On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

November 10th, 2009

Commercial spying app for Android devices released

Posted by Dancho Danchev @ 2:07 pm

Categories: Anti Virus, Browsers, Hackers, Malware, Mobile (In)Security, Passwords, Privacy, Spyware and Adware

Tags: Mobile, Malware, Mobile Malware, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms, Security, Dancho Danchev

A well known commercial provider of spyware applications for numerous mobile platforms, has recently ported its Mobile Spy app to the Android mobile OS.

Just like previous releases of the application, the Android version keeps a detailed log of GPS locations, calls, visited URLs, and incoming/outgoing SMS messages, available at the disposal of the attacker who installed it manually by obtaining physical access to the targeted device.

More details:

“Mobile Spy runs in total stealth mode and no mentions of the program are shown inside the Android device. After the software is set up on the phone, it silently records GPS locations at a rate decided by the owner of the phone. The entire text of all SMS text messages, along with the associated phone number, is also recorded. Additionally, inbound and outbound call information with duration of the call is recorded. Immediately after activities are logged, they are silently uploaded to the user’s private online account.

Mobile Spy runs on all Android devices, including the new My Touch 3G by T-Mobile and Motorola Droid. The software also has a version for iPhone, BlackBerry and other smartphones running the Windows Mobile or Symbian OS operating systems. These devices are available from most major mobile carriers.”

Despite the company’s positioning as a vendor offering the ability to “silently record SMS text messages, GPS locations and call info of your child or employee“, two years ago, F-Secure and Airscanner revealed trivial security vulnerabilities within the most popular vendors of spyware applications( FlexiSpy and Retina-X Studios, LLC), allowing anyone easy access to someone else’s spying logs.

Others, on the other hand have already flagged the application as spyware within their mobile antivirus solutions.

Despite the clear commercial interest in releasing such applications, last month US-CERT warned on the public release of the first free BlackBerry spying application (PhoneSnoop) released by Sheran Gunasekera at this year’s HITBSecConf 2009.

It its current form, Mobile Spy acts and hides like a malware would, however, the day when the vendor starts playing a “cat and mouse” game with antivirus vendors by systematically obfuscating its releases — like cybercriminals do in order to evade detection — it would officially join the mobile malware market segment.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 6 Talkback(s)
It's amazing how people...
It's amazing how people differentiate Google from all others and accuse them of spying.

It's really not justified. I've been using Gmail since it came out in 2005. I have over 33,000 archived... (Read the rest)
Posted by: joe.smetona@... Posted on: 11/12/09  (Edited: 11/12/09 @ 09:21) You are currently: a Guest | | Terms of Use
Nothing new  Bozhidar | 11/10/09
It sounds like a "Mom & Dad" App.  Cayble | 11/10/09
So basically..  AzuMao | 11/11/09
RE: Commercial spying app for Android devices released  DalyDose | 11/11/09
Ironic!  jorjitop | 11/11/09
It's amazing how people...  joe.smetona@... | 11/12/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here