• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Android

Incompetent Android spyware can’t even manage to keep its own stolen data safe

February 25, 2022
Share on FacebookShare on Twitter

Software that covertly pulls info off your phone is a danger none of us want to face, and the fact that there are companies out there selling these tools to anyone who may want to spy on us is outright chilling. If that threat weren’t bad enough already, it turns out that a number of these “stalkerware” apps are themselves woefully insecure, and end up leaving your data potentially exposed to even more prying eyes.

The apps we’re looking at today all share much of the same code base, and were uncovered through the work of TechCrunch’s investigating into suspicious software. They go by names like Copy9, MxSpy, TheTruthSpy, iSpyoo, SecondClone, TheSpyApp, ExactSpy, FoneTracker, and GuestSpy and appear to have affected some 400,000 phones in countries around the globe.

ANDROIDPOLICE VIDEO OF THE DAY

Their intended operation is pretty standard cyber-stalker fare, giving an attacker access to a dashboard that displays real-time data coming from your phone as a feed — and the software is grabbing everything: messaging, GPS data, photos, all of it. Research also shows all these apps communicate back to the same server setup.

That part is a telling find: Since the people behind these spy apps seem to be copying the same setup, they’re also copying any flaws in that implementation — and it turns out there’s a pretty severe one here. The exploit is triggered by way of an insecure direct object reference (IDOR) and it has the potential to expose server-side information.

The IDOR flaw reveals information stolen from the phones of innocent victims — and according to TechCrunch, some intriguing data about the people behind the operation. That trail leads to 1Byte, a mysterious company with ties to London and Ho Chi Minh City in Vietnam, and Affiligate, a company handling the money coming from the spyware operators. Some of these sketchy apps were deactivated after TechCrunch’s attempts to contact 1Byte, but the trail is otherwise cold — for now.

TechCrunch has a helpful tutorial on removing spyware apps from Android devices, if you fear you’ve been affected. Of course, an ounce of prevention is worth a pound of cure, so make sure you keep on top of your security updates, don’t click sketchy links, and think twice about whom you’re letting use your devices.



Galaxy S22, S22+, and S22 Ultra
The Galaxy S22 series is already looking like a hit for Samsung

Early numbers look promising

Read Next


About The Author

Steve Huff
(23 Articles Published)

Steve is the Weekend News Editor for Android Police. He was previously the Deputy Digital Editor for Maxim magazine and has written for Inside Hook, Observer, and New York Mag. He’s the author of two official tie-ins books for AMC’s hit “Breaking Bad” prequel, “Better Call Saul.”

More
From Steve Huff

Next Post

Carvana bets on $2.2B ADESA U.S. acquisition to expand its reach, cut shipping times

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • NYT Connections Sports Edition hints and answers for April 4: Tips to solve Connections #558
  • I’m in love with this underrated streaming platform that costs absolutely nothing
  • How Ryan Goslings Project Hail Mary made a rock spider lovable
  • NinjaOne free trial. Test the unified IT operations platform
  • An ‘Animorphs’ series is on its way to Disney+ thanks to Ryan Coogler

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously