ESET researchers have uncovered two Android spyware campaigns targeting individuals interested in secure communication apps, namely Signal and ToTok. These campaigns distribute malware through deceptive websites and social engineering and appear to target residents of the United Arab Emirates (UAE). ESET’s investigation led to the discovery of two previously undocumented spyware families: Android/Spy.ProSpy impersonates upgrades or plugins for the Signal app and the controversial and discontinued ToTok app, and Android/Spy.ToSpy impersonates the ToTok app. The ToSpy campaigns are ongoing, as suggested by C&C servers that remain active.
ESET Research discovered the ProSpy campaign in June 2025, and it has likely been ongoing since 2024. ProSpy is being distributed through three deceptive websites designed to impersonate communication platforms Signal and ToTok. These sites offer malicious APKs posing as improvements, disguised as a Signal Encryption Plugin and ToTok Pro. The use of a domain name ending in the substring ae.net may suggest that the campaign targets individuals residing in the United Arab Emirates, as AE is the two-letter country code for the UAE.
During the investigation, ESET discovered five more malicious APKs using the same spyware codebase, posing as an enhanced version of the ToTok messaging app under the name ToTok Pro. ToTok, a controversial free messaging and calling app developed in the United Arab Emirates, was removed from Google Play and Apple’s App Store in December 2019 due to surveillance concerns. Given that its user base is primarily located in the UAE, it is likely that ToTok Pro may be targeting users in this region, who may be more liable to download the app from unofficial sources in their own region.
Upon execution, both malicious apps request permissions to access contacts, SMS messages, and files stored on the device. If these permissions are granted, ProSpy starts exfiltrating data in the background. The Signal Encryption Plugin extracts device information, stored SMS messages, and the contact list, and it exfiltrates other files – such as chat backups, audio, video, and images.
In June 2025, ESET telemetry systems flagged another previously undocumented Android spyware family actively distributed in the wild, originating from a device located in the UAE. ESET labeled the malware Android/Spy.ToSpy. Later investigation revealed four deceptive distribution websites impersonating the ToTok app. Given the app’s regional popularity and the impersonation tactics used by the threat actors, it is reasonable to speculate that the primary targets of this spyware campaign are users in the UAE or surrounding regions. In the background, the spyware can collect and exfiltrate the following data: user contacts, device information files such as chat backups, images, documents, audio, and video, among others. ESET findings suggest that the ToSpy campaign likely began in mid-2022.
For a more detailed analysis and technical breakdown of Android/Spy.ProSpy and Android/Spy.ToSpy, check out the latest ESET Research blog post, “New spyware campaigns target privacy-conscious Android users in the UAE” on WeLiveSecurity.com.
Saviynt Launches UNLOCK Global Tour to Showcase the Future of AI-Powered Identity Security
Posted in Commentary with tags Saviynt on October 7, 2025 by itnerdSaviynt, a leader in AI-powered identity security solutions, today announced the launch of its global UNLOCK Tour: Unlock Possibility. Govern Every Identity. Accelerate with AI. This exclusive 2025 event series will explore how organizations are approaching the AI era – spotlighting AI’s incredible potential alongside the critical need to secure and govern it. Attendees will gain actionable blueprints from global industry leaders and practitioners on how intelligent identity security can help enterprises achieve more than they ever thought possible.
The tour will feature a session led by Amazon Web Services (AWS) titled “Leveraging AI to Unlock Productivity and Elevate Security of Cloud Workloads.” In collaboration with Saviynt, AWS will showcase how organizations can harness the power of AI to achieve new levels of security, operational efficiency, and innovation in the intelligence age.
At each UNLOCK event, attendees will:
Explore AI’s Promise and Risks – Understand how AI is reshaping the enterprise, and why securing and governing it is essential to success.
Experience Real-World Strategies – Learn from customer transformation stories and live demos of AI-powered identity security capabilities in action.
Gain Practical Blueprints – Frameworks for streamlining compliance, consolidating tools, and improving efficiency.
Connect with Peers and Innovators – Build relationships through panels, roundtables, networking, and executive 1:1s, with Saviynt executives including CEO Sachin Nayyar, President Paul Zolfaghari, Chief Product & Strategy Officer Jeff Margolies, COO Shankar Ganapathy, Chief Product Officer Vibhuti Sinha, SVP of Strategy Henrique Teixeira, Field CTO David Lee, and Field CIO Simon Gooch.
2025 UNLOCK Tour Dates:
Saviynt’s UNLOCK Global Tour is complimentary for prospects, customers, and partners. To learn more about the event and register for a city near you, please visit https://saviynt.com/unlock-roadshow.
Leave a comment »