← Back to BrewedIntel
adversaryhighMobile MalwareSpywareTargeted Surveillance

Oct 02, 2025 • ESET WeLiveSecurity

New spyware campaigns target privacy-conscious Android users in the UAE

ESET researchers have identified spyware campaigns targeting privacy-conscious Android users in the United Arab Emirates. The attacks distribute malicious...

Source
ESET WeLiveSecurity
Category
adversary
Severity
high

Executive Summary

ESET researchers have identified spyware campaigns targeting privacy-conscious Android users in the United Arab Emirates. The attacks distribute malicious applications disguised as legitimate Signal and ToTok messaging apps. These fake apps appear designed to harvest sensitive user data including contacts, call logs, location information, and device details from compromised devices. The targeted nature of this campaign suggests a focus on surveillance of specific individuals, potentially activists, journalists, or other high-risk users in the region. The use of well-known privacy-focused applications as lures increases the likelihood of successful infiltration, as victims believe they are downloading trusted communication tools. Users are advised to only download applications from official app stores, verify app authenticity, maintain updated security software, and exercise caution when installing messaging applications, particularly in high-risk regions.

Summary

ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates

Published Analysis

ESET researchers have identified spyware campaigns targeting privacy-conscious Android users in the United Arab Emirates. The attacks distribute malicious applications disguised as legitimate Signal and ToTok messaging apps. These fake apps appear designed to harvest sensitive user data including contacts, call logs, location information, and device details from compromised devices. The targeted nature of this campaign suggests a focus on surveillance of specific individuals, potentially activists, journalists, or other high-risk users in the region. The use of well-known privacy-focused applications as lures increases the likelihood of successful infiltration, as victims believe they are downloading trusted communication tools. Users are advised to only download applications from official app stores, verify app authenticity, maintain updated security software, and exercise caution when installing messaging applications, particularly in high-risk regions. ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates