ToSpy is a spyware operation associated with campaigns that distribute malicious mobile applications impersonating popular consumer and messaging platforms in order to compromise victims’ devices and collect sensitive user data. The operation has been linked to broader activity involving state-backed actors and cyber-mercenary-style surveillance tradecraft targeting high-value individuals, including government, military, and political figures as well as civil society members. Reported targeting spans the United States, Europe, and the Middle East. The operation’s known tradecraft includes initial access through application impersonation and social-engineering lures that present counterfeit versions of trusted apps such as Signal and TikTok. Once installed, the spyware is used to harvest chat content, recordings, and files from infected devices. This reflects a broader pattern of bypassing the protections of encrypted messaging ecosystems by compromising endpoints and abusing user trust rather than defeating encryption directly. At high confidence, ToSpy should be understood as part of the commercial-spyware threat landscape focused on covert surveillance and data collection from mobile users. Publicly available information in this context does not firmly attribute the operators to a specific named state or country, nor does it establish distinct sub-groups or a broader alias set beyond ToSpy.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.