Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

CISA Warns of Spyware Targeting Messaging App Users

CISA has described the techniques used by attackers and pointed out that the focus is on high-value individuals.

Spyware targets mobile

The cybersecurity agency CISA on Monday issued a warning over the use of commercial spyware to target the users of mobile messaging applications such as WhatsApp and Signal.

“Cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim’s mobile device,” CISA said.

The agency has referenced several threats and incidents detailed this year by the cybersecurity industry.

It pointed out that threat actors have leveraged zero-day and zero-click exploits to deliver spyware to targeted users. Examples provided by the agency include attacks conducted via WhatsApp against Apple device users, and Samsung phone owners being targeted with Android spyware named Landfall.

The cybersecurity agency also pointed to attacks in which Russian threat actors exploited Signal’s ‘linked devices’ feature for real-time spying. 

CISA’s alert also cites NSO spyware targeting WhatsApp users and the potential risks for strategic targets.

Advertisement. Scroll to continue reading.

The alert also references incidents in which hackers delivered spyware by disguising it as popular messaging applications. The ClayRat Android spyware, for instance, was delivered to Russian users disguised as WhatsApp. ProSpy and ToSpy were delivered to Android users in the United Arab Emirates disguised as Signal and ToTok.

“While current targeting remains opportunistic, evidence suggests these cyber actors focus on high-value individuals, such as current and former high-ranking government, military, and political officials, as well as civil society organizations (CSOs) and individuals across the United States, Middle East, and Europe,” CISA noted.

CISA has urged at-risk users to review its updated guidance for mobile communications security and its guidance for civil society

Related: Chrome Zero-Day Exploitation Linked to Hacking Team Spyware

Related: Samsung Patches Zero-Day Exploited Against Android Users

Related: Apple Sends Fresh Wave of Spyware Notifications to French Users

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.