Cybercriminals have launched a wave of attacks targeting the exact people trying hardest to avoid surveillance—by impersonating the encrypted messaging apps they trust.
Security teams report a sharp uptick in fake Signal and ToTok applications circulating through phishing sites and unofficial app stores. The malicious apps mirror the real thing so closely that users believe they’re downloading legitimate privacy tools.
The scam exploits a basic assumption: if you’re installing a secure messenger, of course it needs access to your contacts, messages, and camera.
Victims approve sweeping permissions without suspicion, then watch the app function normally—unaware it’s simultaneously feeding their data to attackers.
Distribution happens through sideloading—users download APK files from impostor websites rather than official stores.
Once granted system access, the spyware operates invisibly, collecting photos, location data, call records and messages while maintaining its disguise as a working chat app.
The attacks have accelerated in recent months. Researchers say the tactic is particularly effective because it weaponizes security awareness itself—people who specifically sought out privacy tools become victims precisely because they trusted those brands.
Standard advice applies: only download apps from official sources. But the campaigns highlight a darker trend—as users become more privacy-conscious, attackers are learning to exploit that consciousness as a vulnerability.
Security firm WeLiveSecurity has tracked two separate malware strains behind the attacks. The first, dubbed AndroidSpy.ProSpy, masquerades as add-on plugins for Signal and ToTok. The second, AndroidSpy.ToSpy, poses as a complete ToTok application.
Researchers traced ProSpy distribution to domains including signal.ct.ws and encryption-plugin-signal.com-ae.net, which pushed a fictional “Signal Encryption Plugin” that doesn’t actually exist. ToSpy variants appeared on sites designed to look like Samsung’s Galaxy Store.
Both require users to manually enable Android’s “install from unknown sources” setting—a security feature most people leave disabled. The campaigns rely on victims following installation instructions that walk them through loosening their own security protections.
The attacks have intensified in recent months, with researchers warning the tactics exploit security awareness as a vulnerability: people seeking privacy tools become targets because they trust the brands being impersonated.
The campaigns appear regionally focused on the United Arab Emirates, leveraging local user bases of Signal and ToTok. Upon installation, the spyware requests access to contacts, SMS messages, file storage, and device information.

Both require users to manually enable Android’s “install from unknown sources” setting—a security feature most people leave disabled. The campaigns rely on victims following installation instructions that walk them through loosening their own security protections.
Once permissions are approved, both malware strains immediately begin data collection. They harvest device specifications, operating system details, chat backups, photos, videos, documents, and lists of installed applications—essentially creating a complete profile of the compromised phone.
ToTok-specific spyware even targets .ttkmbackup files to harvest chat histories. Both malware families then encrypt the stolen data with a hard-coded AES-CBC key (p2j8w9savbny75xg) and send the ciphertext to their command-and-control endpoints via HTTPS POST.
Infection Mechanism
The infection mechanism begins with social-engineering lures—users encountering links via messaging apps or spoofed social media posts.
When a victim clicks a malicious link, they land on a deceptively branded page that imitates familiar app repositories.
One variant, ProSpy, was distributed through domains offering an “Encryption Plugin” that falsely claimed to boost messaging security — but required users to manually install an APK file.
A related campaign, ToSpy, used phishing pages designed to mimic Samsung’s Galaxy Store, tricking users into downloading a fake “ToTok Pro” app.
Once sideloaded, the app established a persistent background service, displayed a professional-looking onboarding screen, and disguised itself by changing its icon and name to “Play Services.”
To maintain persistence, the spyware employed Android’s AlarmManager to restart itself if terminated and registered a BOOT_COMPLETED receiver to automatically relaunch after device reboots.
Through a blend of social engineering, deceptive branding, and hidden background processes, the malware ensures ongoing data exfiltration with minimal user detection.
Security experts warn that these campaigns are still active, urging Android users to avoid sideloading apps from unverified sources and to keep Google Play Protect enabled.

