By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
Computing

CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users

News Room
Last updated: 2025/11/25 at 1:58 AM
News Room Published 25 November 2025
Share
CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
SHARE

Nov 25, 2025Ravie LakshmananSpyware / Mobile Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday issued an alert warning of bad actors actively leveraging commercial spyware and remote access trojans (RATs) to target users of mobile messaging applications.

“These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim’s mobile device,” the agency said.

DFIR Retainer Services

CISA cited as examples multiple campaigns that have come to light since the start of the year. Some of them include –

  • The targeting of the Signal messaging app by multiple Russia-aligned threat actors by taking advantage of the service’s “linked devices” feature to hijack target user accounts
  • Android spyware campaigns codenamed ProSpy and ToSpy that impersonate apps like Signal and ToTok to target users in the United Arab Emirates to deliver malware that establishes persistent access to compromised Android devices and exfiltrates data
  • An Android spyware campaign called ClayRat has targeted users in Russia using Telegram channels and lookalike phishing pages by impersonating popular apps like WhatsApp, Google Photos, TikTok, and YouTube to trick users into installing them and steal sensitive data
  • A targeted attack campaign that likely chained two security flaws in iOS and WhatsApp (CVE-2025-43300 and CVE-2025-55177) to target fewer than 200 WhatsApp users
  • A targeted attack campaign that involved the exploitation of a Samsung security flaw (CVE-2025-21042) to deliver an Android spyware dubbed LANDFALL to Galaxy devices in the Middle East

The agency said the threat actors use multiple tactics to achieve compromise, including device-linking QR codes, zero-click exploits, and distributing spoofed versions of messaging apps.

CISA also pointed out that these activities focus on high-value individuals, primarily current and former high-ranking government, military, and political officials, along with civil society organizations and individuals across the United States, the Middle East, and Europe.

CIS Build Kits

To counter the threat, the agency is urging highly targeted individuals to review and adhere to the following best practices –

  • Only use end-to-end encrypted (E2EE) communications
  • Enable Fast Identity Online (FIDO) phishing-resistant authentication
  • Move away from Short Message Service (SMS)-based multi-factor authentication (MFA)
  • Use a password manager to store all passwords
  • Set a telecommunications provider PIN to secure mobile phone accounts
  • Periodically update software
  • Opt for the latest hardware version from the cell phone manufacturer to maximize security benefits
  • Do not use a personal virtual private network (VPN)
  • On iPhones, enable Lockdown Mode, enroll in iCloud Private Relay, and review and restrict sensitive app permissions
  • On Android phones, choose phones from manufacturers with strong security track records, only use Rich Communication Services (RCS) if E2EE is enabled, turn on Enhanced Protection for Safe Browsing in Chrome, ensure Google Play Protect is on, and audit and limit app permissions

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article This stunning LG Ultragear gaming monitor has hit its best-ever price over Black Friday — save over 0 at Amazon This stunning LG Ultragear gaming monitor has hit its best-ever price over Black Friday — save over $800 at Amazon
Next Article Trump Is Boosting MAGA X Accounts Operating Overseas Trump Is Boosting MAGA X Accounts Operating Overseas
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Theragun Alternatives: All the Best Budget Massage Guns You Can Buy in 2025
Theragun Alternatives: All the Best Budget Massage Guns You Can Buy in 2025
News
👨🏿‍🚀 Daily – Uber goes Electric |
👨🏿‍🚀 Daily – Uber goes Electric |
Computing
Kuardun7.0 Official Token Pre-Sale: Last Chance for Early Access KRN
Kuardun7.0 Official Token Pre-Sale: Last Chance for Early Access KRN
Gadget
AI could replace 3m low-skilled jobs in the UK by 2035, research finds
AI could replace 3m low-skilled jobs in the UK by 2035, research finds
Software

You Might also Like

👨🏿‍🚀 Daily – Uber goes Electric |
Computing

👨🏿‍🚀 Daily – Uber goes Electric |

2 Min Read
MiniPay, Ruul partner to open access to stablecoins for freelancers
Computing

MiniPay, Ruul partner to open access to stablecoins for freelancers

5 Min Read
Hyperbridge says it is building a hyperstructure for crypto bridges
Computing

Hyperbridge says it is building a hyperstructure for crypto bridges

28 Min Read
Huawei Cloud launches major restructuring, merges departments to focus on AI · TechNode
Computing

Huawei Cloud launches major restructuring, merges departments to focus on AI · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?