Back to News
Market Impact: 0.3

Spyware in Fake Signal and ToTok Apps Targets UAE Android Users

AAPLGOOGLGOOG
Cybersecurity & Data PrivacyTechnology & InnovationRegulation & Legislation

Cybersecurity firm ESET has identified two active mobile spyware campaigns, ProSpy and ToSpy, targeting users in the UAE by impersonating Signal and ToTok messaging apps to exfiltrate sensitive personal data, including contacts and chat backups. These campaigns, active since mid-2022, rely on users installing fake applications from unofficial sources, posing a significant data security risk. ESET's findings led Google to update Play Protect to block these variants, underscoring the ongoing threat landscape for mobile platforms and the critical need for robust digital security measures for companies operating in sensitive data environments.

Analysis

Cybersecurity firm ESET has uncovered two sophisticated mobile spyware campaigns, ProSpy and ToSpy, actively targeting users in the United Arab Emirates (UAE) by impersonating Signal and ToTok messaging applications. Operational since at least mid-2022 with command-and-control servers detected as recently as 2025, these campaigns exfiltrate sensitive personal data including contacts, messages, and chat backups. The malware leverages social engineering, requiring users to manually install malicious APK files from unofficial sources, mimicking legitimate app interfaces. ProSpy masquerades as a Signal "encryption plugin" or ToTok Pro add-on, while ToSpy directly impersonates ToTok, an app with a controversial history regarding user surveillance. Upon installation, the spyware requests common app permissions to collect device details, SMS, contact lists, and files, specifically targeting ToTok backup files for chat history. The fake Signal app even employs evasion tactics by changing its icon and name to "Google Play Services" post-setup, complicating detection. ESET's findings were shared with Google, leading to an update in Google Play Protect that now blocks known variants of these spyware families on Android devices, indicating a proactive industry response. While Google's action is a positive step (GOOGL/GOOG sentiment +0.2), the overall situation carries a strongly negative sentiment (-0.7) due to the persistent and evolving nature of mobile cyber threats. This incident underscores the critical need for robust digital security measures, particularly for companies handling sensitive user data.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.70

Ticker Sentiment

AAPL0.00
GOOG0.20
GOOGL0.20

Key Decisions for Investors

  • Investors should assess the cybersecurity investments and data protection strategies of technology companies, particularly those operating in high-risk regions or with large mobile user bases
  • Institutional investors with exposure to mobile platform providers like Google (GOOGL) should monitor their proactive measures against evolving malware threats and their impact on user trust and regulatory compliance
  • Companies with significant operations or user bases in regions like the UAE should conduct thorough due diligence on local digital security risks and data privacy frameworks