Wednesday, May 27, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET Research discovers new spyware posing as messaging apps targeting users in the UAE

October 2, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 7 mins read
5
SHARES
248
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET Research has uncovered two previously undocumented Android spyware families, which ESET has named Android/Spy.ProSpy and Android/Spy.ToSpy.
  • ProSpy impersonates both Signal and ToTok, while ToSpy targets ToTok users exclusively.
  • Both malware families aim to exfiltrate user data, including documents, media, files, contacts, and chat backups.
  • Confirmed detections in the UAE and the use of both phishing and fake app stores suggest regionally focused operations with strategic delivery mechanisms.

MONTREAL and BRATISLAVA, Slovakia, Oct. 02, 2025 (GLOBE NEWSWIRE) — ESET researchers have uncovered two Android spyware campaigns targeting individuals interested in secure communication apps, namely Signal and ToTok. These campaigns distribute malware through deceptive websites and social engineering and appear to target residents of the United Arab Emirates (UAE). ESET’s investigation led to the discovery of two previously undocumented spyware families: Android/Spy.ProSpy impersonates upgrades or plugins for the Signal app and the controversial and discontinued ToTok app, and Android/Spy.ToSpy impersonates the ToTok app. The ToSpy campaigns are ongoing, as suggested by C&C servers that remain active.

“Neither app containing the spyware was available in official app stores; both required manual installation from third-party websites posing as legitimate services,” explains ESET researcher Lukáš Štefanko, who made the discovery. “Notably, one of the websites distributing the ToSpy malware family mimicked the Samsung Galaxy Store, luring users into manually downloading and installing a malicious version of the ToTok app. Once installed, both spyware families maintain persistence and continually exfiltrate sensitive data and files from compromised Android devices. Confirmed detections in the UAE and the use of phishing and fake app stores suggest regionally focused operations with strategic delivery mechanisms.”

ESET Research discovered the ProSpy campaign in June 2025, and it has likely been ongoing since 2024. ProSpy is being distributed through three deceptive websites designed to impersonate communication platforms Signal and ToTok. These sites offer malicious APKs posing as improvements, disguised as a Signal Encryption Plugin and ToTok Pro. The use of a domain name ending in the substring ae.net may suggest that the campaign targets individuals residing in the United Arab Emirates, as AE is the two-letter country code for the UAE.

During the investigation, ESET discovered five more malicious APKs using the same spyware codebase, posing as an enhanced version of the ToTok messaging app under the name ToTok Pro. ToTok, a controversial free messaging and calling app developed in the United Arab Emirates, was removed from Google Play and Apple’s App Store in December 2019 due to surveillance concerns. Given that its user base is primarily located in the UAE, it is likely that ToTok Pro may be targeting users in this region, who may be more liable to download the app from unofficial sources in their own region.

Upon execution, both malicious apps request permissions to access contacts, SMS messages, and files stored on the device. If these permissions are granted, ProSpy starts exfiltrating data in the background. The Signal Encryption Plugin extracts device information, stored SMS messages, and the contact list, and it exfiltrates other files – such as chat backups, audio, video, and images.

In June 2025, ESET telemetry systems flagged another previously undocumented Android spyware family actively distributed in the wild, originating from a device located in the UAE. ESET labeled the malware Android/Spy.ToSpy. Later investigation revealed four deceptive distribution websites impersonating the ToTok app. Given the app’s regional popularity and the impersonation tactics used by the threat actors, it is reasonable to speculate that the primary targets of this spyware campaign are users in the UAE or surrounding regions. In the background, the spyware can collect and exfiltrate the following data: user contacts, device information files such as chat backups, images, documents, audio, and video, among others. ESET findings suggest that the ToSpy campaign likely began in mid-2022.

“Users should remain vigilant when downloading apps from unofficial sources and avoid enabling installation from unknown origins, as well as when installing apps or add-ons outside of official app stores, especially those claiming to enhance trusted services,” advises Štefanko.

For a more detailed analysis and technical breakdown of Android/Spy.ProSpy and Android/Spy.ToSpy, check out the latest ESET Research blog post, “New spyware campaigns target privacy-conscious Android users in the UAE” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), Bluesky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts, and blogs.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Huize Holding Limited Announces Resignation of an Independent Director

Next Post

Transoft Solutions Receives AiRAP Accreditation

Related Posts

Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era

Disrupts AI-powered exploit-driven attacks earlier in the attack chain Enables security teams to prioritize remediation based on real attacker activity—not severity scores Automatically translates exploit intelligence into immediate protection across primary attack paths SUNNYVALE, Calif., May 27, 2026 (GLOBE NEWSWIRE) -- Proofpoint, Inc., a leading cybersecurity and compliance company, today...

Read moreDetails

2026 Capital Markets Day: Capgemini poised to capture the full value of the Agentic AI revolution

Media relations:Victoire GruxTel.: +33 6 04 52 16 55Email : victoire.grux@capgemini.com Investor relations:Vincent BiraudTel.: +33 1 47 54 50 87Email: vincent.biraud@capgemini.com 2026 Capital Markets Day:Capgemini poised to capture the full value of the Agentic AI revolution Capgemini presents today its strategic direction leveraging its unique positioning to help enterprises bridge the...

Read moreDetails

Astera Labs to Host Press Conference, Live Demos, and Technical Talks at Computex 2026

TAIPEI, Taiwan, May 26, 2026 (GLOBE NEWSWIRE) -- Astera Labs, Inc. (Nasdaq: ALAB), a leader in semiconductor-based connectivity solutions for rack-scale AI infrastructure, will host press and industry analysts at Computex 2026 in the company’s room at the Taipei Nangang Exhibition Center, Hall 1 (TaiNEX 1), Room 303, third floor....

Read moreDetails

Crypto News: AlphaPepe Presale Hits 9,000 Holders as Bitcoin Price Prediction Hits $100,000 Amid Iran War

MONACO, May 26, 2026 (GLOBE NEWSWIRE) -- Crypto news is turning toward AlphaPepe after the project announced that its presale has passed 9,000 holders while Stage 17 remains live at $0.01786 per token. The presale has raised over $1.33 million, the AlphaSwap AI DEX demo has surpassed 5,000 active users,...

Read moreDetails

Asset Workflows Secures Major Strategic Investment to Accelerate Growth Across Sectors and Regions

ABERDEEN, United Kingdom, May 27, 2026 (GLOBE NEWSWIRE) -- Asset Workflows Ltd, a specialist provider of asset data management, operational assurance, and digital workflow solutions, today announced a major strategic investment led by CoMade, alongside two highly regarded specialist healthcare investors. The investment will significantly strengthen Asset Workflows’ expansion across...

Read moreDetails

Evolution Metals & Technologies Corp. Regains Compliance with Nasdaq Listing Rule Following Previously Received Notice and Filing of Quarterly Report on Form 10-Q

MIAMI, FL, May 26, 2026 (GLOBE NEWSWIRE) -- Evolution Metals & Technologies Corp. (“EM&T” or the “Company”) (Nasdaq: EMAT), a U.S.-based critical materials and advanced manufacturing company focused on building a secure, vertically integrated supply chain for rare earth permanent magnets, battery materials, and related critical technologies, today announced that...

Read moreDetails

Global Mofy AI Limited Announces Closing of $8 Million Registered Offering

BEIJING, May 26, 2026 (GLOBE NEWSWIRE) -- Global Mofy AI Limited (the “Company” or “Global Mofy”) (Nasdaq: GMM), a generative AI-driven technology solutions provider engaged in virtual content production and the development of 3D digital assets, today announced the closing of its previously announced registered direct offering (the “Offering”) of...

Read moreDetails

Pasqal and Bleichroeder Acquisition Corp. II Announce Filing of Registration Statement on Form F-4 in Connection with Proposed Business Combination

PARIS and NEW YORK, May 26, 2026 (GLOBE NEWSWIRE) -- Pasqal Holding SAS (“Pasqal”), a global leader in neutral-atom quantum computing, and Bleichroeder Acquisition Corp. II (NASDAQ: BBCQ), a special purpose acquisition company (“Bleichroeder”), today announced the public filing with the U.S. Securities and Exchange Commission (the “SEC”) of their...

Read moreDetails

Microchip Technology to Present at the TD Cowen 54th Annual Technology, Media & Telecom Conference

CHANDLER, Ariz., May 26, 2026 (GLOBE NEWSWIRE) -- (NASDAQ:MCHP) – Microchip Technology Incorporated, a leading provider of smart, connected, and secure embedded control solutions, today announced that the Company will present at the TD Cowen 54th Annual Technology, Media & Telecom Conference on Thursday, May 28, 2026 at 11:25 a.m....

Read moreDetails

AGM Group Receives Notification from Nasdaq Regarding Delayed Filing of Form 20-F

NEW YORK, May 26, 2026 (GLOBE NEWSWIRE) -- AGM Group Holdings Inc. (NASDAQ: AGMH, “AGMH” or the “Company”), an integrated technology company specializing in the assembling and sales of high-performance hardware and computing equipment, today announced that it received a notification letter dated May 18, 2026 (the "Notification Letter") from...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Top Cross-Chain DeFi Solutions to Watch by 2025

    106 shares
    Share 42 Tweet 27
  • What is a Gold IRA? (Guide Released)

    7 shares
    Share 3 Tweet 2
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    168 shares
    Share 67 Tweet 42
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    60 shares
    Share 24 Tweet 15
  • Top Layer 1 Crypto Projects to Watch in 2025

    10 shares
    Share 4 Tweet 3
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era
  • Affordable SEO Expert Anatoly Zadorozhnyy Announces Launch of SEO Consulting Website
  • 2026 Capital Markets Day: Capgemini poised to capture the full value of the Agentic AI revolution
  • Astera Labs to Host Press Conference, Live Demos, and Technical Talks at Computex 2026
  • Crypto News: AlphaPepe Presale Hits 9,000 Holders as Bitcoin Price Prediction Hits $100,000 Amid Iran War

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.