Hacking

CISA Flags Rising Spyware Attacks Targeting Messaging App Users

Published  ·  2 min read

CISA has issued a warning this week after seeing a rush of attackers going after people through the messaging apps they rely on every day. The agency says the groups behind these campaigns aren’t just sending phishing texts, they’re installing full-blown spyware and remote access tools to slip into someone’s chats and then dig deeper into their phone.

Several incidents from the past year paint a clear picture. Some Russia-aligned groups have figured out how to abuse Signal’s linked-device feature, letting them quietly pull messages from a victim’s account. In the UAE, attackers have pushed fake versions of Signal and ToTok that look legitimate but secretly install Android spyware. There have also been cases in Russia where fake WhatsApp, YouTube, and Google Photos apps were distributed through Telegram channels, all leading to malware known as ClayRat.

Two more serious cases involved chained vulnerabilities, one set hitting fewer than 200 WhatsApp users, and another targeting Samsung Galaxy devices through a flaw now known as CVE-2025-21042. In that one, attackers installed a spyware family called LANDFALL.

CISA says these operations focus on a specific kind of victim: people whose messages matter. Senior government officials, political advisers, former diplomats, military personnel, and certain civil society groups have all been targets in different regions, especially the U.S., Europe, and the Middle East.

The agency also outlines what high-risk individuals should do to reduce their exposure. Some advice is simple, keep devices updated, avoid SMS-based two-factor codes, and use a password manager. Other steps are more specific. iPhone users should enable Lockdown Mode and limit which apps can access sensitive data. Android users should stick to manufacturers known for strong security support, turn on Chrome’s Enhanced Protection, and use RCS only when end-to-end encryption is available.

One recommendation : CISA suggests avoiding personal VPNs, which can sometimes create more problems than they solve.
The bottom line is that spyware is no longer limited to large espionage operations. It’s becoming easier to distribute, harder to detect, and more common in targeted attacks. Anyone who works in a sensitive role or communicates with someone who does should treat their phone as a priority security asset, not an afterthought.

Source : The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067