{"id":189052,"date":"2025-08-25T17:27:26","date_gmt":"2025-08-25T17:27:26","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/08\/25\/a-new-security-flaw-in-thetruthspy-phone-spyware-is-putting-victims-at-risk-techcrunch\/"},"modified":"2025-08-25T17:27:26","modified_gmt":"2025-08-25T17:27:26","slug":"a-new-security-flaw-in-thetruthspy-phone-spyware-is-putting-victims-at-risk-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/08\/25\/a-new-security-flaw-in-thetruthspy-phone-spyware-is-putting-victims-at-risk-techcrunch\/","title":{"rendered":"A new security flaw in TheTruthSpy phone spyware is putting victims at risk | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">A stalkerware maker with a history of multiple data leaks\u00a0and breaches now has a critical security vulnerability that allows anyone to take over any user account and steal their victim\u2019s sensitive personal data, TechCrunch has confirmed.<\/p>\n<p class=\"wp-block-paragraph\">Independent security researcher Swarang Wade found the vulnerability, which allows anyone to reset the password of any user of the stalkerware app <a href=\"https:\/\/techcrunch.com\/tag\/thetruthspy\/\" target=\"_blank\" rel=\"noopener\">TheTruthSpy<\/a> and its many companion Android spyware apps, leading to the hijacking of any account on the platform. Given the nature of TheTruthSpy, it\u2019s likely that many of its customers are operating it without the consent of their targets, who are unaware that their phone data is being siphoned off to somebody else.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">This basic flaw shows, once again, that makers of consumer spyware such as TheTruthSpy \u2014 and its many competitors \u2014 cannot be trusted with anyone\u2019s data. These surveillance apps not only facilitate illegal spying, often by abusive romantic partners, but they also have shoddy security practices that expose the personal data of both victims and perpetrators.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">To date, TechCrunch has counted <a href=\"https:\/\/techcrunch.com\/2025\/02\/20\/hacked-leaked-exposed-why-you-should-stop-using-stalkerware-apps\/\" target=\"_blank\" rel=\"noopener\">at least 26 spyware operations that\u2019ve leaked, exposed, or otherwise spilled data<\/a> in recent years. By our count, this is at least the fourth security lapse involving TheTruthSpy.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch verified the vulnerability by providing the researcher with the username of several test accounts. The researcher quickly changed the passwords on the accounts. Wade attempted to contact the owner of TheTruthSpy to alert him of the flaw, but he did not receive any response.<\/p>\n<p class=\"wp-block-paragraph\">When contacted by TechCrunch, the spyware operation\u2019s director Van (Vardy) Thieu said the source code was \u201clost\u201d and he cannot fix the bug.<\/p>\n<p class=\"wp-block-paragraph\">As of publication, the vulnerability still exists and presents a significant risk to the thousands of people whose phones are believed to be unknowingly compromised by TheTruthSpy\u2019s spyware.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Given the risk to the general public, we\u2019re not describing the vulnerability in more detail so as to not aid malicious actors.\u00a0<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-a-brief-history-of-thetruthspy-s-many-security-flaws\">A brief history of TheTruthSpy\u2019s many security flaws<\/h2>\n<p class=\"wp-block-paragraph\">TheTruthSpy is a prolific spyware operation with roots that go back almost a decade. For a time, the spyware network was one of the largest known phone surveillance operations on the web.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">TheTruthSpy is developed by 1Byte Software, <a href=\"https:\/\/techcrunch.com\/2022\/02\/22\/stalkerware-network-spilling-data\/\" target=\"_blank\" rel=\"noopener\">a Vietnam-based spyware maker<\/a> run by Thieu, its director. TheTruthSpy is one of a fleet of near-identical Android spyware apps with different branding, including <a rel=\"nofollow noopener\" href=\"https:\/\/www.vice.com\/en\/article\/xnore-copy9-stalkerware-data-breach-thousands-victims\/\" target=\"_blank\">Copy9<\/a>, and since-defunct brands iSpyoo, MxSpy, and others. The spyware apps share the same back-end dashboards that TheTruthSpy\u2019s customers use to access their victim\u2019s stolen phone data.<\/p>\n<p class=\"wp-block-paragraph\">As such, the security bugs in TheTruthSpy also affect customers and victims of any branded or whitelabeled spyware app that relies on TheTruthSpy\u2019s underlying code.<\/p>\n<p class=\"wp-block-paragraph\">As part of an investigation into the stalkerware industry in 2021, <a href=\"https:\/\/techcrunch.com\/2022\/02\/22\/stalkerware-network-spilling-data\/\" target=\"_blank\" rel=\"noopener\">TechCrunch found that TheTruthSpy had a security bug<\/a> that was exposing the private data of its 400,000 victims to anyone on the internet. The exposed data included the victims\u2019 most personal information, including their private messages, photos, call logs, and their historical location data.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch later received a cache of files from TheTruthSpy\u2019s servers, exposing the inner workings of the spyware operation. The files also contained a list of every Android device compromised by TheTruthSpy or one of its companion apps. While the list of devices did not contain enough information to personally identify each victim, it allowed <a href=\"https:\/\/techcrunch.com\/pages\/thetruthspy-investigation\/\" target=\"_blank\" rel=\"noopener\">TechCrunch to build a spyware lookup tool for any potential victim to check<\/a> whether their phone was found in the list.<\/p>\n<p class=\"wp-block-paragraph\">Our subsequent reporting, based on hundreds of leaked documents from 1Byte\u2019s servers sent to TechCrunch, revealed that <a href=\"https:\/\/techcrunch.com\/2023\/07\/20\/thetruthspy-stalkerware-forged-passports-millions\/\" target=\"_blank\" rel=\"noopener\">TheTruthSpy relied on a massive money-laundering operation<\/a> that used forged documents and false identities to skirt restrictions put in place by credit card processors on spyware operations. The scheme allowed TheTruthSpy to funnel millions of dollars of illicit customer payments into bank accounts around the world controlled by its operators.<\/p>\n<p class=\"wp-block-paragraph\">In late 2023, TheTruthSpy had another data breach, exposing the <a href=\"https:\/\/techcrunch.com\/2024\/02\/12\/new-thetruthspy-stalkerware-victims-is-your-android-device-compromised\/\" target=\"_blank\" rel=\"noopener\">private data on another 50,000 new victims<\/a>. TechCrunch was sent a copy of this data, and we added the updated records to our lookup tool.\u00a0<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-thetruthspy-still-exposing-data-rebrands-to-phoneparental\">TheTruthSpy, still exposing data, rebrands to PhoneParental<\/h2>\n<p class=\"wp-block-paragraph\">As it stands, some of TheTruthSpy\u2019s operations wound down, and other parts rebranded to escape reputational scrutiny. TheTruthSpy still exists today, and it has kept much of its buggy source code and vulnerable back-end dashboards while rebranding as a new spyware app called PhoneParental.<\/p>\n<p class=\"wp-block-paragraph\">Thieu continues to be involved in the development of phone-monitoring software, as well as the ongoing facilitation of surveillance.<\/p>\n<p class=\"wp-block-paragraph\">According to a recent analysis of TheTruthSpy\u2019s current web-facing infrastructure using public internet records, the operation continues to rely on a software stack developed by Thieu called the JFramework (previously known <a href=\"https:\/\/techcrunch.com\/2022\/02\/22\/stalkerware-network-spilling-data\/\" target=\"_blank\" rel=\"noopener\">as the Jexpa Framework<\/a>), which TheTruthSpy and its other spyware apps rely on to share data back to its servers.<\/p>\n<p class=\"wp-block-paragraph\">In an email, Thieu said he was rebuilding the apps from scratch, including a new phone-monitoring app called MyPhones.app. A network analysis test performed by TechCrunch shows MyPhones.app relies on the JFramework for its back-end operations, the same system used by TheTruthSpy.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch has an explainer on <a href=\"https:\/\/techcrunch.com\/2022\/02\/22\/remove-android-spyware\/\" target=\"_blank\" rel=\"noopener\">how to identify and remove stalkerware<\/a> from your phone.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">TheTruthSpy, much like other stalkerware operators, remains a threat to the victims whose phones are compromised by its apps, not just because of the highly sensitive data that they steal, but because these operations continually prove that they cannot keep their victim\u2019s data safe.<\/p>\n<p class=\"has-text-align-center wp-block-paragraph\">\u2014<\/p>\n<p class=\"wp-block-paragraph\"><em>If you or someone you know needs help, the National Domestic Violence Hotline (1-800-799-7233) provides 24\/7 free, confidential support to victims of domestic abuse and violence. If you are in an emergency situation, call 911. The<\/em><a href=\"https:\/\/stopstalkerware.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em> Coalition Against Stalkerware<\/em><\/a><em> has resources if you think your phone has been compromised by spyware.<\/em><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/08\/25\/a-new-security-flaw-in-thetruthspy-phone-spyware-is-putting-victims-at-risk\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A stalkerware maker with a history of multiple data leaks\u00a0and breaches now has a critical security vulnerability that allows anyone to take over any user account and steal their victim\u2019s sensitive personal data, TechCrunch has confirmed. Independent security researcher Swarang Wade found the vulnerability, which allows anyone to reset the password of any user of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":189053,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-189052","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/189052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=189052"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/189052\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/189053"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=189052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=189052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=189052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}