×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET discovers new spyware posing as messaging apps and targeting users in the United Arab Emirates

Customer Press Room

ESET discovers new spyware posing as messaging apps and targeting users in the United Arab Emirates

by Grandangolo Communications / Monday, 13 October 2025 / Published in Eset

The investigation led to the discovery of two unknown Android spyware families Android/Spy.ProSpy and Android/Spy.ToSpy, designed to steal files, contacts and chats, operating via malicious sites and counterfeit stores. The campaigns use targeted distribution strategies

Researchers of ESET, a global European leader in the cybersecurity market, have identified two Android spyware campaigns targeting people interested in secure communication apps, specifically Signal and ToTok. These campaigns spread malware through deceptive websites and social engineering techniques and appear to primarily target residents of the United Arab Emirates (UAE).

ESET's investigation led to the discovery of two previously unknown families of spyware: Android/Spy.ProSpy, which presents itself as an update or plug-in for the Signal and ToTok apps (the latter controversial and now discontinued), and Android/Spy.ToSpy, which imitates ToTok itself. The ToSpy campaigns are still active, as demonstrated by the C&C servers still operational.

“None of the apps containing the spyware were available in the official stores: both required manual installation from third-party sites posing as legitimate services,” explains Lukáš Štefanko, the ESET researcher who made the discovery. "In particular, one of the sites distributing the ToSpy family mimicked Samsung's Galaxy Store, tricking users into manually downloading and installing a malicious version of the ToTok app. Once installed, both spyware families maintain persistence and continue to exfiltrate sensitive data and files from compromised Android devices. Detections in the United Arab Emirates and the combined use of phishing and fake app stores suggest regionally targeted operations with well-defined distribution strategies."

ESET Research identified the ProSpy campaign in June 2025, likely active as early as 2024. ProSpy is distributed via three deceptive websites designed to mimic the Signal and ToTok messaging platforms. These sites offer malicious APK files that present themselves as updates or enhancements, disguised as “Signal Encryption Plugin” and “ToTok Pro”. Using a domain with the final string ae.net could indicate that the campaign is aimed at users residing in the United Arab Emirates, given that AE is the country code.

During the investigation, ESET discovered five more malicious APK files based on the same spyware code, posing as enhanced versions of the ToTok app under the name “ToTok Pro”. ToTok, a free messaging and calling app developed in the United Arab Emirates, was removed from Google Play and Apple's App Store in December 2019 due to surveillance concerns. Considering that ToTok's user base is mainly concentrated in the UAE, it is plausible that ToTok Pro targets users in the region who are more likely to download the app from local, unofficial sources.

Upon execution, both malicious apps ask for permissions to access contacts, SMS messages, and files stored on the device. If such permissions are granted, ProSpy starts data exfiltration in the background. The “Signal Encryption Plugin” extracts device information, stored SMS messages, contact list and other files, such as chat backups, audio files, videos and images.

In June 2025, ESET's telemetry systems identified another previously unknown Android spyware family actively distributed and originating from a device located in the United Arab Emirates. ESET has labeled the malware as Android/Spy.ToSpy. Subsequent investigations revealed four deceptive websites that mimicked the ToTok app. Given the regional popularity of the app and the impersonation techniques used by the attackers, it is reasonable to assume that the main targets of this campaign are users from the United Arab Emirates or surrounding areas. In the background, spyware can collect and exfiltrate different types of data, including contacts, device information, files such as chat backups, images, documents, audio and video files. ESET's findings suggest that the ToSpy campaign began in mid-2022.

“Users should be especially careful when downloading apps from unofficial sources and avoid enabling installation from unknown sources, as well as when installing apps or add-ons outside of official stores, especially those that claim to enhance trusted services,” warns Štefanko.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET updates its consumer offering for advanced protection against ransomware and scams
ESET discovered zero-day and zero-click vulnerabilities in Mozilla and Windows exploited by pro-Russian APT group RomCom
ESET Mobile Security for a safe return to class

Customer Press Room

  • ESET Research: FamousSparrow steps up operations in Latin America and hits governments with new backdoor

    The pro-Chinese APT group concentrates its activities...
  • ESET's ultra-fast, high-accuracy threat detection scanner, now available in AWS Marketplace

    The ESET PRIVATE Scanning Solutions suite is available...
  • Arrow Electronics signs distribution agreement with Usercentrics

    Arrow Electronics, a global supplier of technology...
  • Acronis names Denis Cassinerio Vice President South Europe CEE

    In the new role the manager will continue the...
  • SentinelOne enhances Wayfinder's Frontier AI services by integrating OpenAI's Daybreak models

    Advanced cybersecurity services expanded with...

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP