Skip to content
New Spyware Campaigns Target Apple and Google Users

New Spyware Campaigns Target Apple and Google Users

Azat.Tv • March 21, 2026

A wave of sophisticated phishing and spyware attacks is currently targeting mobile users across both the Apple and Google ecosystems, forcing a reassessment of how individuals handle digital security alerts in 2026. Security researchers have identified distinct campaigns that bypass traditional technical defenses by manipulating user trust, rather than relying solely on software vulnerabilities.

Cybersecurity reports indicate that millions of iPhone users face an elevated risk from a new class of spyware designed to infiltrate devices through deceptive links and unauthorized third-party applications. These attacks, which are described as highly sophisticated, attempt to exploit both known and undisclosed iOS vulnerabilities to bypass standard security measures. Once a device is compromised, the spyware gains the capability to monitor messages, track real-time location data, and record keystrokes, effectively capturing sensitive personal and financial information.

Parallel to the threats facing iOS, Android and desktop browser users are being targeted by a deceptive phishing campaign that mimics official Google account protection systems. Operating through malicious domains such as google-prism[.]com, the scam presents users with a fake security verification page. Upon following the prompts, users are tricked into installing a Progressive Web App that appears harmless but functions as a persistent spying tool. This malware can monitor clipboard activity, intercept one-time login codes, and even route internet traffic through the user’s own network, potentially masking the attacker’s movements.

Experts emphasize that because these attacks rely on social engineering, the most effective defense is a combination of skepticism and strict adherence to official protocols. Apple has urged users to maintain the latest iOS version to ensure patches for zero-day exploits are applied, while also strictly avoiding app sideloading. Similarly, security analysts recommend that users ignore any browser-based security alerts that originate from pop-ups or unfamiliar websites. Instead, users should navigate directly to official account settings by typing the URL manually. Implementing robust password managers and shifting from SMS-based two-factor authentication to dedicated authenticator apps remains the primary method for neutralizing the impact of these interception campaigns.

The shift toward social engineering as a primary attack vector represents a significant evolution in cybercrime, as attackers are increasingly capitalizing on the psychological reliance users place on trusted brand interfaces to secure their own devices, rendering traditional automated defenses only partially effective.

Extracted Entities