ESET reported that the StrongPity espionage group targeted Android users by distributing trojanized versions of legitimate messaging applications, including Signal and a modified Telegram build, through attacker-controlled websites that mimicked official download pages. The campaign relied on users sideloading the apps outside official stores, allowing the spyware to masquerade as functional software while gaining access to sensitive mobile data.
Once installed, the Android malware could collect a wide range of information from infected devices, including SMS messages, call logs, contact lists, and stored files, and it could also record phone calls and ambient audio. The operation extended StrongPity’s long-running espionage activity from Windows into mobile platforms, underscoring the group’s focus on covert surveillance of individuals through fake app distribution and broad device-level data theft.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
ESET disclosed a StrongPity espionage campaign targeting Android users, documenting the activity in a WeLiveSecurity report. The reference indicates the campaign was publicly revealed on the report's publication date.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.