Researchers studying cybersecurity have found two Android spyware operations called ProSpy and ToSpy that target users in the United Arab Emirates (U.A.E.) by mimicking apps like Signal and ToTok.
According to Slovak cybersecurity firm ESET, the malicious apps are disseminated through social engineering and phony websites to fool unwary users into downloading them. Once installed, both strains of spyware software gain ongoing access to Android devices that have been infected and begin to steal data.
According to ESET researcher Lukáš Štefanko, none of the spyware-containing apps could be found in official app stores and had to be manually installed via unaffiliated websites masquerading as trustworthy services. Interestingly, one of the websites that spread the ToSpy malware family deceived users into manually downloading and installing a malicious version of the ToTok software by imitating the Samsung Galaxy Store.
The ProSpy campaign, which was uncovered in June 2025, is thought to have been active since 2024. It uses phony websites posing as Signal read more about Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
