Morpheus: new Android spyware delivered as a fake update
Researchers have identified Morpheus, a new Android spyware linked to the Italian firm IPS Intelligence, known for developing lawful interception technology. The malware is delivered through a fake update application, often presented to the user after network connectivity has been deliberately disrupted so the prompt appears legitimate. Once installed, Morpheus can access sensitive data and take over accounts, including on messaging platforms such as WhatsApp. The infection chain requires no exploit, only a convincing prompt and the user's approval.
What this means for your organisation
Commercial spyware is normally sold to governments, but the market leaks and the target set keeps widening. The Norwegian organisations most exposed are those operating abroad, negotiating agreements of strategic value, or employing people with access to politically sensitive information. The mobile phone is often the device with the weakest governance and the strongest access: it reads mail, approves logins and holds conversations that never reach any archive.
Berigo recommends
- Disable installation of apps from sources other than the official store on company Android devices.
- Give staff travelling to higher-risk regions one simple rule: updates are never installed from a pop-up prompt, only from the settings menu.
- Consider dedicated, wiped travel phones for staff with access to sensitive negotiations or data.
- Include mobile phones in your risk assessment and incident response plan, not just laptops and servers.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch