The investigation led to the discovery of two unknown Android spyware families Android/Spy.ProSpy and Android/Spy.ToSpy, designed to steal files, contacts and chats, operating via malicious sites and counterfeit stores. The campaigns use targeted distribution strategies
Researchers of ESET, a global European leader in the cybersecurity market, have identified two Android spyware campaigns targeting people interested in secure communication apps, specifically Signal and ToTok. These campaigns spread malware through deceptive websites and social engineering techniques and appear to primarily target residents of the United Arab Emirates (UAE).
ESET's investigation led to the discovery of two previously unknown families of spyware: Android/Spy.ProSpy, which presents itself as an update or plug-in for the Signal and ToTok apps (the latter controversial and now discontinued), and Android/Spy.ToSpy, which imitates ToTok itself. The ToSpy campaigns are still active, as demonstrated by the C&C servers still operational.
“None of the apps containing the spyware were available in the official stores: both required manual installation from third-party sites posing as legitimate services,” explains Lukáš Štefanko, the ESET researcher who made the discovery. "In particular, one of the sites distributing the ToSpy family mimicked Samsung's Galaxy Store, tricking users into manually downloading and installing a malicious version of the ToTok app. Once installed, both spyware families maintain persistence and continue to exfiltrate sensitive data and files from compromised Android devices. Detections in the United Arab Emirates and the combined use of phishing and fake app stores suggest regionally targeted operations with well-defined distribution strategies."
ESET Research identified the ProSpy campaign in June 2025, likely active as early as 2024. ProSpy is distributed via three deceptive websites designed to mimic the Signal and ToTok messaging platforms. These sites offer malicious APK files that present themselves as updates or enhancements, disguised as “Signal Encryption Plugin” and “ToTok Pro”. Using a domain with the final string ae.net could indicate that the campaign is aimed at users residing in the United Arab Emirates, given that AE is the country code.
During the investigation, ESET discovered five more malicious APK files based on the same spyware code, posing as enhanced versions of the ToTok app under the name “ToTok Pro”. ToTok, a free messaging and calling app developed in the United Arab Emirates, was removed from Google Play and Apple's App Store in December 2019 due to surveillance concerns. Considering that ToTok's user base is mainly concentrated in the UAE, it is plausible that ToTok Pro targets users in the region who are more likely to download the app from local, unofficial sources.
Upon execution, both malicious apps ask for permissions to access contacts, SMS messages, and files stored on the device. If such permissions are granted, ProSpy starts data exfiltration in the background. The “Signal Encryption Plugin” extracts device information, stored SMS messages, contact list and other files, such as chat backups, audio files, videos and images.
In June 2025, ESET's telemetry systems identified another previously unknown Android spyware family actively distributed and originating from a device located in the United Arab Emirates. ESET has labeled the malware as Android/Spy.ToSpy. Subsequent investigations revealed four deceptive websites that mimicked the ToTok app. Given the regional popularity of the app and the impersonation techniques used by the attackers, it is reasonable to assume that the main targets of this campaign are users from the United Arab Emirates or surrounding areas. In the background, spyware can collect and exfiltrate different types of data, including contacts, device information, files such as chat backups, images, documents, audio and video files. ESET's findings suggest that the ToSpy campaign began in mid-2022.
“Users should be especially careful when downloading apps from unofficial sources and avoid enabling installation from unknown sources, as well as when installing apps or add-ons outside of official stores, especially those that claim to enhance trusted services,” warns Štefanko.






