← Back to BrewedIntel
adversaryhighMobile MalwareSpyware

Oct 02, 2025 • ESET WeLiveSecurity

New spyware campaigns target privacy-conscious Android users in the UAE

ESET researchers have identified new spyware campaigns specifically targeting privacy-conscious Android users within the United Arab Emirates. The malicious...

Source
ESET WeLiveSecurity
Category
adversary
Severity
high

Executive Summary

ESET researchers have identified new spyware campaigns specifically targeting privacy-conscious Android users within the United Arab Emirates. The malicious activity involves distributing spyware disguised as legitimate communication applications, specifically mimicking Android Signal and ToTok apps. This campaign poses a significant risk to user privacy and data security in the region, as the malware likely facilitates unauthorized surveillance and data exfiltration. While specific threat actor attribution remains unconfirmed in this report, the targeted nature suggests a focused operation against high-value individuals or specific demographics utilizing encrypted messaging services. Users are advised to exercise extreme caution when downloading applications outside of official stores and to verify app authenticity. Security teams should monitor for anomalous network traffic associated with these impersonated apps and ensure mobile device management policies are updated to prevent sideloading of unverified software to mitigate the risk of infection.

Summary

ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates

Published Analysis

ESET researchers have identified new spyware campaigns specifically targeting privacy-conscious Android users within the United Arab Emirates. The malicious activity involves distributing spyware disguised as legitimate communication applications, specifically mimicking Android Signal and ToTok apps. This campaign poses a significant risk to user privacy and data security in the region, as the malware likely facilitates unauthorized surveillance and data exfiltration. While specific threat actor attribution remains unconfirmed in this report, the targeted nature suggests a focused operation against high-value individuals or specific demographics utilizing encrypted messaging services. Users are advised to exercise extreme caution when downloading applications outside of official stores and to verify app authenticity. Security teams should monitor for anomalous network traffic associated with these impersonated apps and ensure mobile device management policies are updated to prevent sideloading of unverified software to mitigate the risk of infection. ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates