Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: Spyware Gangs Now Impersonating Signal, ToTok to Hack Privacy-Seekers
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Cyber > Spyware Gangs Now Impersonating Signal, ToTok to Hack Privacy-Seekers
Cyber

Spyware Gangs Now Impersonating Signal, ToTok to Hack Privacy-Seekers

A new strain of Android spyware is targeting device users by disguising itself as trusted apps like Signal and ToTok. Once installed, these malicious payloads take advantage of users’ trust to compromise their data and security.

Editorial Desk
Last updated: October 6, 2025 6:34 pm
Editorial Desk
Share
SHARE

Cybercriminals have launched a wave of attacks targeting the exact people trying hardest to avoid surveillance—by impersonating the encrypted messaging apps they trust.

Security teams report a sharp uptick in fake Signal and ToTok applications circulating through phishing sites and unofficial app stores. The malicious apps mirror the real thing so closely that users believe they’re downloading legitimate privacy tools.

The scam exploits a basic assumption: if you’re installing a secure messenger, of course it needs access to your contacts, messages, and camera.

Victims approve sweeping permissions without suspicion, then watch the app function normally—unaware it’s simultaneously feeding their data to attackers.

Distribution happens through sideloading—users download APK files from impostor websites rather than official stores.

Once granted system access, the spyware operates invisibly, collecting photos, location data, call records and messages while maintaining its disguise as a working chat app.

The attacks have accelerated in recent months. Researchers say the tactic is particularly effective because it weaponizes security awareness itself—people who specifically sought out privacy tools become victims precisely because they trusted those brands.

Standard advice applies: only download apps from official sources. But the campaigns highlight a darker trend—as users become more privacy-conscious, attackers are learning to exploit that consciousness as a vulnerability.

Security firm WeLiveSecurity has tracked two separate malware strains behind the attacks. The first, dubbed AndroidSpy.ProSpy, masquerades as add-on plugins for Signal and ToTok. The second, AndroidSpy.ToSpy, poses as a complete ToTok application.

Researchers traced ProSpy distribution to domains including signal.ct.ws and encryption-plugin-signal.com-ae.net, which pushed a fictional “Signal Encryption Plugin” that doesn’t actually exist. ToSpy variants appeared on sites designed to look like Samsung’s Galaxy Store.

Both require users to manually enable Android’s “install from unknown sources” setting—a security feature most people leave disabled. The campaigns rely on victims following installation instructions that walk them through loosening their own security protections.

The attacks have intensified in recent months, with researchers warning the tactics exploit security awareness as a vulnerability: people seeking privacy tools become targets because they trust the brands being impersonated.

The campaigns appear regionally focused on the United Arab Emirates, leveraging local user bases of Signal and ToTok. Upon installation, the spyware requests access to contacts, SMS messages, file storage, and device information.

Signal, ToTok to Hack Privacy Spyware chart

Both require users to manually enable Android’s “install from unknown sources” setting—a security feature most people leave disabled. The campaigns rely on victims following installation instructions that walk them through loosening their own security protections.

Once permissions are approved, both malware strains immediately begin data collection. They harvest device specifications, operating system details, chat backups, photos, videos, documents, and lists of installed applications—essentially creating a complete profile of the compromised phone.

ToTok-specific spyware even targets .ttkmbackup files to harvest chat histories. Both malware families then encrypt the stolen data with a hard-coded AES-CBC key (p2j8w9savbny75xg) and send the ciphertext to their command-and-control endpoints via HTTPS POST.


Infection Mechanism

The infection mechanism begins with social-engineering lures—users encountering links via messaging apps or spoofed social media posts.

When a victim clicks a malicious link, they land on a deceptively branded page that imitates familiar app repositories.

One variant, ProSpy, was distributed through domains offering an “Encryption Plugin” that falsely claimed to boost messaging security — but required users to manually install an APK file.

A related campaign, ToSpy, used phishing pages designed to mimic Samsung’s Galaxy Store, tricking users into downloading a fake “ToTok Pro” app.

Once sideloaded, the app established a persistent background service, displayed a professional-looking onboarding screen, and disguised itself by changing its icon and name to “Play Services.”

To maintain persistence, the spyware employed Android’s AlarmManager to restart itself if terminated and registered a BOOT_COMPLETED receiver to automatically relaunch after device reboots.

Through a blend of social engineering, deceptive branding, and hidden background processes, the malware ensures ongoing data exfiltration with minimal user detection.

Security experts warn that these campaigns are still active, urging Android users to avoid sideloading apps from unverified sources and to keep Google Play Protect enabled.

ByEditorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article Search Engine Wars AI Perplexity The Search Wars Heat Up: Why Silicon Valley Is Betting Billions On AI’s Answer To Google
Next Article SOTI Launches New Mobile Tech That’s Changing the T&L Game SOTI Launches New Mobile Tech That’s Changing the T&L Game
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

New Android Spyware Attacking Android Users Mimic as Signal and ToTok Apps

Tech Articles

Sean Yu, VP of Commercial APAC at EBANX.

The Consumers Driving Global E-Commerce Growth Are Closer to Australia Than Many Businesses Think

The consumers driving global e-commerce growth are closer to Australia…

June 9, 2026
The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

How some of the internet’s best independent blogs were quietly…

June 3, 2026
Why your nbn evening speeds slow down

Why Your NBN Slows Down at Night — And How To Find the Real Cause

NBN slow at night? ACCC data shows why evening speeds…

July 2, 2026

Recent News

Log4j
Cyber

Recommendations for Log4j Mitigation

10 Min Read
Radware Hacktivists Target Paris 2024 Olympics - Tech News
Cyber

Hacktivists Target Paris 2024 Olympics with Advanced DDoS Attacks

2 Min Read
US Schools Cyber Attacks
CyberWorld Tech

Cyberattacks on US schools increasing amid reliance on technology

5 Min Read
IDSAustralia - Domain Name Scam
Cyber

idsaustralia.net Domain Name Scam Targets Australian Website Owners

2 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

July, 23, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?