Spyrtacus is a spyware family identified in malicious applications linked by researchers and reporting to the Italian surveillance vendor SIO and its subsidiary ASIGINT. Lookout identified the malware name from references in the code and found 13 samples dating from 2019 through October 17, 2024. The malware was embedded in Android apps masquerading as WhatsApp and Italian telecom or support applications, including apps impersonating TIM, Vodafone, and WINDTRE. Reporting also states that an unofficial iPhone version of WhatsApp used against targets in Italy contained spyware previously identified as Spyrtacus, indicating use on iPhone/iOS in addition to Android; Kaspersky also reported finding a Windows version and indicators suggesting possible iOS and macOS variants.
Documented capabilities include theft of text messages, chats and chat histories from apps such as WhatsApp, Signal, and Facebook Messenger, exfiltration of contacts and call logs, recording of phone calls and ambient audio via the microphone, and capture of images or video through device cameras. Multiple sources described the activity as highly targeted and consistent with government spyware.
Distribution initially included Google Play-hosted apps in 2018 according to Kaspersky, but by 2019 had shifted largely to malicious websites and phishing pages impersonating major Italian internet or telecom providers; later reporting on the fake WhatsApp campaign said distribution relied on social engineering and third-party channels rather than official app stores. Google stated protections against Spyrtacus had been in place since 2022 and that no apps containing the malware were currently on Google Play.
Attribution in the provided content centers on SIO/ASIGINT: command-and-control servers were reportedly registered to ASIGINT and another linked company, DataForense; ASIGINT was described as an SIO subsidiary involved in computer wiretapping software; and public records and employee statements were cited as linking the 'Spyrtacus Project' to these entities. The campaign appears focused on Italy, with apps, infrastructure lures, and most reported victims tied to the Italian context. No specific IOC values are provided in the content beyond the malware name, associated fake app themes, and the cited infrastructure linkage to ASIGINT and DataForense.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lookout identified the spyware as ‘Spyrtacus’, with reference to the malware itself being found in the code.
Security researchers have identified the underlying malware embedded in these fake applications as “Spyrtacus,” a surveillance tool discovered within the spyware’s code.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
by 2019 switched to hosting the apps on malicious web pages made to look like some of Italy’s top internet providers.
Spyrtacus can steal text messages, as well as chats from Facebook Messenger, Signal, and WhatsApp; exfiltrate contacts information
Spyrtacus could steal texts, chats, calls, and contacts, as well as record ambient audio and imagery directly from a device’s microphones and cameras.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyware embedded in a malicious unofficial WhatsApp iPhone application used to deceive users into installing it and compromise their devices.
A surveillance spyware embedded in fraudulent WhatsApp clones for iPhone and Android. Once installed, it can steal text messages, extract chat histories, copy call logs, and covertly record audio and video using the device microphone and camera.
Spyware family used in malicious Android apps masquerading as WhatsApp and other popular apps to steal private data from victims' devices.
A spyware family consisting of malicious Android apps masquerading as popular applications such as WhatsApp. It can extract sensitive data including messages, contact lists, and call logs, and can monitor victims through microphones and cameras.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.