Connect with us

News

Another spyware maker caught distributing fake Android snooping apps

info

Published

on

Android spyware malloc.jpg

Yet another government spyware maker has been caught after its customers used fake Android apps to install its surveillance software on targets, according to a new report.

On Thursday, Osservatorio Nessuno, an Italian digital rights organization that researches spyware, published a report on a new malware it calls Morpheus. The spyware, which masquerades as a phone updating app, is capable of stealing a broad range of data from an intended target’s device. 

The researchers’ findings show that the demand for spyware by law enforcement and intelligence agencies is so high that there are a large number of companies providing this technology, some of whom operate outside of the public spotlight.

In this case, Osservatorio Nessuno concluded that the spyware is made by IPS, an Italian company that has been operating for more than 30 years providing traditional so-called lawful interception technology, meaning tools used by governments to capture a person’s real-time communications that flow through the networks of phone and internet providers. 

According to IPS’ website, the company operates in more than 20 countries, though that likely does not refer to its spyware product, which until today was a secret. The company lists several Italian police forces among its customers. 

IPS did not respond to TechCrunch’s request for comment about the report.  

The researchers called Morpheus “low cost” spyware because it relies on the rudimentary infection mechanism of tricking the targets into installing the spyware on their own. 

More advanced government spyware makers, such as NSO Group and Paragon Solutions, allow their government customers to infect their targets with invisible techniques, known as zero-click attacks, which install the malware in a completely stealthy and invisible way by exploiting expensive and difficult-to-find vulnerabilities that break through a device’s security defenses.

In this case, the researchers said the authorities had help from the target’s cellphone provider, which began deliberately blocking the target’s mobile data. At that point, the telecom provider sent the target an SMS, prompting them to install an app that was supposed to help them update the phone, and regain cellular data access. This is a strategy that has been well documented in other cases involving other Italian spyware makers.

Image Credits:Osservatorio Nessuno

Once the spyware was installed, it abused Android’s in-built accessibility features, which allows the spyware to read the data on the victim’s screen and interact with other apps. The malware was designed to access all kinds of information on the device, according to the researchers. 

The spyware then prompted a fake update, showed the target a reboot screen, and finally spoofed the WhatsApp app asking the target to provide their biometrics to prove that it’s them. Unbeknownst to the target, the biometric tap granted the spyware full access to their WhatsApp account by adding a device to the account. This is a known strategy used by government hackers in Ukraine, as well as in a recent spy campaign in Italy.

An old company with a new spyware

Osservatorio Nessuno’s researchers, who asked to be referred only with their first names, Davide and Giulio, concluded that the spyware belongs to IPS based on the spyware’s infrastructure. 

In particular, one of the IP addresses used in the campaign was registered to “IPS Intelligence Public Security.” 

The two also found several fragments of code that contained Italian phrases — something that has seemingly become tradition among the Italian spyware industry. The malware code included words in Italian, including references to Gomorra, the famous book and TV show about the Neapolitan mob, and “spaghetti.” 

Davide and Giulio told TechCrunch that they can’t provide specifics about who the target was, but they said they believe the attack is “related to political activism” in Italy, a world where “this type of targeted attacks are very common nowadays.” 

A researcher at a cybersecurity firm told TechCrunch that their company has been tracking this specific malware. After reviewing the Osservatorio Nessuno report, the researcher said that the malware is definitely developed by an Italian surveillance tech maker.

IPS is the latest in a long list of Italian spyware makers that have filled the void left by the long-defunct Italian company Hacking Team, one of the first spyware makers in the world. The company controlled a large share of the local market apart from selling abroad before it was hacked, and later sold and rebranded. In recent years, researchers have publicly exposed several Italian spyware makers, including CY4GATE, GR Sistemi, Movia, Negg, Raxir, RCS Lab, and most recently SIO

Earlier this month WhatsApp notified around 200 users who installed a fake version of the app, which was actually spyware made by SIO. In 2021, Italian prosecutors suspended their use of CY4GATE and SIO spyware due to serious malfunctions.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Ekiti 2026: Re-elect Oyebanji for second term – Tinubu tells residents

info

Published

on

By

Tinubu 2 1.jpg

President Bola Ahmed Tinubu has commended Governor Biodun Oyebanji’s performance in office, telling Ekiti voters that the governor came into leadership fully prepared to serve the people.

Speaking ahead of the June 20 governorship election, Tinubu urged residents to re-elect Oyebanji for a second term.

The endorsement came on Tuesday at the All Progressives Congress mega rally in Ado-Ekiti. The venue was packed with party faithful, allies from other political groups, and supporters across religious and ethnic lines, all showing solidarity with Oyebanji’s re-election bid.

Represented by Vice President Kashim Shettima, President Tinubu praised Ekiti citizens for their loyalty to the APC over the years.

He described the state as fortunate to have Oyebanji at the helm of affairs, noting that the governor’s actions and policies prove that true leadership is about serving people, not oppressing them or undermining their rights.

Tinubu highlighted Oyebanji’s humility, patience, and respect for traditional rulers and past leaders, pointing out the absence of opposition posters across the state as a sign of Oyebanji’s wide acceptance.

“On Saturday, go out and re-elect this humble and peaceful man to further serve you better,” Shettima said on Tinubu’s behalf. The President then symbolically handed Oyebanji over to former governors and first ladies, urging them to secure victory for him.

Chairman of the APC National Campaign Council and Kaduna State Governor, Uba Sani, described Oyebanji’s popularity as electrifying.

Chairman of the APC Governors Forum and Imo State Governor, Hope Uzodinma, said the party’s visibility in Ekiti was unmatched. He noted that only the APC had campaigned market to market and house to house.

APC National Chairman, Prof Nentawe Yilwadta, insisted the party’s confidence was rooted in Oyebanji’s connection to the people, not just in being the ruling party.

A visibly elated Governor Oyebanji, joined by his wife Dr Olayemi Oyebanji and Deputy Monisade Afuye, said he was not relying on federal might but on his record and the promises he kept since 2022.

He appealed for a peaceful election and promised that his second term would surpass the achievements of the last three and a half years.

Continue Reading

News

Nigerian Striker Toyosi Olusanya Completes Permanent Move to Aberdeen on Two-Year Deal

info

Published

on

By

IMG 20260616 WA0268.jpg

Scottish Premiership club Aberdeen have secured the permanent signing of London-born Nigerian striker Toyosi Olusanya, with the forward committing his future to the club on a two-year contract after an impressive loan spell.

READ ALSO: Isaac John Turns Heads at Ex-Internationals Cup in Lagos, Declares Himself Ready for the Big Stage 

Sports247 reports that the 28-year-old joins the Dons as a free agent following the expiration of his contract with Major League Soccer side Houston Dynamo. His arrival marks another key addition to manager Stephen Robinson’s rebuilding project ahead of the new season.

Olusanya spent the second half of the previous campaign on loan at Aberdeen, where he quickly adapted to life in Scottish football.

During his stint, he made 18 appearances across all competitions and contributed three goal involvements, earning the confidence of the coaching staff and convincing the club to pursue a permanent deal.

The striker’s work rate, physical presence, and attacking versatility made him a valuable option during his loan spell, and Aberdeen will be hoping he can build on that foundation as they prepare for the challenges of the upcoming Premiership campaign.

His signing represents the fifth addition to Robinson’s squad during the summer transfer window as the club continues to strengthen its roster with an eye on domestic success and improved performances across all competitions.

Born in London and eligible to represent Nigeria, Olusanya has enjoyed a career spanning English football and Major League Soccer before making the move north of the border.

The permanent transfer offers him the opportunity to continue his development in a familiar environment after settling into the team during his loan period.

For Aberdeen, retaining a player who already understands the club’s style and expectations provides continuity as they reshape the squad for the new season.

Supporters will be eager to see the Nigerian forward translate his promising displays into consistent goals and assists over the course of the campaign.

With his future now secured at Pittodrie, Olusanya begins the next chapter of his career aiming to establish himself as a key figure in Aberdeen’s attack and help the club compete strongly in the Scottish Premiership.

Continue Reading

Trending