Android

Over 150 Flaws in 58 Stalkerware Apps Let Attackers Steal Control and Carry out Malicious Activities

Spouseware. Nope! Not the term used when your spouse troubles you!

It is a mobile monitoring software, also known as mobile stalkerware. This is installed by the stalker onto a victim’s phone without their knowledge. A stalker usually requires to have physical access to the victim’s device.

Due to this, the stalker is usually a very close friend or family member. These apps have the ability to track GPS location, conversations, images, and browser history of a victim. Due to the volume of data amassed by these apps and transmitted to the stalker, a study was conducted to analyse how these apps protect the data they track.

Stalkerware apps are usually flagged once identified. To stay hidden and lay low, these are usually disguised as an app claiming to protect women and children, however, these apps do not shy away from using the word “shy” on their websites.

Fig 1. Example of a stalkerware app disguised as an app offering protection

A group of researchers analyzed 86 stalkerware apps for Android, provided by 86 different vendors. The analysis identified several serious security and privacy issues.

The security issues ranged from an attacker taking control of the victim’s device, taking over the stalker’s account, intercepting the victim’s data, framing the victim by uploading fabricated and duplicated evidence.

These issues were reported to the vendors. However, very few vendors had taken the effort to fix these issues. Several vendors did not respond to these analyses.

Below is the list of issues identified.

Also Read

‘FluBot’ Malware Delivery Via SMS Texts Targets Android Devices

New Advanced Android Malware Poses as “System Update” to Steal Messages, Images and Taking Control of Android Phones

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago