Android/Spy.ToSpy is a previously undocumented Android spyware family reported by ESET in 2025. It was observed actively distributed in the wild, with telemetry indicating activity originating from a device located in the UAE, and confirmed detections in the UAE. The malware was described alongside Android/Spy.ProSpy as part of Android spyware campaigns impersonating Signal or ToTok, or targeting ToTok users. Reported distribution vectors include phishing and fake app stores. High-confidence context indicates it is Android spyware targeting mobile users in the UAE; no additional technical capabilities or specific indicators of compromise were provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
"Cybersecurity Training Programs Don’t Prevent Employees from Falling for Phishing Scams" ... "After sending 10 different types of phishing emails..."; "...servers... resolve multiple domains used for phishing purpose."; "...use of phishing and fake app stores..."; "...email attachment."
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware family targeting ToTok users to exfiltrate user data (documents, media/files, contacts, chat backups); observed targeting UAE users via phishing/fake app stores.
Android/Spy.ToSpy is an Android spyware family that impersonates the ToTok messaging app, distributed via phishing websites mimicking legitimate app stores. It targets users (primarily in the UAE) to exfiltrate contacts, files (including ToTok chat backups), and device information. It uses AES encryption for exfiltrated data and maintains persistence via Android services and boot receivers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.