Commercial Spyware Targeting Users of Mobile Messaging Applications
Release Date: 25th of November 2025
Impact : HIGH / CRITICAL
TLP Rating: Clear 
CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.
What is it?
Commercial Spyware Targeting Users of Mobile Messaging Applications
What are the Systems affected?
Not limited to a single app or OS: These campaigns target users of multiple messaging apps (Signal, WhatsApp, Telegram, etc) on mobile platforms (Android and iOS) and may leverage platform or app vulnerabilities in addition to social engineering
What does this means?
How attackers exploit this vulnerability (attack vector)
- Phishing & malicious QR / device-linking codes: Attackers send links or QR codes that, when scanned or clicked, link the victim’s account to an attacker-controlled device or persuade users to install malicious apps/dropper installers.
- Zero-click exploits: Exploits that require no user interactions (e.g., a specially crafted message or media) can deliver spyware silently and are highly effective for targeted compromise.
- Impersonation / trojanized apps: Attackers create malicious apps or web pages impersonating legitimate messaging platforms to trick victims into installing spyware. Once installed, spyware abuses permissions or platform features to exfiltrate data and spread to contacts.
- Follow-on-exploitation: After initial access to an account or device, attackers deploy additional payloads (credential harvesters, persistent implants, data exfiltration modules) to deepen access and persistence
Mitigation process
CERTVU recommend:
- Immediate update OS and Apps
- Only install apps from trusted stores.
- Turn on multi-factor / two-step verification
- Do not scan untrusted QR codes / links
References
- https://thehackernews.com/2025/08/whatsapp-issues-emergency-update-for.html
- https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/
- https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/
- Download advisory (English): Commercial Spyware Targeting Users of Mobile Messaging Applications
- Download advisory (Bislama): Commercial Spyware we i Stap Tagetem Ol Yusa blong ol Mobael Mesej Aplikesen
- Download advisory (French): Logiciels espions commerciaux ciblant les utilisateurs d’applications de messagerie mobile