Bug In A Spyware Tool Leaks Data Of Hundreds Of Thousands Of People

People use their phones for practically everything.

From browsing the web to using social media apps, to calling and messaging, to emails, taking photos and videos, working with documents, play games, commute and many many more. With an increasing number of people turning into so-called "digital zombies", through the increasing amount of usage, user data is enormous.

And this time, a bug in a popular consumer-grade spyware is leaking that many data to the public.

From call records to browsing history and even precise geolocations, the sensitive data of tens of thousands of people can be accessed via the web by anyone.

As reported by TechCrunch, the agency has tried contacting the developer of the app and also the company that provides hosting for the developer’s spyware infrastructure. But due to the scarce information regarding their whereabouts and contact details, inquiries were difficult.

"We can’t name the spyware or its developer since it would make it easier for bad actors to access the insecure data," said the report.

Stalkerware

TechCrunch discovered the security issue as part of its wider investigation into consumer-grade spyware.

The apps in question, are spyware apps, but marketed as child tracking or spouse monitoring apps. Operating in the so-called grey area of apps, these apps also go by another name: "stalkerware."

With smartphones becoming common and internet connectivity becoming increasingly reliable and wide, devices can connect to the internet 24/7 without issues.

And due to the connectivity, stalking has never been easier.

In fact, in the first few months of the 'COVID-19' coronavirus pandemic, the use of spyware and stalkerware has increased by more than 50%.

Through these stalkerware apps and services, people with malicious intentions can silently, and continually siphon the contents of a target's device, allowing its operators to track a person’s whereabouts and who they communicate with. Many will have no idea that their phones are compromised, since these apps are designed to disappear from home screens to avoid detection or deletion.

“I am disappointed but not even slightly surprised,” said Eva Galperin, the Director of Cybersecurity at the Electronic Frontier Foundation (EFF) who led the effort to launch the Coalition Against Stalkerware, in a call with TechCrunch.

“I think that we could reasonably characterize this kind of behavior as negligent. Not only do we have a company, which is making a product which enables abuse, but they’re doing such a poor job of securing the information that’s exfiltrated that they are opening the targets of this abuse to even further abuse.”

[block:block=87]

This kind of discovery is utterly disheartening, considering how much people use their phones.

And due to spyware apps are easy to obtained and relatively cheap, this should prompt an industry-wide effort to crack down on these apps.

Developers of antivirus services have worked to improve their ability to detect malware, including stalkerware, and Google has also banned developers of spyware from promoting their products.

They should continue to prevent these apps from thriving, and do more to prevent anymore of these apps from being marketed.

In the past, mobile spyware has been reported to be riddled with bugs.

A few years before this, reports said that about a dozen developers of stalkerware apps were hacked, and left victims' data exposed.

They include mSpy, Mobistealth, Flexispy and Family Orbit. Another stalkerware, KidsGuard, had a security lapse that exposed thousands of people’s phone data, and the more recent would be pcTattleTale, which promotes itself as able to spy on a spouse’s device. The app was leaking screenshots by way of easily guessable web addresses.