The Cybersecurity and Infrastructure Security Agency (CISA) recently announced it is aware of multiple cyber threat actors actively leveraging commercial spyware to target users of mobile messaging apps.
Criminals use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim’s messaging app. Once they have access, they deploy additional malicious payloads that can further compromise the victim’s mobile device.
Tactics include impersonating messaging app platforms, such as Signal and WhatsApp; zero-click exploits, that require no direct action from the device user; and phishing and malicious device-linking QR codes to compromise victim accounts and link them to actor-controlled devices.
Anyone can become a victim, but the focus appears to be on high-value individuals such as civil society organizations and current and former high-ranking government, military, and political officials. Victims have been in the United States, Europe and the Middle East.
CISA urges messaging app users to review the updated Mobile Communications Best Practice Guidance and Mitigating Cyber Threats with Limited Resources: Guidance for Civil Society for steps on how to protect mobile communications and messaging apps. The guide also includes mitigations against spyware.
CISA works with partners at every level to identify and manage risk to the cyber and physical infrastructure.