A little-known phone monitoring app called Xnspy has stolen data from tens of thousands of iPhones and Android devices, the majority whose owners are unaware that their data has been compromised.
Xnspy is one of many so-called stalkerware apps sold under the guise of allowing a parent to monitor their childs activities, but are explicitly marketed for spying on a spouse or domestic partners devices without their permission. Its website boasts, to catch a cheating spouse, you need Xnspy on your side, and, Xnspy makes reporting and data extraction simple for you.
Stalkerware apps, also known as spouseware, are surreptitiously planted by someone with physical access to a persons phone, bypassing the on-device security protections, and are designed to stay hidden from home screens, which makes them difficult to detect. Once installed, these apps will silently and continually upload the contents of a persons phone, including their call records, text messages, photos, browsing history and precise location data, allowing the person who planted the app near-complete access to their victims data.
But new findings show many stalkerware apps are riddled with security flaws and are exposing the data stolen from victims phones. Xnspy is no different.
Security researchers Vangelis Stykas and Felipe Solferini spent months decompiling several known stalkerware apps and analyzing the edges of the networks that the apps send data to. Their research, presented at BSides London this month, identified common and easy to find security flaws in several stalkerware families, including Xnspy, such as credentials and private keys left behind in the code by the developers and broken or nonexistent encryption. In some cases the flaws are exposing the victims stolen data, now sitting on someone elses insecure servers.
During their research, Stykas and Solferini discovered clues and artifacts that identified the individuals behind each operation, but they declined to share details of the vulnerabilities with the stalkerware operators or publicly disclose details about the flaws for fear that doing so would benefit malicious hackers and further harm victims. Stykas and Solferini said that all of the flaws they found are easy to exploit and have likely existed for years.
Others have waded into murkier legal waters by exploiting those easy-to-find vulnerabilities with the apparent aim of exposing stalkerware operations as a form of vigilantism. A huge cache of internal data taken from the servers of TheTruthSpy stalkerware and its affiliate apps and given to TechCrunch earlier this year allowed us to notify thousands of victims whose devices were compromised.
Since our investigation into TheTruthSpy, TechCrunch has obtained further caches of stalkerware data, including from Xnspy, exposing their operations and the individuals who profit from the surveillance.
Xnspy advertises its phone monitoring app for spying on a persons spouse or domestic partner. Image Credits: TechCrunch (screenshot)
Data seen by TechCrunch shows Xnspy has at least 60,000 victims dating back to 2014, including thousands of newer compromises recorded as recently as 2022. The majority of victims are Android owners, but Xnspy also has data taken from thousands of iPhones.
Many stalkerware apps are built for Android since it is easier to plant a malicious app than on an iPhone, which have tighter restrictions on which apps can be installed and what data can be accessed. Instead of planting a malicious app, stalkerware for iPhones tap into a devices backup stored in Apples cloud storage service iCloud.
With a victims iCloud credentials, the stalkerware continually downloads the devices most recent iCloud backup directly from Apples servers without the owners knowledge. ICloud backups contain the majority of a persons device data, allowing the stalkerware to steal their messages, photos and other information. Enabling two-factor authentication makes it far more difficult for malicious individuals to compromise a persons online account.
The data we have seen contains more than 10,000 unique iCloud email addresses and passwords used for accessing a victims cloud-stored data, though many of the iCloud accounts are connected to more than one device. Of that number, the data contains more than 6,600 authentication tokens, which had been actively used to exfiltrate victims device data from Apples cloud, though many had expired. Given the possibility of ongoing risk to victims, TechCrunch provided the list of compromised iCloud credentials to Apple before publication.
The Xnspy data we obtained was unencrypted. It also included information that further unmasked Xnspys developers.
Konext is a small development startup in Lahore, Pakistan, manned by a dozen employees, according to its LinkedIn page. The startups website says the startup specializes in bespoke software for businesses that seek all-in-one solutions, and claims to have built dozens of mobile apps and games.
What Konext doesnt advertise is that it develops and maintains the Xnspy stalkerware.
The data seen by TechCrunch included a list of names, email addresses and scrambled passwords registered exclusively to Konext developers and employees for accessing internal Xnspy systems.
The cache also includes Xnspy credentials for a third-party payments provider that are tied to the email address of Konexts lead systems architect, according to his LinkedIn, and who is believed to be the principal developer behind the spyware operation. Other Konext developers used credit cards registered to their own home addresses in Lahore for testing the payment systems used for Xnspy and TrackMyFone, an Xnspy clone also developed by Konext.
Some of Konexts employees are located in Cyprus, the data shows.
Konext, like other stalkerware developers, makes a concerted effort to conceal its activities and keep the identities of its developers from public view, likely to shield from the legal and reputational risks that come with facilitating covert surveillance on a massive scale. But coding mistakes left behind by Konexts own developers further link its involvement in developing stalkerware.
TechCrunch found that Konexts website is hosted on the same dedicated server as the website for TrackMyFone, as well as Serfolet, a Cyprus-based entity with a conspicuously barebones website, which Xnspy says processes refunds on behalf of its customers. No other websites are hosted on the server.
TechCrunch contacted Konexts lead systems architect by email for comment, both to his Konext and Xnspy email addresses. Instead, a person named Sal, whose Konext email address was also in the data but declined to provide their full name, responded to our email. Sal did not dispute or deny the companys links to Xnspy in a series of emails with TechCrunch, but declined to comment. When asked about the number of compromised devices, Sal appeared to confirm his companys involvement, saying in one email that the figures you quoted dont match with what we have. When asked for clarity, Sal did not elaborate.
Xnspy is the latest in a long list of flawed stalkerware apps: mSpy, Mobistealth, Flexispy, Family Orbit, KidsGuard and TheTruthSpy have all exposed or compromised their victims data in recent years.
If you or someone you know needs help, the National Domestic Violence Hotline (1-800-799-7233) provides 24/7 free, confidential support to victims of domestic abuse and violence. If you are in an emergency situation, call 911. The Coalition Against Stalkerware also has resources if you think your phone has been compromised by spyware. You can contact this reporter on Signal and WhatsApp at +1 646-755-8849 or zack.whittaker@techcrunch.com by email.
Read more:
Read more:
Xnspy stalkerware spied on thousands of iPhones and Android devices - TechCrunch
- Introducing Canada, Montreal Local IP and Data Center with Dedicated Server Hosting by TheServerHost - EIN News - July 28th, 2024
- Introducing Hong Kong Local IP and Data Center with Dedicated Server Hosting by TheServerHost - EIN News - July 28th, 2024
- Introducing Singapore Local IP and Data Center with Dedicated Server Hosting by TheServerHost - EIN News - July 28th, 2024
- Introducing Texas, Dallas, Houston Local IP and Data Center with VPS and Dedicated Server Hosting by - EIN News - July 20th, 2024
- PQ.Hosting: Leading the Way in Web Hosting with Affordable VPS and Dedicated Servers Forbes Georgia - Forbes Georgia - May 27th, 2024
- ServerWhere Kicks Off Netherlands-based 10 Gbps Dedicated Servers and Cloud IaaS - Audacy - May 8th, 2024
- Palworld might be getting dedicated Xbox servers sooner than you think - Gamesradar - March 28th, 2024
- 10 Best Dedicated Server Hosting Options in India 2024 - The New Indian Express - March 20th, 2024
- 'Probably one of the worst launches of all time': Star Wars: Battlefront Classic Collection players tear into Aspyr for bugs ... - PC Gamer - March 20th, 2024
- Palworld Dedicated Servers and how to set them up - Gamesradar - February 11th, 2024
- What are the different types of web hosting? - TechRadar - February 11th, 2024
- Xbox Working Closely With Palworld Developers to Enable Faster Updates, Dedicated Servers, and More - IGN - February 3rd, 2024
- Palworld Is Missing One Key PvP Feature That Would Make It So Much Better - Screen Rant - February 3rd, 2024
- How to host and join a dedicated server in 'Palworld' - NME - January 25th, 2024
- Palworld on Xbox Doesnt Have Dedicated Servers, Limiting Co-Op to 2-4 Players While Steam Gets Up to 32 Players - IGN - January 25th, 2024
- How To Play With Friends In Enshrouded - TheGamer - January 25th, 2024
- Palworld on Game Pass Is Different From the Steam Version - The Escapist - January 25th, 2024
- Palworld Limits Multiplayer Numbers On Xbox, Here's Why - Kotaku - January 25th, 2024
- Palworld does not support dedicated servers on Xbox and will not be seeing them anytime soon - Windows Central - January 25th, 2024
- Palworld Multiplayer and how to play with friends explained - Eurogamer.net - January 25th, 2024
- What is Dedicated Hosting? Learn about the benefits and drawbacks of this powerful web hosting solution. | by Dale ... - Medium - December 10th, 2023
- Best web hosting 2023: Our experts review the top services - TechRadar - December 10th, 2023
- How to choose the best web hosting and its importance - Arizona Big Media - December 2nd, 2023
- Introducing the ToughPigs Discord Server! - ToughPigs - December 2nd, 2023
- How Smarthub's Investment Is Taking Ad Tech To New Heights - The Drum - December 2nd, 2023
- Restaurants for New Year's Eve Dinner That Will Dazzle Your Date - Orlando Date Night Guide - December 2nd, 2023
- Who Is @BasedBeffJezos, The Leader Of The Tech Elite's 'E/Acc ... - Forbes - December 2nd, 2023
- The best things to do this weekend in San Diego: Nov. 30 to Dec. 3 - The San Diego Union-Tribune - December 2nd, 2023
- 5 Ways to Protect Customer Information for Small Businesses - Small Business Trends - December 2nd, 2023
- Remote Access Adds API to Its Feature Arsenal and Marks a Turn for ... - GlobeNewswire - November 24th, 2023
- 9 Best Cheap Web Hosting India Updated Nov 2023 - Analytics Insight - November 24th, 2023
- The Need for Modernized, AI-Ready Server and Compute ... - Spiceworks News and Insights - November 24th, 2023
- Hyve and Remarkable partner to reduce cloud downtime on Black Friday - DataCentreNews UK - November 24th, 2023
- Boost Your Online Security and Privacy: The Advantages of Socks5 ... - Analytics Insight - November 24th, 2023
- What are you thankful for this holiday season? Here are 11 Ocala ... - Ocala - November 24th, 2023
- How to Choose the Right VPN: 10 Things to Consider in {YEAR} - CyberGhost VPN - November 24th, 2023
- Save Up to 81% with InMotion Hosting's Cyber Week Sale - Yahoo Finance - November 16th, 2023
- The best things to do this weekend in San Diego: Nov. 16-19 - The San Diego Union-Tribune - November 16th, 2023
- Three Truths and a Lie: Modernization and Migrating to the Cloud - Newsweek - November 16th, 2023
- Top 10 Business Intelligence Platforms, Features, and Pricing ... - Spiceworks News and Insights - November 16th, 2023
- What you need to know about the launch of Ark: Survival Ascended - Windows Central - November 16th, 2023
- What does the Wynn Casino $1 million package include for this years Las Vegas Grand Prix? - AS USA - November 16th, 2023
- ARK: Survival Ascended Impressions - The Good, The Bad And The Ugly - MMORPG.com - November 16th, 2023
- How to Watch BBC iPlayer Outside UK in 2023 - The Tech Report - November 16th, 2023
- NordVPN Vs. Atlas VPN: Which One Is Best In 2023? - Forbes - November 16th, 2023
- Raising the Bar on FIX Protocol Support - Traders Magazine - November 16th, 2023
- What Is A Remote Access VPN? Forbes Advisor INDIA - Forbes - November 16th, 2023
- Life is sweet at this local family business - BurlingtonToday.com - November 16th, 2023
- SI-BONE to Report Third Quarter 2023 Financial Results on ... - GlobeNewswire - October 17th, 2023
- There's a Film Festival Happening in Minecraft Right Now - Decrypt - October 17th, 2023
- The fight over the future of encryption, explained - MIT Technology Review - October 17th, 2023
- Kong Named in the Leaders Quadrant of the Gartner Magic ... - Yahoo Finance - October 17th, 2023
- Microsoft to create team dedicated to data center automation and ... - DatacenterDynamics - October 17th, 2023
- A brief guide to choose the right cloud solution for your law firm - Lexology - October 17th, 2023
- How to Fix BLZ51903006 Error in World of Warcraft - PC Invasion - May 12th, 2023
- Robot food service workers on the rise in metro - Detroit Free Press - May 12th, 2023
- MySQL Database Optimisation in Simple but Effective Way - Medium - May 12th, 2023
- Function-As-A-Service Market Will Accelerate Rapidly with Excellent CAGR of 26.35% in the forecast period of 2 - openPR - May 12th, 2023
- Rising Trends of Cloud Server Hosting Market will Witness ... - Digital Journal - May 12th, 2023
- SIGMA LITHIUM AND BRAZILIAN GOVERNMENT OFFICIALS RING ... - PR Newswire - May 12th, 2023
- An Introduction to the Bun JavaScript Runtime SitePoint - SitePoint - May 12th, 2023
- Introducing Cloudzupp: The One-Stop Destination for Cloud Services and Digital Marketing Solutions - openPR - May 4th, 2023
- Scared of Leaking Data to ChatGPT? Microsoft Tests a Private ... - The Information - May 4th, 2023
- Webyne: Revolutionizing Web Hosting Services in India With ... - Deccan Herald - May 4th, 2023
- THE DISH: Special events in works for Mother's Day - The Bakersfield Californian - May 4th, 2023
- Healthcare's Recent Cybercriminal Activity Attributed to ... - MedCity News - May 4th, 2023
- AMD says new Ryzen 7040 chips beat Intel (and Apple) in thin-and-light PCs - Ars Technica - May 4th, 2023
- Tips to use the Cockpit web consoles - TechTarget - May 4th, 2023
- Bluesky: the invite-only social network disrupting the digital landscape - CyberNews.com - May 4th, 2023
- Pet Shampoo Market was valued at USD 510.58 million in 2021 and is expected to reach USD 815.02 million by 202 - openPR - May 4th, 2023
- Spotify Not Working On iPhone? Here's How To Fix It - The Mac Observer - May 4th, 2023
- What Is a Guest Network And How to Set It Up - X-bit Labs - May 4th, 2023
- How to join a Mastodon server with the official Android app - ZDNet - April 26th, 2023
- Website Hosting: A Guide to Choosing the Perfect One - Digital Journal - April 26th, 2023
- I Voyaged to the North Pole Aboard the Worlds Only Luxury Ice-Breaking Cruise Ship. Heres What It Was Like. - Robb Report - April 26th, 2023
- Volunteer and dedicated community member will be missed as he heads back to Ireland - The Eganville Leader - April 26th, 2023
- Dining Out In 2023? Here Are 40 Dos And Don'ts To Follow - BuzzFeed - April 26th, 2023
- 5g Proxies: Exploring The Future Of Mobile Internet And How You Can Benefit Today - Startup.info - April 26th, 2023
- Inside the Discord Where Thousands of Rogue Producers Are ... - VICE - April 26th, 2023
- The Impact of Blockchain on the Hosting Industry - Finextra - April 26th, 2023