ESET Research discovers new spyware posing as messaging apps targeting users in the UAE
Two Android spyware families impersonate Signal and ToTok to steal sensitive data from UAE users, with ProSpy discovered in June 2025 and ToSpy active since mid-2022.
- On Oct. 02, 2025, ESET Research disclosed two previously undocumented Android spyware families named ProSpy and ToSpy, which impersonate Signal app and ToTok app to target Android users.
- Researchers say ProSpy has likely been active since at least 2024, while ToSpy likely began on June 30, 2022 and remains active with command-and-control servers.
- Distributing the malware, threat actors used deceptive websites impersonating Signal and ToTok plus a fake Samsung Galaxy Store page hosting malicious APKs.
- UAE users face data theft, with spyware exfiltrating contacts, ToTok chat backups, images, documents, audio, video, and maintaining persistence via foreground service and AlarmManager.
- Researchers recommended keeping Play Protect active and avoiding third-party APK installs as ESET published IoCs while attribution remains inconclusive; ToTok's removal over surveillance concerns likely influenced its use as a lure.
10 Articles
10 Articles
Android spyware disguised as legitimate messaging apps targets UAE victims, researchers reveal
Researchers have found two Android spyware families masquerading as messaging apps Signal and ToTok, apparently targeting residents of the United Arab Emirates. ESET revealed the spyware campaigns Thursday in a blog post, saying that researchers discovered it in June but believe it dates back to last year. They dubbed the campaigns ProSpy and ToSpy, with the first impersonating both Signal and ToTok, and the second just ToTok. ToTok has been eff…
ESET Research discovers new spyware posing as messaging apps targeting users in the UAE
ESET Research has uncovered two previously undocumented Android spyware families, which ESET has named Android/Spy.ProSpy and Android/Spy.ToSpy. ProSpy impersonates both Signal and ToTok, while ToSpy targets ToTok users exclusively. Both malware families aim to exfiltrate user data, including documents, media, files, contacts, and chat backups. Confirmed detections in the UAE and the use of both phishing and fake app stores suggest regionally fo…
ProSpy and ToSpy are two Android spywares that target users of Signal and ToTok email applications. Attackers distribute them via fake websites that pass on to official platforms or application shops.
Coverage Details
Bias Distribution
- 80% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium