ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Commercial spying app for Android devices released

By | November 10, 2009, 2:07pm PST

Summary: A commercial provider of multi-platform spying applications has recently ported its main product to the Android mobile OS.

A well known commercial provider of spyware applications for numerous mobile platforms, has recently ported its Mobile Spy app to the Android mobile OS.

Just like previous releases of the application, the Android version keeps a detailed log of GPS locations, calls, visited URLs, and incoming/outgoing SMS messages, available at the disposal of the attacker who installed it manually by obtaining physical access to the targeted device.

More details:

“Mobile Spy runs in total stealth mode and no mentions of the program are shown inside the Android device. After the software is set up on the phone, it silently records GPS locations at a rate decided by the owner of the phone. The entire text of all SMS text messages, along with the associated phone number, is also recorded. Additionally, inbound and outbound call information with duration of the call is recorded. Immediately after activities are logged, they are silently uploaded to the user’s private online account.

Mobile Spy runs on all Android devices, including the new My Touch 3G by T-Mobile and Motorola Droid. The software also has a version for iPhone, BlackBerry and other smartphones running the Windows Mobile or Symbian OS operating systems. These devices are available from most major mobile carriers.”

Despite the company’s positioning as a vendor offering the ability to “silently record SMS text messages, GPS locations and call info of your child or employee“, two years ago, F-Secure and Airscanner revealed trivial security vulnerabilities within the most popular vendors of spyware applications( FlexiSpy and Retina-X Studios, LLC), allowing anyone easy access to someone else’s spying logs.

Others, on the other hand have already flagged the application as spyware within their mobile antivirus solutions.

Despite the clear commercial interest in releasing such applications, last month US-CERT warned on the public release of the first free BlackBerry spying application (PhoneSnoop) released by Sheran Gunasekera at this year’s HITBSecConf 2009.

It its current form, Mobile Spy acts and hides like a malware would, however, the day when the vendor starts playing a “cat and mouse” game with antivirus vendors by systematically obfuscating its releases — like cybercriminals do in order to evade detection — it would officially join the mobile malware market segment.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter
12
Comments

Join the conversation!

Just In

RE: Commercial spying app for Android devices released
omegaspy 13th Oct
Do you want to track someone, use the full functionality and save more money ????, So, you can go to http://www.omegaspy.com with us. You can use a lot of different functions developed by experienced programmers. But its price is very cheap only from 4.99$/ 10 days package. i hope it help you ^^
0 Votes
+ -
Nothing new
Bozhidar 10th Nov 2009
Regardless of what the 'official brand name' of spyware products, one should also consider what are the standards of development in the developers company, and following that logic, what else may have sneaked into the code of the spyware product.

Spirovski Bozidar
http://www.shortinfosec.net
0 Votes
+ -
It sounds like a "Mom & Dad" App.
Cayble 10th Nov 2009
About a year or little more ago I couldn't believe the number of relatively positive responses that Mom and Dad types gave for key logging spy ware made commercially available to concerned parents who want to track their kids online behavior.

Spyware that couldn't be easily discovered particularly if the user of the system had no reason to suspect it was installed. Sounds marvelous right Mom and Dad??

Short sightedness is amazing to say the least. My response was simply that if your little Johny is a computer guru tyke, then he may know how to download pirate software, and this key logging software would be available no doubt; little Johny put it secretively on Dads computer and hey away we go.

Saying any Spyware is good for any reason and should be made commercially available is just opening up the world to abuse. Your choice Mom and Dad, have Spyware available that you can track the kids with, and visa versa, they can put on your devices to spy on you, or simply no legal Spyware available. Your choice. Now choose.
0 Votes
+ -
So basically..
AzuMao 11th Nov 2009
..make a password, or don't leave your phone out in the
open unattended.
Why doesn't someone make a variation of this app for when
your phone is lost or stolen? I'd love to give the
police the GPS coordinates of someone who stole my stuff.
0 Votes
+ -
Ironic!
jorjitop 11th Nov 2009
A "spy app" on a spyware OS. Everything Google produces is spyware. Which spy is worse?
0 Votes
+ -
It's amazing how people...
Joe.Smetona Updated - 12th Nov 2009
It's amazing how people differentiate Google from all others and accuse them of spying.

It's really not justified. I've been using Gmail since it came out in 2005. I have over 33,000 archived emails, many have large attachments. What do I pay for this? Easy, I get relavent text ads generated from my emails. A google robot scans for selected key words and sets up about 3 or 4 targeted text ads on my desktop.

It's not hard to take at all.

They have never been offensive and they have never been of a personal nature. Google is smart enough to keep it simple and make a ton of money without any deceptive practices. This is very commendable.

I'm only using 30% of my capacity and Google will probably keep raising the bar (add more free space) when I need it. I would not want to give up this deal. And, yes, I do click on the ads to take advantage of their specials like discounts, and especially free shipping. It's just very convenient when you are doing online shopping. They are better than you are at finding deals.

I don't get spam in my inbox at all. I just don't have to deal with it.

If you tried keeping 33,000+ emails on your desktop with Outlook, the computer would be jumping up and down and eventually wind up smashed on the floor. Not to mention trying to backup those emails or restore them to a new computer if the hard drive fails.

Gmail has extremely good virus scanning and it will not allow sending or receiving .exe files. MS should be proud. Given Gmails' customer base, if they ever stopped these precautions, Windows would probably become unusable.

Also, Google and Gmail use Linux. Netcraft.com lists the top 100 web sites. Google has most of them.

Did you ever hear of Google or Gmail getting broken into or hacked?

Google's competition: Yahoo, Microsoft, etc. aren't as transparent with their intentions. They are just not specific with their actions. Google has done a great job. If you don't use Google, you are just punishing yourself.
If you'd like to try out a Free Spyphone Android app on your own phone check out http://flexispy.com/spyphone-flexispy-android.htm

(I don't advocate spying but it's pretty useful for automated backups, usage monitoring, & in case the phone is stolen)
happy
0 Votes
+ -
Well done! Thank you very much for professional templates and community edition
sesli sohbet sesli chat
With the Copy9 application, you can now locate and activate the microphone away from a free Android phone

You can download the software for free at: http://www.spytic.com
New app for back up or spy an iphone 3g/3gs/4g 100% undetectable . www.omegaspy.com There has anything about app for mobile you need. Hope you fun ^^
Today. The smart phone users are familiar with spyware, the functions available in the current spyware is:
- Track your iPhone location
- Read your SMS remotely
- Read your address Book
- See Your Call history
- Track Your Web history
The developers of www.omegaspy.com has released two new functions, two functions unique only in the www.omegaspy.com. there are two functions:
- See all photos captured
- Usage record your apps
Now. Go to www.omegaspy.com and feeling it. Have fun ^^
Do you want to track someone, use the full functionality and save more money ????, So, you can go to http://www.omegaspy.com with us. You can use a lot of different functions developed by experienced programmers. But its price is very cheap only from 4.99$/ 10 days package. i hope it help you ^^

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix