HomeSecurityCISA: Spyware campaigns target Signal & WhatsApp users

CISA: Spyware campaigns targeting Signal & WhatsApp users

The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about malicious actors actively exploiting commercial spyware and remote access trojans (RATs) to target users of mobile messaging apps, including Signal and WhatsApp users.

 Signal & WhatsApp spyware

“ These cybercriminals use advanced targeting and social engineering to deliver spyware and gain unauthorized access to the victim’s messaging app, facilitating the deployment of additional malicious payloads that can further exacerbate the mobile device victim’s techniques compromise of the ,” the agency said

See also: APT group ToddyCat gains access to internal employee communications

CISA cited multiple campaigns that have come to light since the beginning of the year as examples. Some of these include:

  • The targeting of the messaging app Signal by multiple threat actors linked to Russia , exploiting the service's " linked devices " feature to take over target user accounts.
  • Android spyware campaigns, codenamed ProSpy and ToSpy, impersonate apps like Signal and ToTok to target users in the United Arab Emirates, delivering malware that installs persistent access to compromised Android devices.
  • An Android spyware, dubbed ClayRat, has targeted users in Russia using Telegram channels and phishing pages that resemble popular apps like WhatsApp, Google Photos, TikTok, and YouTube. The goal is to trick users into installing them and steal sensitive data.
  • A targeted campaign that likely combined two security vulnerabilities in iOS and WhatsApp (CVE-2025-43300 and CVE-2025-55177) to target fewer than 200 WhatsApp users.
  • A targeted campaign that involved exploiting a Samsung security vulnerability (CVE-2025-21042) to deliver an Android spyware called LANDFALL to Galaxy devices in the Middle East.

See also: Hackers replace the letter 'm' with the combination 'rn' in Microsoft

The agency reported that threat actors are using multiple tactics to achieve a breach, including QR codes to connect devices, zero-click exploits, and the distribution of tampered versions of messaging apps.

CISA also noted that these activities focus on “high-value” individuals, primarily current and former high-ranking government, military and political officials, as well as civil society organizations and individuals in the United States, the Middle East and Europe.

See also: ShadowPad malware: Distribution via WSUS vulnerability

CISA: Spyware campaigns targeting Signal & WhatsApp users

Spyware targets WhatsApp and Signal users: Protection

To address the threat, the agency urges targets to consider and adhere to the following best practices:

  • Use only end-to-end encrypted (E2EE) communications.
  • Enable phishing-resistant Fast Identity Online (FIDO) authentication
  • Move away from SMS-based multi-factor authentication (MFA).
  • Use a manager password to store all your passwords.
  • Set a PIN carrier to secure your mobile accounts.
  • Update the software periodically.
  • Choose the latest hardware version from your mobile phone manufacturer to maximize security benefits.
  • Do not use a personal virtual private network (VPN).
  • On iPhones, enable Lockdown Mode, sign up for iCloud Private Relay , and review and restrict “sensitive” app permissions.
  • On Android, choose phones from manufacturers with strong security histories, only use Rich Communication Services (RCS) if E2EE is enabled, enable Enhanced Protection for Safe Browsing in Chrome, make sure Google Play Protect is active, and review and restrict app permissions.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS