Skip to content

Android Spyware Operation Targets UAE Users

Two types of spyware, ProSpy and ToSpy, are secretly replacing legitimate apps to steal sensitive data from Android users in the UAE.

In this image, we can see an advertisement contains robots and some text.
In this image, we can see an advertisement contains robots and some text.

Android Spyware Operation Targets UAE Users

Security researchers have uncovered a sophisticated spyware operation targeting Android users in the United Arab Emirates. The operation involves two types of malware, ProSpy and ToSpy, which pose as legitimate messaging apps like Signal and ToTok.

The campaigns were first detected in June 2022 (ToSpy) and June 2024 (ProSpy). Both spyware types can only be installed manually via third-party websites, suggesting regionally focused operations. Once installed, they are persistent and can steal sensitive data files, contacts, chat backups, and media. The ToSpy campaign is ongoing, with active command-and-control servers.

The malware operates by replacing legitimate apps with malicious versions. For instance, a website impersonating the Samsung Galaxy Store was used to distribute the ToSpy malware. The developers behind these campaigns remain unknown.

The discovery of ProSpy and ToSpy highlights the growing threat of targeted spyware campaigns. Users in the United Arab Emirates are urged to be cautious when downloading apps from third-party sources. Further investigation is needed to identify the developers and their motivations.

Read also:

Latest