Back Benzatine Another spyware maker caught distributing fake Android snooping apps
A recent investigation has revealed that a prominent surveillance software manufacturer has been implicated in the distribution of deceptive Android applications designed to deploy its spyware on unsuspecting users. The Italian digital rights group Osservatorio Nessuno published a report on Thursday detailing the malware, dubbed Morpheus, which disguises itself as a phone update application. Morpheus is capable of extracting a wide array of information from the targeted devices. The report indicates a growing demand for such surveillance tools among law enforcement and intelligence agencies, leading to numerous companies providing these technologies, often away from public scrutiny. The research team identified the spyware as being linked to IPS, a company with over 30 years of experience in lawful interception technology—tools that enable governments to capture real-time communications over telecommunication networks. IPS claims to operate in more than 20 countries, although this does not necessarily pertain to its spyware offerings, which had remained largely undisclosed until now. Among its clientele are several Italian law enforcement agencies. IPS did not respond to inquiries from TechCrunch regarding the findings. Researchers categorized Morpheus as “low cost” spyware, relying on a basic infection method that tricks users into installing the malware themselves. In contrast, more sophisticated spyware developers like NSO Group utilize advanced techniques, such as zero-click attacks, to infect devices without user interaction by exploiting hidden vulnerabilities. In this instance, the researchers noted that the target’s cellular provider played a role in the spyware deployment. The provider intentionally restricted the target's mobile data access, subsequently sending a text message that urged the target to download an application meant to restore connectivity. Once installed, the spyware exploited Android's built-in accessibility features, enabling it to read data displayed on the victim’s screen and interact with other applications. The malware was programmed to extract various types of information from the device. It also initiated a counterfeit update process, displayed a reboot screen, and impersonated WhatsApp, misleading the target into providing their biometric information, which inadvertently granted the spyware full access to their WhatsApp account. This tactic aligns with methods previously observed in government hacking operations in Ukraine and recent espionage activities in Italy. The researchers, who requested anonymity, suggested that the spyware's infrastructure strongly indicates its origin from IPS. They identified a specific IP address tied to “IPS Intelligence Public Security” and noted the presence of Italian phrases within the malware code, a peculiar trend among Italian spyware developers. The malware's code even referenced cultural elements, including the book and TV series Gomorra, along with terms like “spaghetti.” The researchers speculated that the attack was likely politically motivated, reflecting a troubling trend of targeted attacks on political activists in Italy. An expert from a cybersecurity firm confirmed ongoing monitoring of this specific malware and corroborated the findings from Osservatorio Nessuno. IPS adds to the growing list of Italian spyware developers filling the gap left by the now-defunct Hacking Team—once a major player in the spyware market before its downfall. Over recent years, multiple Italian spyware firms, such as CY4GATE and SIO, have come under scrutiny, with WhatsApp even alerting around 200 users recently a counterfeit version of their app that contained SIO’s spyware. Notably, Italian authorities suspended the use of CY4GATE and SIO spyware in 2021 due to significant operational issues.
Published On : Apr 24, 2026, 14:45
Moderna has received approval in Europe for its groundbreaking mRNA-based vaccine that targets both COVID-19 and influen ...
For nearly ten years, Palantir Technologies has played a crucial role in assisting the IRS’s Criminal Investigations uni ...
Weiyao Wang, who dedicated eight years of his career to Meta, has recently made a significant career shift to Thinking M ...
In a bold and unconventional move, a tech banker is offering his stunning $4.8 million California estate in Marin County ...
In a bold move, Google is set to invest as much as $40 billion in Anthropic, a rising player in the artificial intellige ...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
