By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
Tech News

CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users

By Viral Trending Content 4 Min Read
Share
SHARE

Nov 25, 2025Ravie LakshmananSpyware / Mobile Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday issued an alert warning of bad actors actively leveraging commercial spyware and remote access trojans (RATs) to target users of mobile messaging applications.

“These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim’s mobile device,” the agency said.

DFIR Retainer Services

CISA cited as examples multiple campaigns that have come to light since the start of the year. Some of them include –

  • The targeting of the Signal messaging app by multiple Russia-aligned threat actors by taking advantage of the service’s “linked devices” feature to hijack target user accounts
  • Android spyware campaigns codenamed ProSpy and ToSpy that impersonate apps like Signal and ToTok to target users in the United Arab Emirates to deliver malware that establishes persistent access to compromised Android devices and exfiltrates data
  • An Android spyware campaign called ClayRat has targeted users in Russia using Telegram channels and lookalike phishing pages by impersonating popular apps like WhatsApp, Google Photos, TikTok, and YouTube to trick users into installing them and steal sensitive data
  • A targeted attack campaign that likely chained two security flaws in iOS and WhatsApp (CVE-2025-43300 and CVE-2025-55177) to target fewer than 200 WhatsApp users
  • A targeted attack campaign that involved the exploitation of a Samsung security flaw (CVE-2025-21042) to deliver an Android spyware dubbed LANDFALL to Galaxy devices in the Middle East

The agency said the threat actors use multiple tactics to achieve compromise, including device-linking QR codes, zero-click exploits, and distributing spoofed versions of messaging apps.

CISA also pointed out that these activities focus on high-value individuals, primarily current and former high-ranking government, military, and political officials, along with civil society organizations and individuals across the United States, the Middle East, and Europe.

CIS Build Kits

To counter the threat, the agency is urging highly targeted individuals to review and adhere to the following best practices –

  • Only use end-to-end encrypted (E2EE) communications
  • Enable Fast Identity Online (FIDO) phishing-resistant authentication
  • Move away from Short Message Service (SMS)-based multi-factor authentication (MFA)
  • Use a password manager to store all passwords
  • Set a telecommunications provider PIN to secure mobile phone accounts
  • Periodically update software
  • Opt for the latest hardware version from the cell phone manufacturer to maximize security benefits
  • Do not use a personal virtual private network (VPN)
  • On iPhones, enable Lockdown Mode, enroll in iCloud Private Relay, and review and restrict sensitive app permissions
  • On Android phones, choose phones from manufacturers with strong security track records, only use Rich Communication Services (RCS) if E2EE is enabled, turn on Enhanced Protection for Safe Browsing in Chrome, ensure Google Play Protect is on, and audit and limit app permissions

You Might Also Like

11 Best Down Comforters (2025), Tested in Our Homes in Every Season

Auxilion survey reveals almost a third of office workers use their work device for personal use

How one uni achieved greater maths gender diversity in just five years

Meta’s Pyrefly Speeds up Python Type Checking by up to 95%

HBO Max Black Friday Deal: Now Just $2.99 a Month in Best-Ever Offer

TAGGED: Android, Cyber Security, Cybersecurity, Data Exfiltration, Internet, iOS, Messaging app, mobile security, social engineering, spyware
Share This Article
Facebook Twitter Copy Link
Previous Article Northern Ireland town set to rename street honouring former Prince Andrew
Next Article UAE president chairs ADNOC board meeting as company backs €130bn investment plan
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

11 Best Down Comforters (2025), Tested in Our Homes in Every Season
Tech News
Strategy ramps up capital mix shift as Bitcoin-focused funding model expands
Crypto
Pepe’s Bullish Wedge: Best Meme Coins Set to Rally
Crypto
US and Russia to hold Ukraine talks in Abu Dhabi after overnight strikes
World News
Pauline Hanson suspended from Australian Senate for wearing burqa in protest stunt
World News
Auxilion survey reveals almost a third of office workers use their work device for personal use
Tech News
To target £7,377 in annual passive income, how much should I invest in this FTSE dividend gem?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

11 Best Down Comforters (2025), Tested in Our Homes in Every Season

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
11 Best Down Comforters (2025), Tested in Our Homes in Every Season
November 25, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?