Skip to main content
See every side of every news story
Published loading...Updated

ESET Research discovers new spyware posing as messaging apps targeting users in the UAE

Two Android spyware families impersonate Signal and ToTok to steal sensitive data from UAE users, with ProSpy discovered in June 2025 and ToSpy active since mid-2022.

  • On Oct. 02, 2025, ESET Research disclosed two previously undocumented Android spyware families named ProSpy and ToSpy, which impersonate Signal app and ToTok app to target Android users.
  • Researchers say ProSpy has likely been active since at least 2024, while ToSpy likely began on June 30, 2022 and remains active with command-and-control servers.
  • Distributing the malware, threat actors used deceptive websites impersonating Signal and ToTok plus a fake Samsung Galaxy Store page hosting malicious APKs.
  • UAE users face data theft, with spyware exfiltrating contacts, ToTok chat backups, images, documents, audio, video, and maintaining persistence via foreground service and AlarmManager.
  • Researchers recommended keeping Play Protect active and avoiding third-party APK installs as ESET published IoCs while attribution remains inconclusive; ToTok's removal over surveillance concerns likely influenced its use as a lure.
Insights by Ground AI

10 Articles

ProSpy and ToSpy are two Android spywares that target users of Signal and ToTok email applications. Attackers distribute them via fake websites that pass on to official platforms or application shops.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 80% of the sources are Center
80% Center

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

Benzinga broke the news in New York, United States on Thursday, October 2, 2025.
Sources are mostly out of (0)
News
For You
Search
BlindspotLocal