CyberzSOC

Publication detail
← Back to advisories & guidance

​​Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications​ ↗ source

November 24, 2025 CISA Alert

Summary

1 These cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app, facilitating the deployment of additional malicious payloads that can further compromise the victim’s mobile device. These cyber actors use tactics such as: Phishing and malicious device-linking QR codes to compromise victim accounts and link them to actor-controlled devices. Zero-click exploits, 2 which require no direct action from the device user. Impersonation 3 of messaging app platforms, such as Signal and WhatsApp. While current targeting remains opportunistic, evidence suggests these cyber actors focus on high-value individuals, such as current and former high-ranking government, military, and political officials, 4 as well as civil society organizations (CSOs) and individuals across the United States, 5 Middle East, 6 and Europe. 7 CISA strongly encourages messaging app users to review the updated Mobile Communications Best Practice Guidance and Mitigating Cyber Threats with Limited Resources: Guidance for Civil Society for steps to protect mobile communications and messaging apps, as well as mitigations against spyware. 7 Paganini, “ ClayRat Campaign Uses Telegram and Phishing Sites to Distribute Android Spyware. ” This product is provided subject to this Notification and this Privacy & Use policy.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.