New malicious software focused on mobile devices has raised alarms among digital security experts in recent weeks. The invading program acts silently and manages to take control of the device’s vital functions. The main tactic involves deceiving the phone owner with promises of network connection improvements.
Pesquisadores from the Italian organization Osservatorio Nessuno discovered the threat and named it Morpheus. The malicious code disguises itself as an operating system update or carrier configuration package. Once installed, the agent gains power to view the screen, record audio and link additional devices into messengers without the victim’s knowledge. The detailed report on the case revealed unusual methods of infection.
The social engineering behind the service outage
The attack begins in a way that deviates from the common pattern of randomly sent links. Telephony Operadoras participate in the first stage in some of the cases registered in Europa. Elas performs the cutting off of the specific target’s mobile internet access. Logo after the signal drops, the user receives a conventional text message.
The content of the message contains a link to a website that simulates the telecommunications operator’s official technical assistance. The user is left without a connection and tends to follow the guidance immediately. The fake page suggests installing an app to restore data service. The desperation for connectivity makes it easier for criminals to act.
The home app only works as a cargo carrier. Ele goes by the technical name of dropper and loads the primary installation package. The sole function of this first program is to prepare the ground for the main agent. Todo process exploits user trust in system maintenance tools. The transporter scans the environment, copies the necessary files, and requests initial permissions to perform automatic installation of the full malware.
Learn more: Apple warns iPhone users about mercenary spyware attacks and the importance of protection
Essa approach avoids the use of complex operating system security flaws. The method relies almost entirely on social engineering to work. Researchers classify the threat as low-cost spying software. The effectiveness lies in the psychological manipulation of the target at a time of technical vulnerability.
Controle system deep and privacy invasion
Depois installation is complete, the master agent enables the operating system’s accessibility services. Essa native tool was originally created to help people with motor or visual disabilities. The feature allows the system to read the screen content aloud and simulate touches. Morpheus claims to be a legitimate assistance tool for obtaining these critical permissions.
The rogue software also requests device administrator permission. Ele enables wireless debugging covertly. The program executes internal commands to silently grant all dangerous permissions without generating on-screen alerts. The code disables the camera and microphone indicator lights. The application prevents protection systems from working properly and adjusts battery settings to remain active in the background uninterruptedly.
More on this story: How to enable two-step verification on all your accounts
The agent’s monitoring capabilities go far beyond simply collecting basic data. The technical report confirmed a series of invasive actions that completely compromise user privacy. Key functions identified include:
- Captura real-time screen images during use.
- Gravação continuous audio and video via microphone and camera.
- Leitura of all messaging app notifications and content.
- Vinculação of an extra device in the messenger with biometrics fraud.
- Desativação complete system native privacy icons.
- Execução of advanced commands for elevation of privileges on the device.
- Persistência of the code even after the phone has been completely reset.
- Technical Suporte for multiple models from different manufacturers.
Durante the hacking process, the malware displays fake update and reboot screens. The user observes a simulated progress bar and believes that the device is undergoing routine maintenance. The app performs actions in the background while the fake screen blocks the interaction. The program opens the messenger and adds a device controlled by the attacker invisibly.
Rastreamento points to legal interception company
The network infrastructure used by Morpheus points to a specific corporate origin. The data directs to the Intelligence IPS. The Italian company has more than three decades of experience in the legal interception technology market. The company’s focus is on providing tools for police forces and government intelligence agencies. The organization operates in more than twenty countries and lists several European public security bodies as official clients.
On the same topic: Digital scams in 2026: learn how to protect yourself and avoid losses
The malware’s source code contains several expressions written in Italian. Analysts found cultural references typical of other similar software developments originating from the same country. Security researchers linked internet protocol addresses and structural components to domains associated with the surveillance company. The report also cites related companies that operate in the same telecommunications sector.
The digital espionage market is usually divided by the level of sophistication of the tools. The Morpheus requires direct action from the user to be installed on the device. Essa feature drastically reduces the tool development cost. The software maintains high effectiveness against specific targets in targeted surveillance contexts. The tactic differs from more expensive programs that infect the cell phone without any interaction from the victim.
Estratégias risk protection and mitigation
Especialistas in information security recommend extreme caution with links received via text messages. The main guideline is to never install applications that arrive through unofficial channels. Atualizações legitimate operating system and application applications must occur exclusively through official software stores. The device’s own settings menu is the only safe way to seek network improvements.
Users can check accessibility permissions and device administrators in advanced settings. Unknown Aplicativos that have wide screen access or permission to run unrestricted in the background deserve extra attention and immediate removal. Manter operating system always in the latest version helps limit privilege elevation techniques exploited by criminals.
More on this story: Digital scams in 2026: learn how to protect yourself and avoid losses
Internal malicious agent management uses sequential workflows to bypass defenses. The program overlays fake interfaces over any open application. The code adapts its actions according to the device manufacturer to ensure operation. The discovery reinforces global discussions about the use of surveillance tools by governments. The case also raises debates about the need for transparency from telephone operators when they interrupt services in a targeted manner.
