Skip to main content

CISA issues alert on spyware targeting users of mobile messaging applications

3 companies named across 1 category, one of 5 articles referencing WhatsApp. Previous coverage: MCP and LLM network troubleshooting, Redis and SEALSQ updates - Week of September 8, 2025 (Sep 2025).

Companies mentioned

Best suited for

Persona
Security Operations Leader
Buyer journey
Open to Buy
Adoption curve
Early Majority
Industry
Information Technology / Software & Services / IT Services / Internet Services & Infrastructure

Our classification, not the publisher's statement. Best suited for, not only for.

CISA has identified ongoing activity by cyber threat actors exploiting commercial spyware to infiltrate users of various mobile messaging applications, resulting in unauthorized access and further mobile device compromise.

The threat actors employ several techniques including phishing, malicious QR codes linking target devices to attacker-controlled endpoints, zero-click exploits requiring no interaction from users, and platform impersonation involving messaging applications such as Signal and WhatsApp. These methods facilitate the deployment of surveillance tools without user consent or knowledge.

This cyber activity predominantly affects high-value individuals including current and former government, military, and political officials, as well as civil society organizations and individuals located in regions including the United States, the Middle East, and Europe.

Available countermeasures include updated security guidance addressing mobile communications and mitigating spyware risks. CISA recommends reviewing these resources to enhance protection of messaging applications against such threats.

Users are advised to consult the updated Mobile Communications Best Practice Guidance and Mitigating Cyber Threats with Limited Resources: Guidance for Civil Society to inform protective measures for mobile messaging platforms and to counter spyware deployment.

Blog post, originally published by CISA at cisa.gov.