Hack-for-Hire Campaign Combines Phishing and Android Spyware in MENA

This campaign breaks the usual mobile spyware pattern by combining phishing for iCloud and Signal access with Android spyware deployment. Attackers gain persistent access to cloud backups and messaging accounts, not just the compromised device, making standard mobile incident response insufficient. The shared infrastructure and repeated targeting across multiple countries reveal a reusable hack-for-hire service rather than isolated intrusions. Researchers from Access Now, Lookout, and SMEX linked spearphishing cases from 2023 to 2025 targeting journalists and officials in the Middle East and North Africa. They identified overlapping domains, hosting, and code tied to the Bitter group, along with ProSpy Android spyware and account-access phishing. Victims include Egyptian and Lebanese journalists, with additional targets in Bahrain, UAE, Saudi Arabia, the UK, and possibly the US. The campaign uses fake personas and messages mimicking legitimate services like Signal to deliver spyware and steal credentials. The persistence of shared infrastructure and cross-border reuse indicates this is an ongoing espionage threat delivered by a hack-for-hire vendor with suspected Indian government ties. The risk extends beyond device compromise to cloud and messaging account infiltration, which can maintain attacker visibility even after device remediation. This elevates the threat for journalists, activists, and government personnel in MENA and their support networks.

Part of the PlainSec briefing for 2026-04-10

Sources