Skip to content

ProSpy

ProSpy is an Android spyware family, detected by ESET as Android/Spy.ProSpy, that has been active since at least 2024 and was discovered in June 2025.

Profile source: Mallory opens in a new tab

ProSpy

Family profile

ProSpy is an Android spyware family, detected by ESET as Android/Spy.ProSpy, that has been active since at least 2024 and was discovered in June 2025. It was distributed outside official app stores via fake websites and phishing pages, primarily targeting users in the United Arab Emirates. ProSpy impersonated a nonexistent Signal Encryption Plugin and a fake ToTok Pro application; reporting also states it masqueraded as other communications apps including WhatsApp, Zoom, and Botim in related campaigns. Known distribution domains mentioned in the reporting include signal.ct[.]ws, encryption-plug-in-signal.com-ae[.]net, and totok-pro[.]io.

Once installed, ProSpy requests access to contacts, SMS messages, and files stored on the device, then exfiltrates sensitive data including device information, public IP address, SMS messages, contact lists, installed applications, and files such as documents, archives, images, audio, and video. Reported local staging filenames include contacts_list.json, device_info.json, and sms_list.json. In broader reporting on associated espionage activity, ProSpy was described as capable of stealing chats, files, media, SMS messages, contacts, and app backups, and in some accounts as providing full device control.

The malware uses persistence mechanisms including foreground services, AlarmManager restarts, and BOOT_COMPLETED receivers. The Signal-themed variant could change its icon and label to Play Services using Android activity-alias functionality, launch the legitimate Signal app, or redirect users to signal.org if Signal was not installed. The fake ToTok Pro variant redirected users to the official ToTok download page and later launched the real ToTok app to reduce suspicion.

Multiple reports link ProSpy to espionage targeting journalists, activists, opposition figures, and some government-linked individuals across the Middle East and North Africa, with confirmed or likely targeting in the UAE and reporting also naming Egypt, Lebanon, and Bahrain. Lookout attributed malware used in this broader campaign to the South Asian threat group BITTER, also known as T-APT-17 and APT-Q-37, citing code similarities between ProSpy and the earlier Dracarys malware, though ESET stated attribution for the ProSpy campaign itself remained unknown. Researchers assessed the activity as surveillance-oriented and possibly hack-for-hire. CISA later highlighted ProSpy among spyware campaigns abusing trust in messaging applications to target high-value individuals.

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Aug 26, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Reported operators

Threat actors

2 named in public reporting
APT Q 37

This joint research, and an October 2025 report from ESET, reveals that Android users are tricked into downloading any of these malware: ProSpy or ToSpy. Both are spyware... Researchers explain that ProSpy is a feature-rich spyware developed in Kotlin, and out of the 11 ProSpy samples obtained, the earliest was from August 2024.

Bitter

This joint research, and an October 2025 report from ESET, reveals that Android users are tricked into downloading any of these malware: ProSpy or ToSpy. Both are spyware... Researchers explain that ProSpy is a feature-rich spyware developed in Kotlin, and out of the 11 ProSpy samples obtained, the earliest was from August 2024.

MITRE ATT&CK

ProSpy in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.