Advertisement
Subscribe to our daily newsletter.
Subscribe

CISA alert draws attention to spyware’s targeting of messaging apps

The agency’s brief notice also directed messaging app users to advice on how to protect themselves.

By

Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
In this photo illustration, social media and messaging apps are seen on a mobile phone screen on Nov. 11, 2025 in Istanbul, Turkey. (Photo Illustration by Chris McGrath/Getty Images)

The Cybersecurity and Infrastructure Security Agency warned Monday about threat groups using commercial spyware to target messaging apps, and urged users to take protective steps.

“CISA is aware of multiple cyber threat actors actively leveraging commercial spyware to target users of mobile messaging applications (apps),” the agency said in abrief online notice. “These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim’s mobile device.”

The warning draws on research this year that calls attention to hackers who aremimicking popular apps to deploy Android spyware, as well as Android spywaretargeting Samsung devices by sending image files over WhatsApp. The warning also piggybacks on research about Russian hackersinfecting Signal accounts.

“While current targeting remains opportunistic, evidence suggests these cyber actors focus on high-value individuals, such as current and former high-ranking government, military, and political officials, as well as civil society organizations (CSOs) and individuals across the United States, Middle East, and Europe,” the CISA warning states.

Advertisement

It’s rare, but not unheard of, for CISA to warn about spyware threats.One alert dates back to 2009 from a predecessor to CISA. It has releasedcybersecurity advice for dealing with spyware, and placed vulnerabilities that spyware vendors have exploited on its so-called“must-patch” list for federal agencies, includingthe recent Samsung vulnerability.

This time, CISA directed users tomobile security guidelines and advice forcivil society groups

Beyond the warnings about targeting messaging apps, CISA also said threat groups are using malicious QR codes and zero-click exploits, which infect users even if they don’t take any direct action themselves.

Advertisement
Advertisement

More Like This

  1. Privacy group sues feds over talks with tech companies on ICE raid trackers 

  2. NSO Group argues WhatsApp injunction threatens existence, future U.S. government work

  3. The slow rise of SBOMs meets the rapid advance of AI

Advertisement

Top Stories

  1. New legislation targets scammers that use AI to deceive

  2. Crisis24 shuts down emergency notification system in wake of ransomware attack

  3. Congress calls on Anthropic CEO to testify on Chinese Claude espionage campaign

Advertisement

More Scoops

(Getty Images)

New Landfall spyware apparently targeting Samsung phones in Middle East

Palo Alto Networks researchers haven’t been able to identify who’s behind the commercial-grade tech yet.
The Signal encrypted messaging application is seen on a mobile device in this illustration photo taken in Warsaw, Poland on March 25, 2025. (Photo by Jaap Arriens/NurPhoto)

Android spyware disguised as legitimate messaging apps targets UAE victims, researchers reveal

DHS, Department of Homeland Security, cybersecurity, Cyber Storm
(Getty Images)

CISA alerts federal agencies of widespread attacks using Cisco zero-days

Latest Podcasts

What happens if CISA 2015 lapses?

How Visa’s CISO turns a ‘paranoid and pessimisitic mindset’ into positive security outcomes

What security teams should do to prepare for the quantum computing future

CMMC compliance made practical: A data-first path forward

Government

Technology

Threats

Policy