Italian spyware used to hack into iPhones and Android phones — are you at risk?

Image of a security icon on a phone
(Image credit: Tero Vesalainen / Shutterstock)

Thousands of phones — running Android and iOS are at risk of getting hacked into by spyware developed by an Italian firm. 

As part of their effort to make Android phones more secure — Google’s Threat Analysis Group (TAG) publishes reports on vulnerabilities that are spotted around the world. TAG has now reported that Milan based RCS Labs had come up with tools to spy on private messages, passwords and contacts of users. These tools are now being used to spy on the phones of people based in Italy and Kazakhstan.

How would you know if this was attacking your phone? Well, TAG reports that the spyware uses a combination of clever tactics to enter a user's phone. This includes trying to get users to download a malicious app on either Android or iOS or sometimes disables the users data via their carrier before sending a malicious link via text to get them to ‘fix’ the issue. 

Strangely enough, RCS Labs’ website claims that they have European law enforcement agencies as clients. Google said that the big problem is that they are “enabling the proliferation of dangerous hacking tools and arming governments that would not be able to develop these capabilities in-house.” European and American regulators have been deciding new rules against the sale and purchase of spyware. 

Spyware like that of RCS Labs can be dangerous especially when it falls into the wrong hands. This is also not the first time a spyware firm has been found hacking into phones. Israeli firm NSO’s Pegasus spyware was found to be spying on journalists and activists by many different governments around the world. RCS’ spyware doesn’t seem as dangerous or widespread as Pegasus though.

In an email to Reuters, RCS Labs mentioned that they condemned any abuse of its products and insisted that they are used to help law enforcement agencies investigate crimes.

An Apple spokesperson said that the company had revoked all accounts and certificates associated with this hacking campaign. Apple has patched each of the iOS exploits used, so you should be safe if you have at least iOS 15.2.

Google has ramped up its defenses and mentioned that they have informed the affected users in both Italy and Kazakhstan. 

There might be little reason to worry though. The attack does not seem widespread and there is no indication users beyond those countries have been affected. 

The hack is a good reminder to keep installing security patches on your Android or iPhone. Spyware is something everyone should be aware of to avoid falling victim to. You can also download the best Android antivirus apps to keep spyware at bay. 

TOPICS
Sanjana Prakash
News Editor

Sanjana loves all things tech. From the latest phones, to quirky gadgets and the best deals, she's in sync with it all. Based in Atlanta, she is the news editor at Tom's Guide. Previously, she produced India's top technology show for NDTV and has been a tech news reporter on TV. Outside work, you can find her on a tennis court or sipping her favorite latte in instagrammable coffee shops in the city. Her work has appeared on NDTV Gadgets 360 and CNBC.

Read more
Google Play logo on an android smartphone with corner hole punch camera
At least 5 North Korean spy apps have been found on Google Play — what you need to know
Green skull on smartphone screen.
Hackers are spreading info-stealing malware and taking over accounts using fake wedding invitations — how to stay safe
Find My iPhone
Apple Find My hack turns any Bluetooth device into a secret AirTag — what we know
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
DeepSeek logo on smartphone in front of merging US and Chinese flags
DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Emma D'Arcy in House of the Dragon season 2
‘House of the Dragon’ season 3 has officially begun filming — what it could mean for the potential release window
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Claude AI on phone sitting on keyboard
Claude 3.7 Sonnet now supports real-time web searching — but there's a catch