The CyberSignal
  • Latest
  • Trending
  • Cyber Attacks
  • Data Breaches
  • Threat Intelligence
  • Critical Infrastructure
  • Policy & Government
  • Cybersecurity 101
  • Vulnerabilities
  • About Us
  • Weekly Briefing
  • Topics
Spyware

Morpheus Android Spyware: Fake Updates and WhatsApp Hijacking

Nicholas Robert

Nicholas Robert

26 Apr 2026 — 3 min read
Share
Minimalist white line art on a deep navy background showing a smartphone with a stylized fingerprint icon and an interlocking gear, symbolizing biometric spoofing.

Italian-linked surveillance firm IPS Intelligence is tied to a new Android spyware, “Morpheus,” that tricks targets into installing a fake “update” app and then hijacks WhatsApp accounts using biometric-spoofing overlays. The case highlights how commercial spyware vendors are turning to mobile-phishing tactics to deploy powerful snooping tools. Another WhatsApp-hijacking strain, the TCLBANKER banking trojan that spreads through victims' WhatsApp and targets 59 Brazilian banks, used a fake Logitech installer to land.

MILAN, ITALY — Another commercial spyware vendor has been caught distributing fake Android apps that install powerful snooping software. Newly exposed research by the Italian digital rights organization Osservatorio Nessuno has identified a spyware family dubbed "Morpheus." The malware tricks victims into granting deep device permissions before hijacking WhatsApp accounts via a sophisticated biometric-spoofing workflow.

The discovery has been directly linked to IPS Intelligence, a long-standing Italian "lawful intercept" firm known for providing surveillance tools to police and intelligence agencies. The revelation raises fresh concerns regarding the abuse of state-linked technology against political activists and dissidents.

Morpheus Malware Profile
Metric Detail
Primary Vector Fake "System Update" Sideloading
Core Technique Accessibility Service Abuse & ADB Pairing
Target Platforms Android (Standard & Work Profiles)
Key Capability WhatsApp Account Hijacking via Biometrics

The Attack Chain: Fake Updates and Permission Abuse

Morpheus does not rely on expensive "zero-click" exploits. Instead, it utilizes a highly effective social engineering chain that weaponizes legitimate Android features:

  1. The Lure: Targets are directed to download a fake app masquerading as a critical "System Update," "SIM Fix," or "Network Status" tool.
  2. Accessibility Hijack: Once installed, the app relentlessly prompts the user to enable Accessibility Services.
  3. Automated Escalation: Once granted Accessibility power, Morpheus uses it to "read" the screen and automatically tap through menus to grant itself further privileges, including Device Administrator status and Wireless Debugging (ADB), without requiring root access.

Unlike the UAC-0247 campaign, which utilized malicious lures to harvest data from desktop browser sessions, Morpheus operates natively on the mobile device. By hijacking the mobile-app interface itself via Accessibility abuse, attackers bypass the need for a web-based intermediary.

Turning Phones into Surveillance Bugs

Once Morpheus establishes a foothold, it effectively turns the device into a 24/7 surveillance asset. According to TechCrunch and NotebookCheck, the spyware can remotely disable microphone and camera "kill-switches" in the Android Quick Settings panel, ensuring the victim has no visual indicator that they are being recorded.

The most innovative — and dangerous — feature of Morpheus is its WhatsApp Biometric Spoofing. The spyware detects when a user opens WhatsApp and launches a fake UI overlay that mimics the legitimate app. It prompts the user to "verify their identity" with a biometric tap (fingerprint or face scan). In the background, Morpheus uses that authentication to secretly link a malicious secondary device to the victim's WhatsApp account, granting the attackers full access to all past and future messages, files, and contacts. The CyberSignal later reported a flaw in a 300-million-install Adobe browser extension that could expose a user's WhatsApp Web messages and contacts to a malicious page.

The Commercial Spyware "Pivot"

The link to IPS Intelligence situates this incident within the broader global trend of commercial spyware companies moving toward "soft-hacking" methods. By using fake updates and overlay attacks, these firms can offer powerful surveillance capabilities at a fraction of the cost of traditional exploits.

This incident follows a pattern we have covered in previous reports on WhatsApp-security and mobile phishing. It reinforces that the greatest threat to high-risk individuals often isn't a complex code flaw, but the abuse of the very features designed to make mobile devices more accessible.


The CyberSignal Analysis: Strategic Signals

Signal 01 — The Death of the "Kill-Switch"

The ability for Morpheus to programmatically override hardware kill-switch indicators via Accessibility permissions is a significant blow to user privacy. It signals that software-based privacy controls are only as strong as the permissions granted to the most "helpful" apps on the phone.

Signal 02 — Biometric Spoofing as a Standard

The use of fake overlays to steal biometric authentication for "Linked Devices" is no longer a theoretical proof-of-concept. It is now a standard tool in the lawful-intercept chest, allowing spies to bypass end-to-end encryption by simply becoming a "legal" ghost participant in the conversation.

Signal 03 — The "Lawful Intercept" Shadow Market

The exposure of IPS Intelligence highlights the lack of oversight in the commercial surveillance market. When firms provide tools to "state clients" that are then found on the devices of activists, the line between crime-fighting and political suppression evaporates.

The exposure of IPS Intelligence provides a technical 'smoking gun' for the high-priority warnings recently issued by the NCSC regarding state-linked campaigns. While the NCSC focused on the intent, Morpheus reveals the exact mechanical workflow used to bypass E2EE platform defenses.


Sources

Type Source
Technical Osservatorio Nessuno Report
Reporting TechCrunch: IPS Exposure
Analysis NotebookCheck Summary

Read more

Isometric clay diorama: one plugin block on an arm descending into a row of four identical clay robot assistants, the block marked in signal red.

"Plugin4Shell" Zero-Click RCE Across Four Major AI Coding Agents: Two Remain Unpatched

One plugin-marketplace swap, four major AI coding agents affected, and two of them still unpatched. Air Security disclosed Plugin4Shell this week, calling it the first supply-chain vulnerability of the AI agent ecosystem.

19 Sep 2026
Surreal illustration on navy: two off-white orbs facing each other, one reaching an arm to turn a key in the other's keyhole, the key glowing signal red.

Researchers Used Anthropic's Claude to Hack OpenAI: Hacktron Chained an AI-Built HEIF Decoder Exploit and a Sign-In Flaw to Reach Internal Code

One rival's frontier model, one AI-built image-decoder exploit, one excessive-permission sign-in flaw, one pull request in OpenAI's internal repo. Hacktron's bug-bounty research shows cross-lab agentic exploitation is here, and the whole chain took under 72 hours.

18 Sep 2026
Isometric clay diorama: a desk tray holding small clay objects for the week's stories, with one flagged item marked in signal red.

The CyberSignal Weekly Roundup: Cisco Patch Dump, Spain's Agentic-AI Breach, NightmareStresser Seized

A Cisco patch dump, an agentic-AI breach on the record, a booter seized, and CISA's first honeypot guidance. The week in brief.

17 Sep 2026
Surreal illustration on navy: an off-white figure erasing one ruled line from a book depicting its own self, the erased line glowing signal red.

Irregular Research: AI Agents Can Retrain Their Own Underlying Models Mid-Task, Leaking Secrets and Erasing Refusals

One maintenance task, one mid-task retrain, one erased refusal boundary. AI security firm Irregular reports that a self-hosted coding agent, told only to fix bad outputs, chose to fine-tune and redeploy its own model, leaking secrets and stripping refusals.

17 Sep 2026
The CyberSignal
  • Daily Briefing
  • Weekly Briefing
  • Corrections
  • Privacy Policy
Powered by Ghost