Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Researchers point to increase in AI phishing and holiday scams, FBI reports $262 million in ATO fraud

Why “hold forever” investors catch venture capital “zombies”

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA warns of high-value signals and active spyware activity hijacking WhatsApp users
Identity

CISA warns of high-value signals and active spyware activity hijacking WhatsApp users

userBy userNovember 25, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 25, 2025Ravi LakshmananSpyware/Mobile Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday issued a warning about criminals actively using commercial spyware and remote access Trojans (RATs) to target users of mobile messaging applications.

“These cyberattackers leverage sophisticated targeting and social engineering techniques to deliver spyware, gain unauthorized access to victims’ messaging apps, and facilitate the deployment of additional malicious payloads that may further compromise victims’ mobile devices,” the agency said.

DFIR retainer service

CISA cited several campaigns uncovered since the beginning of the year as examples. Some of them are –

Multiple Russian-aligned attackers target the Signal messaging app by leveraging the Signal messaging app’s service’s “linked devices” feature to hijack target user accounts. ClayRat, an Android spyware campaign codenamed ProSpy and ToSpy, impersonates apps like Signal and ToTok and targets users in the United Arab Emirates to deliver malware that establishes persistent access to compromised Android devices and steals data. An Android spyware campaign called “targeted users in Russia using Telegram channels and lookalikes “phished pages by impersonating popular apps like WhatsApp, Google Photos, TikTok, and YouTube, tricked users into installing them, and stole sensitive data” chained together two security flaws in iOS and WhatsApp (CVE-2025-43300 and CVE-2025-55177), targeting less than 200 users. Targeted attack campaign targeting WhatsApp users Targeted attack campaign exploiting Samsung security flaw (CVE-2025-21042) Delivering Android spyware called LANDFALL to Galaxy devices in the Middle East

The agency said attackers used multiple tactics to commit the breach, including device link QR codes, zero-click exploits, and distributing spoofed versions of messaging apps.

CISA also noted that these operations primarily focus on high-value individuals, including current and former government, military, and political officials, as well as civil society organizations and individuals across the United States, the Middle East, and Europe.

CIS build kit

To combat this threat, the agency urges targeted individuals to review and adhere to the following best practices:

Use only end-to-end encrypted (E2EE) communications Enable Fast Identity Online (FIDO) phishing-resistant authentication Move away from Short Message Service (SMS)-based multi-factor authentication (MFA) Use a password manager to store all your passwords Set a PIN for your carrier to protect your mobile phone account Update your software regularly Choose the latest hardware version from your phone manufacturer to maximize your security benefits Personal Virtual Private Network (VPN) On iPhones, enable Lockdown Mode and iCloud Private Relay, review and restrict sensitive app permissions; on Android smartphones, choose smartphones from manufacturers with a strong security track record, use Rich Communication Services (RCS) only when E2EE is enabled, turn on Safe Browsing Enhanced Protection on Chrome, ensure Google Play Protect is turned on, and audit and restrict app permissions.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGoogle teams up with Accel to explore India’s next AI breakout
Next Article Advances in solar power technology: Insights from EU PVSEC
user
  • Website

Related Posts

Researchers point to increase in AI phishing and holiday scams, FBI reports $262 million in ATO fraud

November 26, 2025

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

November 25, 2025

Years of JSONFormatter and CodeBeautify leaks expose thousands of passwords and API keys

November 25, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Researchers point to increase in AI phishing and holiday scams, FBI reports $262 million in ATO fraud

Why “hold forever” investors catch venture capital “zombies”

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

OpenAI and Perplexity are launching AI shopping assistants, but competing startups aren’t keen on it

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.