Wednesday, February 18, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET Research discovers new spyware posing as messaging apps targeting users in the UAE

October 2, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 7 mins read
5
SHARES
247
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET Research has uncovered two previously undocumented Android spyware families, which ESET has named Android/Spy.ProSpy and Android/Spy.ToSpy.
  • ProSpy impersonates both Signal and ToTok, while ToSpy targets ToTok users exclusively.
  • Both malware families aim to exfiltrate user data, including documents, media, files, contacts, and chat backups.
  • Confirmed detections in the UAE and the use of both phishing and fake app stores suggest regionally focused operations with strategic delivery mechanisms.

MONTREAL and BRATISLAVA, Slovakia, Oct. 02, 2025 (GLOBE NEWSWIRE) — ESET researchers have uncovered two Android spyware campaigns targeting individuals interested in secure communication apps, namely Signal and ToTok. These campaigns distribute malware through deceptive websites and social engineering and appear to target residents of the United Arab Emirates (UAE). ESET’s investigation led to the discovery of two previously undocumented spyware families: Android/Spy.ProSpy impersonates upgrades or plugins for the Signal app and the controversial and discontinued ToTok app, and Android/Spy.ToSpy impersonates the ToTok app. The ToSpy campaigns are ongoing, as suggested by C&C servers that remain active.

“Neither app containing the spyware was available in official app stores; both required manual installation from third-party websites posing as legitimate services,” explains ESET researcher Lukáš Štefanko, who made the discovery. “Notably, one of the websites distributing the ToSpy malware family mimicked the Samsung Galaxy Store, luring users into manually downloading and installing a malicious version of the ToTok app. Once installed, both spyware families maintain persistence and continually exfiltrate sensitive data and files from compromised Android devices. Confirmed detections in the UAE and the use of phishing and fake app stores suggest regionally focused operations with strategic delivery mechanisms.”

ESET Research discovered the ProSpy campaign in June 2025, and it has likely been ongoing since 2024. ProSpy is being distributed through three deceptive websites designed to impersonate communication platforms Signal and ToTok. These sites offer malicious APKs posing as improvements, disguised as a Signal Encryption Plugin and ToTok Pro. The use of a domain name ending in the substring ae.net may suggest that the campaign targets individuals residing in the United Arab Emirates, as AE is the two-letter country code for the UAE.

During the investigation, ESET discovered five more malicious APKs using the same spyware codebase, posing as an enhanced version of the ToTok messaging app under the name ToTok Pro. ToTok, a controversial free messaging and calling app developed in the United Arab Emirates, was removed from Google Play and Apple’s App Store in December 2019 due to surveillance concerns. Given that its user base is primarily located in the UAE, it is likely that ToTok Pro may be targeting users in this region, who may be more liable to download the app from unofficial sources in their own region.

Upon execution, both malicious apps request permissions to access contacts, SMS messages, and files stored on the device. If these permissions are granted, ProSpy starts exfiltrating data in the background. The Signal Encryption Plugin extracts device information, stored SMS messages, and the contact list, and it exfiltrates other files – such as chat backups, audio, video, and images.

In June 2025, ESET telemetry systems flagged another previously undocumented Android spyware family actively distributed in the wild, originating from a device located in the UAE. ESET labeled the malware Android/Spy.ToSpy. Later investigation revealed four deceptive distribution websites impersonating the ToTok app. Given the app’s regional popularity and the impersonation tactics used by the threat actors, it is reasonable to speculate that the primary targets of this spyware campaign are users in the UAE or surrounding regions. In the background, the spyware can collect and exfiltrate the following data: user contacts, device information files such as chat backups, images, documents, audio, and video, among others. ESET findings suggest that the ToSpy campaign likely began in mid-2022.

“Users should remain vigilant when downloading apps from unofficial sources and avoid enabling installation from unknown origins, as well as when installing apps or add-ons outside of official app stores, especially those claiming to enhance trusted services,” advises Štefanko.

For a more detailed analysis and technical breakdown of Android/Spy.ProSpy and Android/Spy.ToSpy, check out the latest ESET Research blog post, “New spyware campaigns target privacy-conscious Android users in the UAE” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), Bluesky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts, and blogs.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Huize Holding Limited Announces Resignation of an Independent Director

Next Post

Transoft Solutions Receives AiRAP Accreditation

Related Posts

OLB Group Inc. Announces Pricing of $3.0 Million Private Placement at a Premium to Market

NEW YORK, NY / ACCESS Newswire / February 18, 2026 / The OLB Group, Inc. (NASDAQ:OLB) ("OLB" or the "Company"), a diversified fintech company providing payment processing and digital asset technology solutions, today announced that it has entered into a securities purchase agreement with an institutional investor for the purchase...

Read moreDetails

Venice Security Launches with $33M to Redefine Enterprise Privileged Access Management in the AI Era

Backed by IVP and Index, Venice gives organisations real-time, zero-standing-privilege control over high-risk access points across cloud, SaaS, on-prem, and AI-driven systems NEW YORK CITY, NEW YORK / ACCESS Newswire / February 18, 2026 / Venice (formerly Valkyrie), an adaptive privileged access platform, today announced its launch and $33M in...

Read moreDetails

Zero-Training CRM: Bitrix24’s Guide to Faster Adoption and Higher Sales in 2026

Bitrix24 Growth Hub article presents a practical six-step framework to help businesses simplify CRM implementation, drive consistent adoption, and remove the everyday obstacles that slow sales productivity. WASHINGTON, D.C. / ACCESS Newswire / February 18, 2026 / Companies are investing heavily in CRM software to improve sales pipeline visibility, customer...

Read moreDetails

New Open-Source SOC Grader Solves the MDR “Mean Time to Detect Poor Quality” Problem

The free tool uses a transparent rubric to score cases consistently - turning reviews into a repeatable feedback loop, with data staying in your environment. PALO ALTO, CA / ACCESS Newswire / February 18, 2026 / Today, AirMDR released SOC Grader, a first-in-the-market open source tool that solves the challenge...

Read moreDetails

Komerz Acquires Pathformance to Build the Commercial Growth Operating System for Global Brands

The Acquisition Brings Together Komerz's Global Commerce Platform With Pathformance's Industry-Leading Measurement and Attribution Expertise, Creating a Unified Growth Engine Valued in the Hundreds of Millions and Charting a Path to Unicorn Status CITY OF LONDON, GB / ACCESS Newswire / February 18, 2026 / Komerz Ltd., a global commercial...

Read moreDetails

Cyberentic Expands Nationwide with AI-Powered Workflow Automation Services

Cyberentic technology team at work Cyberentic, an AI-driven automation firm founded in New York City, today announced its nationwide expansion, delivering intelligent workflow automation solutions to small and mid-sized businesses (SMBs) across major U.S. metropolitan areas. The expansion marks a significant step in the company's growth as demand increases for...

Read moreDetails

Softean Strengthens Its Position in Cryptocurrency Exchange and Wallet Development Services

Softean, a leading blockchain development company, continues to strengthen its position in Cryptocurrency Exchange Development and Cryptocurrency Wallet Development services by delivering secure, scalable, and high-performance digital asset solutions for global businesses.With the rapid growth of the crypto industry, startups and enterprises are actively seeking reliable technology partners to build...

Read moreDetails

AI Fraud Could Escalate Into a $1-2 Trillion Global Crisis by 2028, New Analysis Suggests

AI-driven fraud could become one of the largest economic threats of the decade, with global losses potentially reaching $1-2 trillion by 2028, according to a new analysis released by Social Links.The methodology behind the forecast combines long-term AI adoption modeling published in Sequoia Capital research with real-world fraud dynamics observed...

Read moreDetails

Abzer Expands UAE Digital Payment Capabilities Through BNPL Collaboration with Tamara

Abzer and Tamara Collaboration to Enable Flexible BNPL Payments in the UAE Abzer, an enterprise technology company delivering digital payment, invoicing, and revenue automation platforms, has announced a strategic collaboration with Tamara to introduce Buy Now, Pay Later (BNPL) capabilities across its payment ecosystem in the United Arab Emirates.The collaboration...

Read moreDetails

Connascent Brings a Simplicity-First Approach to Digital Agency Services for Small and Enterprise Businesses

Connascent is a digital agency for web development, apps, SEO, and advertising The digital services industry has long been criticized for overcomplicating what should be straightforward processes. Businesses looking for a new website, a mobile application, or help ranking on Google often find themselves buried in jargon, locked into long...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Best Crypto Investing App 2026 Announced

    7 shares
    Share 3 Tweet 2
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    80 shares
    Share 32 Tweet 20
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    151 shares
    Share 60 Tweet 38
  • Best Gold IRA Companies February 2026 Announced (Top Gold-backed IRA Companies Revealed)

    6 shares
    Share 2 Tweet 2
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    91 shares
    Share 36 Tweet 23
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • OLB Group Inc. Announces Pricing of $3.0 Million Private Placement at a Premium to Market
  • Venice Security Launches with $33M to Redefine Enterprise Privileged Access Management in the AI Era
  • Zero-Training CRM: Bitrix24’s Guide to Faster Adoption and Higher Sales in 2026
  • New Open-Source SOC Grader Solves the MDR “Mean Time to Detect Poor Quality” Problem
  • Komerz Acquires Pathformance to Build the Commercial Growth Operating System for Global Brands

RSS Latest on Block3Wire

  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age
  • Cathedra Bitcoin Announces Leasing of 2.5-MW Bitcoin Mining Facility
  • Global Web3 Payments Leader, Banxa, Announces Integration With Metis to Usher In Next Wave of Cryptocurrency Users
  • Dexalot Launches First Hybrid DeFi Subnet on Avalanche

RSS Latest on Meta3Wire

  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
  • MetatronAI.com Unveils Revolutionary AI-Chat Features and Interface Upgrades
  • Purely.website – Disruptive new platform combats rising web hosting costs
  • WEMADE and Metagravity Sign Strategic Alliance MOU to Collaborate on Blockchain Games for the Metaverse
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Whitepaper | Tokenomics

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Media Portfolio: Block3Wire | Meta3Wire

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!
Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.