Policy & Regulation
Italian firm IPS linked to new Morpheus spyware
Italian digital rights group Osservatorio Nessuno linked a new, low-cost Android spyware called Morpheus to the Italian surveillance firm IPS.
On Thursday, the Italian digital rights organization Osservatorio Nessuno published a report detailing a new malware called Morpheus. The researchers linked this spyware—which functions as fake Android snooping apps masquerading as phone updates—to the Italian company IPS. Unlike surveillance software, Morpheus relies on relatively simple infection mechanisms, tricking targets into manually installing the application on their own devices. In this campaign, the target’s mobile data was deliberately blocked, prompting an SMS that instructed them to install the fake update to regain access.
IPS has been operating for more than 30 years providing what it calls lawful interception technology—tools used by governments to capture real-time communications flowing through phone and internet networks. According to the IPS website, the company likely operates in more than 20 countries, though this footprint likely does not refer to its previously secret spyware product. Morpheus represents a low-cost alternative to the zero-click attacks—invisible techniques used to install malware without user interaction—deployed by government spyware makers like NSO Group and Paragon Solutions.
The researchers, Davide and Giulio, believe the attack is related to political activism in Italy. Davide and Giulio, who are Osservatorio Nessuno researchers, noted that “this type of targeted attacks are very common nowadays.” To compromise targets, the spyware exploits Android’s built-in accessibility features to read screen data and interact with other applications. It then prompts a fake update and spoofs the WhatsApp platform, tricking users into providing biometric data. This biometric tap grants the spyware full access to the target’s WhatsApp account, a technique previously used by government hackers in Ukraine and in a recent campaign in Italy.
IPS is the latest in a long list of Italian surveillance tech developers that have filled the market void left by Hacking Team, a defunct Italian spyware maker. This domestic industry includes firms such as CY4GATE, eSurv, GR Sistemi, Movia, Negg, Raxir, RCS Lab, and SIO. The sector has faced operational setbacks; in 2021, Italian prosecutors suspended their use of spyware from CY4GATE and SIO due to serious malfunctions. More recently, WhatsApp notified around 200 users who had installed a fake version of its app containing spyware developed by SIO.
Why it matters
The emergence of Morpheus highlights the ongoing proliferation of low-cost surveillance tools in Italy, continuing a trend of private firms filling the void left by the defunct Hacking Team.