabling attackers to perform unauthorized actions or access sensitive data.
Affected Products:
Google Android – 12, 13, 14, 15
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Deliver Malicious App via Authorized App Store
Input Capture
Download New Code at Runtime
Obfuscated Files or Information
Bluetooth Discovery
Process Discovery
Access Sensitive Data or Credentials in Files
Exfiltration Over Command and Control Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Protect Stored Account Data
Control ID: 3.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 9(2)
CISA ZTMM 2.0 – Continuous Monitoring and Least Privilege Enforcement
Control ID: 3.2.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Android spyware targeting UAE users poses critical threats to government communications, requiring enhanced mobile security policies and encrypted traffic monitoring capabilities.
Telecommunications
Mobile spyware impersonating Signal threatens telecom infrastructure security, demanding zero trust segmentation and anomaly detection systems for network protection.
Financial Services
Spyware campaigns compromise mobile banking security, necessitating robust threat detection, egress security controls, and PCI compliance enforcement mechanisms.
Oil/Energy/Solar/Greentech
Energy sector mobile communications face spyware risks requiring multicloud visibility, encrypted traffic solutions, and comprehensive threat intelligence for operational security.
Sources
- Warning: Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Prohttps://thehackernews.com/2025/10/warning-beware-of-android-spyware.htmlVerified
- ESET Research discovers new spyware posing as messaging apps targeting users in the UAEhttps://www.eset.com/us/about/newsroom/research/eset-research-new-spyware-messaging-apps-users-uae/Verified
- ProSpy and ToSpy: New spyware families impersonating secure messaging appshttps://www.helpnetsecurity.com/2025/10/02/android-spyware-signal-totok/Verified
- CVE-2024-43093: Critical Android Framework Vulnerability Exploited in Targeted Espionage Campaignshttps://www.rescana.com/post/cve-2024-43093-critical-android-framework-vulnerability-exploited-in-targeted-espionage-campaignsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Network segmentation, egress policy enforcement, threat detection, and encrypted traffic controls provided by CNSF capabilities would have limited initial compromise spread, detected malicious outbound activity, and restricted data exfiltration paths in a cloud-managed or enterprise-managed mobile environment.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous downloads or traffic to malicious app sources would trigger alerts.
Control: Zero Trust Segmentation
Mitigation: Excessive or risky internal communications are segmented and policy-restricted.
Control: East-West Traffic Security
Mitigation: Unauthorized intra-environment movement is detected and blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Malicious outbound communications are blocked or subjected to strict policy controls.
Control: Encrypted Traffic (HPE) & Inline IPS
Mitigation: Suspicious encrypted data transfers are inspected, alerted, or blocked.
Widespread compromise is rapidly detected and limited by centralized monitoring.
Impact at a Glance
Affected Business Functions
- User Communications
- Data Security
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive user data, including contacts, messages, and media files, leading to privacy violations and reputational damage.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and microsegmentation in mobile and cloud environments to restrict malware movement.
- • Implement strict egress policy enforcement to block malicious outbound traffic and C2 channel establishment.
- • Leverage advanced anomaly detection and inline IPS to rapidly identify and block suspicious application behaviors and outbound connections.
- • Ensure comprehensive visibility and centralized policy control across all managed endpoints, including mobile devices and cloud workloads.
- • Mandate least privilege access and application permission reviews to limit the scope of potential exploitation by malicious or trojanized apps.



