Asin Android Spyware Targets Arabic-Speaking Users Across MENA
ESET has identified a new Android spyware, Asin, targeting Arabic-speaking users via fake government news, PDF reader, and war-map applications distributed since early 2025.

Android smartphone showing a security alert in Arabic, representing the Asin spyware campaign targeting MENA users
A newly identified Android spyware campaign is targeting Arabic-speaking users across the Middle East, impersonating government news portals, PDF editing tools, and military conflict mapping services to deliver malicious applications capable of silently harvesting device data. Researchers at ESET have designated the malware Asin and report it has been active since at least early 2025. The campaign deploys three distinct lure sites, each registered separately to avoid pattern detection: govlens[.]net (a fake government news portal registered May 2025), pdf-reader[.]help (a fictitious secure PDF editor), and live-war-map[.]com (claiming to offer live military incident updates, registered January 2025). Two of the three sites operated dedicated Facebook and Telegram promotion accounts, with the Telegram channel name designed to closely mirror Liveuamap, a legitimate and widely used open-source conflict tracking platform. This deliberate naming overlap is intended to attract users already familiar with real-world OSINT resources.
Each fraudulent application bundles genuine functionality alongside concealed spyware capability. Critically, this campaign relies heavily on social engineering to bypass modern Android security controls that require active user consent for deep-system access. Users must manually install the application and manually grant it the permissions it requests, with those requests framed as legitimate operational requirements such as enabling map layers or improving PDF rendering. The social engineering layer is as consequential as the malware itself.
ESET confirmed multiple artefacts, including a sample uploaded to VirusTotal from Turkiye in October 2025, an APK retrieved from "c-pdf[.]net" in December 2025 on a Xiaomi Redmi Note 13 Pro running Android 15, and a third sample labelled "Syria Defense Map" identified on similar hardware in January 2026 and distributed from syriadefensemap[.]com. The threat actor behind Asin remains unattributed, classified by ESET as a cluster of activity rather than a named nation-state group. This places it in the persistent, mid-tier threat category: less visible than headline APT operations but consistent in targeting and execution. Based on the lures selected, ESET suspects the primary targets are Arabic-speaking journalists and open-source intelligence (OSINT) practitioners, a group that routinely consumes government and conflict-related digital resources.
The Asin campaign is a prime example of the low-and-slow persistent threat model currently dominating the MENA region, where attackers prioritise high-value targets such as journalists and OSINT researchers over mass-market infection, using highly localised and context-aware lures. It is also documented as part of ESET's Q4 2025 to Q1 2026 APT Activity Report, a period that additionally recorded the compromise of a defence company in the United Arab Emirates through a SmartOffice CRM server. Taken together, these findings confirm that the GCC threat landscape during this period extended across both mobile and enterprise attack surfaces simultaneously.
What this means for MENA enterprise security teams
The targeting of OSINT practitioners and journalists carries clear enterprise risk implications. Personnel in government, legal, financial services, and energy sectors who consume geopolitical intelligence as part of their professional responsibilities are potential targets. The social engineering approach, which exploits trust in recognisable platforms such as Liveuamap, lowers the user's guard considerably. IT and security administrators across the GCC should review mobile device management (MDM) policies to ensure enforcement of corporate app store restrictions, block sideloading on managed devices, and conduct awareness sessions specifically addressing fake-site lookalike distribution. User awareness programmes are as important as MDM configuration: no technical control compensates for a user who has been socially engineered into granting permissions voluntarily.
The pattern of targeting Arabic-speaking audiences with mobile-first threats is consistent with broader threat actor behaviour documented in the region throughout 2025 and 2026. Organisations operating in rapidly digitising markets should treat mobile threat intelligence as a first-class security function rather than a secondary concern. The Asin campaign serves as a stark reminder that in the current GCC threat landscape, governance frameworks and technical defences are inseparable. As organisations mature their AI and digital governance, mobile threat intelligence must evolve from a secondary concern into a foundational pillar of enterprise resilience.
CISO Action Checklist
MDM Policy Review: Enforce strict sideloading blocks on all corporate-managed Android devices and verify that app installation is restricted to approved store sources only.
Threat Hunting: Scour DNS and proxy logs for the identified Asin lure domains, specifically govlens[.]net, pdf-reader[.]help, live-war-map[.]com, c-pdf[.]net, and syriadefensemap[.]com, and flag any historical resolution attempts across managed endpoints.
User Awareness: Run a targeted awareness campaign for high-value personnel in communications, legal, research, and intelligence functions, focused specifically on conflict-themed and government-impersonation mobile lures and the social engineering tactics used to obtain permissions.
CRM Hardening: Audit access controls on internally deployed CRM platforms, ensure all instances are on current patch levels, and restrict access to verified sessions protected by multi-factor authentication.
Each fraudulent application bundles genuine functionality alongside concealed spyware capability. Critically, this campaign relies heavily on social engineering to bypass modern Android security controls that require active user consent for deep-system access. Users must manually install the application and manually grant it the permissions it requests, with those requests framed as legitimate operational requirements such as enabling map layers or improving PDF rendering. The social engineering layer is as consequential as the malware itself.
ESET confirmed multiple artefacts, including a sample uploaded to VirusTotal from Turkiye in October 2025, an APK retrieved from "c-pdf[.]net" in December 2025 on a Xiaomi Redmi Note 13 Pro running Android 15, and a third sample labelled "Syria Defense Map" identified on similar hardware in January 2026 and distributed from syriadefensemap[.]com. The threat actor behind Asin remains unattributed, classified by ESET as a cluster of activity rather than a named nation-state group. This places it in the persistent, mid-tier threat category: less visible than headline APT operations but consistent in targeting and execution. Based on the lures selected, ESET suspects the primary targets are Arabic-speaking journalists and open-source intelligence (OSINT) practitioners, a group that routinely consumes government and conflict-related digital resources.
The Asin campaign is a prime example of the low-and-slow persistent threat model currently dominating the MENA region, where attackers prioritise high-value targets such as journalists and OSINT researchers over mass-market infection, using highly localised and context-aware lures. It is also documented as part of ESET's Q4 2025 to Q1 2026 APT Activity Report, a period that additionally recorded the compromise of a defence company in the United Arab Emirates through a SmartOffice CRM server. Taken together, these findings confirm that the GCC threat landscape during this period extended across both mobile and enterprise attack surfaces simultaneously.
What this means for MENA enterprise security teams
The targeting of OSINT practitioners and journalists carries clear enterprise risk implications. Personnel in government, legal, financial services, and energy sectors who consume geopolitical intelligence as part of their professional responsibilities are potential targets. The social engineering approach, which exploits trust in recognisable platforms such as Liveuamap, lowers the user's guard considerably. IT and security administrators across the GCC should review mobile device management (MDM) policies to ensure enforcement of corporate app store restrictions, block sideloading on managed devices, and conduct awareness sessions specifically addressing fake-site lookalike distribution. User awareness programmes are as important as MDM configuration: no technical control compensates for a user who has been socially engineered into granting permissions voluntarily.
The pattern of targeting Arabic-speaking audiences with mobile-first threats is consistent with broader threat actor behaviour documented in the region throughout 2025 and 2026. Organisations operating in rapidly digitising markets should treat mobile threat intelligence as a first-class security function rather than a secondary concern.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.