{"id":152895,"date":"2025-02-27T20:05:32","date_gmt":"2025-02-27T20:05:32","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/02\/27\/spyzie-stalkerware-is-spying-on-thousands-of-android-and-iphone-users-techcrunch\/"},"modified":"2025-02-27T20:05:32","modified_gmt":"2025-02-27T20:05:32","slug":"spyzie-stalkerware-is-spying-on-thousands-of-android-and-iphone-users-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/02\/27\/spyzie-stalkerware-is-spying-on-thousands-of-android-and-iphone-users-techcrunch\/","title":{"rendered":"Spyzie stalkerware is spying on thousands of Android and iPhone users | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">A little-known phone surveillance operation called Spyzie has compromised more than half a million Android devices and thousands of iPhones and iPads, according to data shared by a security researcher.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Most of the affected device owners, who are unknown, are likely unaware that their phone data has been compromised.<\/p>\n<p class=\"wp-block-paragraph\">The security researcher told TechCrunch that <a href=\"https:\/\/techcrunch.com\/2025\/02\/20\/stalkerware-apps-cocospy-spyic-exposing-phone-data-of-millions-of-people\/\" target=\"_blank\" rel=\"noreferrer noopener\">Spyzie is vulnerable to the same bug as Cocospy and Spyic<\/a>, two near-identical but differently branded <a href=\"https:\/\/techcrunch.com\/2024\/12\/23\/techcrunch-reference-guide-to-security-terminology\/#stalkerware\" target=\"_blank\" rel=\"noreferrer noopener\">stalkerware<\/a> apps that share the same source code and exposed the data of more than 2 million people, as we reported last week. The bug allows anyone to access the phone data, including messages, photos, and location data, exfiltrated from any device compromised by the three apps.<\/p>\n<p class=\"wp-block-paragraph\">The bug also exposes the email addresses of each customer who signed up to Spyzie to compromise someone else\u2019s device, the researcher said.<\/p>\n<p class=\"wp-block-paragraph\">The researcher exploited the bug to collect 518,643 unique email addresses of Spyzie customers and provided the cache of email addresses to TechCrunch and to Troy Hunt, who operates the <a href=\"https:\/\/haveibeenpwned.com\/PwnedWebsites#Spyzie\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Have I Been Pwned<\/a> data breach notification site.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">This latest leak shows how increasingly prevalent consumer phone surveillance apps have become among civil society, even from little-known operations like Spyzie, which barely have any online presence and are largely <a href=\"https:\/\/techcrunch.com\/2021\/10\/11\/google-pulls-stalkerware-ads-that-promoted-phone-spying-apps\/\" target=\"_blank\" rel=\"noreferrer noopener\">banned by Google from running ads in search results<\/a>, and yet have amassed thousands of paying customers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Collectively, Cocospy, Spyic, and Spyzie are used by more than 3 million customers.<\/p>\n<p class=\"wp-block-paragraph\">The leak also shows that flaws in stalkerware apps are increasingly common and put both the customer and victims\u2019 data at risk. Even in the case of parents who want to use these apps to monitor their children, which is legal, they are putting their kids\u2019 data at risk of hackers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">By our count, Spyzie is now <a href=\"https:\/\/techcrunch.com\/2025\/02\/20\/hacked-leaked-exposed-why-you-should-stop-using-stalkerware-apps\/\" target=\"_blank\" rel=\"noreferrer noopener\">the 24th stalkerware operation<\/a> since 2017 to have been hacked or otherwise leaked or exposed its victims\u2019 highly sensitive data because of shoddy security.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Spyzie\u2019s operators have not returned TechCrunch\u2019s request for comment. At the time of writing, the bug has yet to be fixed.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-planted-android-apps-and-stolen-apple-credentials\"><strong>Planted Android apps and stolen Apple credentials<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Apps like Spyzie, or Cocospy and Spyic, are designed to stay hidden from home screens, making the apps difficult to identify by their victims. All the while, the apps continually upload the contents of the victim\u2019s device to the spyware\u2019s servers and are accessible to the person who planted the app.<\/p>\n<p class=\"wp-block-paragraph\">A copy of the data shared by the security researcher with TechCrunch shows that the vast majority of affected Spyzie victims are Android device owners, whose phones have to be physically accessed to plant the Spyzie app, usually by someone with knowledge of the person\u2019s device passcode.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">This is one of the reasons why these apps are typically used in the context of abusive relationships, where people often know their romantic partner\u2019s phone passcode.<\/p>\n<p class=\"wp-block-paragraph\">The data also shows Spyzie has been used to compromise at least 4,900 iPhones and iPads.<\/p>\n<p class=\"wp-block-paragraph\">Apple has stricter rules about which apps can run on iPhones and iPads, so stalkerware usually taps into a victim\u2019s device data stored in Apple\u2019s cloud storage service iCloud by using the victim\u2019s Apple account credentials, rather than on the device itself.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Some of the earliest compromised Apple device owners date back to early to  late February 2020 and as recently as July 2024, the leaked Spyzie records show.\u00a0<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-to-remove-nbsp-spyzie-stalkerware\"><strong>How to remove\u00a0Spyzie stalkerware<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">As with Cocospy and Spyic, it was not possible to identify individual victims of Spyzie\u2019s surveillance from the scraped data.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">But there are things you can do to see if your phone was compromised by Spyzie.<\/p>\n<p class=\"wp-block-paragraph\"><strong>For Android users: <\/strong>Even if Spyzie is hidden from view, you can usually dial \u2731\u2731<strong>001<\/strong>\u2731\u2731 into your Android phone app\u2019s keypad and then hit the call button. If Spyzie is installed, it should appear on your screen.<\/p>\n<p class=\"wp-block-paragraph\">This is a backdoor feature built into the app that allows the person who planted the app on the victim\u2019s phone to regain access. In this case, it can also be used by the victim to see if the app is installed.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch has a <a href=\"https:\/\/techcrunch.com\/2022\/02\/22\/remove-android-spyware\/\" target=\"_blank\" rel=\"noreferrer noopener\">general Android spyware removal guide<\/a> that can help you identify and remove common types of phone stalkerware and switch on the settings to secure your Android device.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">You should also have <a href=\"https:\/\/stopstalkerware.org\/resources\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a safety plan in place<\/a>, as switching off spyware can alert the person who planted it.<\/p>\n<p class=\"wp-block-paragraph\"><strong>For iPhone and iPad users:<\/strong> Spyzie relies on using the victim\u2019s Apple Account username and password to access the data stored in their iCloud account. You should ensure your Apple Account uses <a href=\"https:\/\/support.apple.com\/en-us\/102660\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">two-factor authentication<\/a>, which is a vital protection against account hacks and a primary way for stalkerware to target your data. You should also check and <a href=\"https:\/\/support.apple.com\/en-us\/102560\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">remove any devices from your Apple Account that you don\u2019t recognize<\/a>.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p class=\"wp-block-paragraph\"><em>If you or someone you know needs help, the National Domestic Violence Hotline (1-800-799-7233) provides 24\/7 free, confidential support to victims of domestic abuse and violence. If you are in an emergency situation, call 911. The <\/em><a href=\"https:\/\/stopstalkerware.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em>Coalition Against Stalkerware<\/em><\/a><em> has resources if you think your phone has been compromised by spyware.<\/em><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/02\/27\/spyzie-stalkerware-spying-on-thousands-of-android-and-iphone-users\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A little-known phone surveillance operation called Spyzie has compromised more than half a million Android devices and thousands of iPhones and iPads, according to data shared by a security researcher.\u00a0 Most of the affected device owners, who are unknown, are likely unaware that their phone data has been compromised. The security researcher told TechCrunch that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":152896,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-152895","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/152895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=152895"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/152895\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/152896"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=152895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=152895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=152895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}