Xnspy stalkerware on thousands of iPhones and Android devices

A little known phone tracker called Xnspy has stolen data from tens of thousands of iPhones and Android devices. In fact, the majority of owners do not know that their data has been stolen.

spying eye

Xnspy is one of the many so-called stalkerware sold under the guise of allowing a parent to monitor their child's activities. In the market, however, it is available for spying on spouses or partners without their permission. The app's website states that “to see if you're a cheating spouse, you need Xnspy by your side” and “Xnspy makes reporting and data extraction simpler for you.”

Stalkerware, also known as spouseware, is secretly installed by someone with physical access to the device. They bypass device security protections and are designed to remain hidden from home screens, making them very difficult to detect.

Once installed, these apps silently and continuously send phone contents such as call logs, text messages, photos, browsing and precise location data, to the one who installed the app allowing them to have almost complete access to their victim's data.

However, new findings show that many stalkerware apps are riddled with security holes and reveal data stolen from victims' phones. Xnspy is no different.

Security researchers Vangelis Stykas and Felipe Solferini spent months examining several known stalkerware applications and analyzing the networks to which they send their victims' data.

Their research, presented in BSides London this month, it identified common and easy security flaws in several stalkerware families, including Xnspy. They discovered, for example, credentials and private keys left in the code by developers and broken or non-existent encryption. In some cases, the security holes exposed the victims' stolen data, which is on someone else's unsecured servers anyway.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.
Xnspy,stalkerware,iphone,Android

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).