Back Mezha Researchers expose Morpheus spyware used in fake Android update attacks
A new report reveals how a low-cost Italian spyware called Morpheus tricked victims into installing fake updates, then seized control through Android accessibility features.
As mentioned by Techcrunch
Another spyware maker has come under scrutiny after its clients used fake Android apps to install surveillance tools on target devices, according to a new report.
On Thursday Osservatorio Nessuno, an Italian organization that studies spyware, published material Morpheus – a new sample of malware. It disguises itself as a phone update program and can steal a wide range of data from the target’s device.
Research indicates that demand from law enforcement and intelligence agencies for spyware and related technologies is extremely high, generating a sizeable pool of companies that provide it, sometimes out of the public eye.
According to Osservatorio Nessuno, Morpheus was allegedly developed by IPS – an Italian company with more than three decades of experience in the field of so-called lawful interception technologies.
IPS, according to its website, operates in more than 20 countries, although this likely refers to its traditional solutions rather than the spyware product, which had previously remained secret. The list of clients includes several Italian police forces.
IPS did not respond to requests for this report.
Researchers described Morpheus as an ‘inexpensive’ spyware because it uses a primitive infection mechanism – tricking the target into installing the spyware themselves.
More advanced state-snooping vendors, such as NSO Group and Paragon Solutions, allow their government clients to infect targets using covert techniques, including zero-click attacks, which install malware completely invisibly by exploiting expensive and complex vulnerabilities.
In this case, according to researchers, authorities received help from the target’s mobile operator, which began blocking mobile data. The provider then sent the target an SMS asking to install an app that supposedly would help update the phone and restore network access. Such approaches are not new and have been seen in other cases involving other Italian spyware vendors.
After installing the spyware, the attackers abused Android’s built-in accessibility features that allow the spyware to read data on the victim’s screen and interact with other apps.
– Osservatorio Nessuno
Researchers also noted that the operation is likely linked to political activity in Italy, where similar targets and attack methods are becoming more widespread.
After Morpheus was installed, the spyware exploited Android accessibility features and gained near-full control over the device, enabling reading data from the screen and interacting with other apps.
Subsequently, a fake update was proposed, a reboot screen was displayed, and the user’s biometric data were requested to verify identity. Without informing the target, the biometric authentication granted the spyware full access to the WhatsApp account by adding the device to the account.
Such tactics have been observed in other cases in Italy and elsewhere: for example, in 2023 WhatsApp warned 200 users regarding a fake version of an app linked to SIO; in 2021 Italian prosecutors halted the use of CY4GATE and SIO due to serious glitches.
The spread of Morpheus underscores that the Italian spyware technology market, after the collapse of Hacking Team, is continuing to rebound, and IPS is subject to deeper scrutiny by research groups and regulators. Other companies in this space – CY4GATE, GR Sistemi, Movia, Negg, Raxir, RCS Lab, and SIO – are also mentioned in public investigations.
Finally, analysts note that governments still need lawful interception and surveillance tools, but the use of such technologies carries risks of abuse and privacy violations. Public demand for transparency and accountability of these tools is growing globally.
Going forward, regulators and rights advocates call for tighter control over the use of spyware and for clear rules of deployment to prevent abuse and increase transparency in the surveillance sphere.
In conclusion, the Morpheus story demonstrates the complexity of regulating the spyware sector and the need for ongoing monitoring by regulators and rights advocates to prevent the use of technologies for illegal surveillance and cyber espionage.
You might be interested in:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
