CISA Warns of Active Spyware Campaigns Hijacking Signal and WhatsApp Users
These articles are AI-generated summaries. Please check the original sources for full details.
CISA Warns of Active Spyware Campaigns Hijacking Signal and WhatsApp Users
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on November 25, 2025, detailing active campaigns leveraging commercial spyware and Remote Access Trojans (RATs) to compromise users of mobile messaging apps. These campaigns exploit vulnerabilities and social engineering tactics, impacting high-profile targets across multiple regions.
Why This Matters
Current threat models often assume user diligence, but sophisticated actors are circumventing these safeguards with zero-click exploits and convincing social engineering. The potential for compromise of high-ranking officials and sensitive data represents a significant national security risk, with potential costs reaching millions in remediation and damage control.
Key Insights
- CVE-2025-43300 & CVE-2025-55177: Exploited in targeted WhatsApp attacks, affecting fewer than 200 users.
- Linked Device Feature Abuse: Russia-aligned actors exploit Signal’s “linked devices” to hijack accounts.
- ProSpy & ToSpy: Android spyware campaigns impersonating legitimate apps to gain persistent access.
Working Example
(No code provided in the source text)
Practical Applications
- Use Case: Government officials using Signal for sensitive communications are prime targets for account hijacking via linked devices.
- Pitfall: Relying solely on SMS-based multi-factor authentication (MFA) leaves users vulnerable to SIM swapping attacks, a common initial access vector.
References:
Continue reading
Next article
Cognitive Load: The Invisible UX Killer
Related Content
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
A China-linked threat actor compromised 8.8 million users over seven years with malicious browser extensions designed for data theft and corporate espionage.
Operation SkyCloak: Tor-Powered OpenSSH Backdoor Targeting Defense Sectors
Researchers reveal a sophisticated cyber campaign, Operation SkyCloak, using Tor-enabled OpenSSH backdoors to target defense networks in Russia and Belarus via phishing attacks.
Sturnus Android Trojan Captures Encrypted Chats and Enables Device Hijacking
The Sturnus Android trojan bypasses encryption to steal chats from WhatsApp, Telegram, and Signal, impacting financial institutions in Southern and Central Europe.