In short
Stalkerware/spouseware phone spyware—how it’s bought and installed, how it steals messages/photos/location, and why victims can’t safely be notified. It also covers breaches of stalkerware companies, their criminal business practices, and enforcement/legal consequences.
Guest
Zach Whittaker, editor at TechCrunch; long-time reporter covering stalkerware/spouseware.
Key claims
Stalkerware is “phone spyware” used mainly by intimate partners; it’s often easy to deploy (Android app sideloading; iOS via stolen Apple account credentials/tokens to access iCloud backups). It can affect millions daily, with scale inferred from repeated company breaches/leaks. Victim notification is dangerous because the abuser may see alerts. Companies are frequently hacked; leaked data often isn’t secured.
Notable examples
“Truth Spy” breach; a tool letting users check their IMEI on TechCrunch. iCloud token theft to pull iPhone/iPad backups. Location maps showing dots at sensitive sites like military bases (e.g., Diego Garcia). FTC action against Scott Zuckerman; conviction of PC Tattletail CEO Brian Fleming (small fine).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOIntroduction to Stalkerware
0:30 to 2:24
Understanding stalkerware and its implications on personal relationships.
“They're money laundering, they're using identity theft.”
Defining Stalkerware and Its Dangers
3:04 to 6:36
In-depth explanation of what stalkerware is and its invasive nature.
“because you can easily plant an Android app, a stalkerware app on someone's phone.”
Scope and Scale of Stalkerware
6:36 to 10:06
Discussion on the prevalence and the scale of stalkerware operations globally.
“So they leak and they have all this information on the internet for other people to find.”
Challenges in Addressing Stalkerware
10:06 to 14:00
Exploring the complexities and challenges of notifying victims of stalkerware.
“Yeah, and there's the additional very complicated threat that this software, this malware is being deployed often in the context of an abusive relationship.”
Understanding Stalkerware: Identification and Removal
14:00 to 16:42
Learn about how stalkerware operates and methods for victims to identify and remove it safely.
“and it's not something that can easily or feasibly be done.”
Inside Apple Attacks: Mechanisms and Prevention
16:42 to 18:57
Explore how stalkerware targets Apple devices and what users can do to safeguard their accounts.
“And to the best of your knowledge, what is happening there with Apple-focused tools?”
The Role of Tech Companies in Combating Stalkerware
18:57 to 21:18
Discuss the responsibilities of Apple and Google in preventing stalkerware and their responses to reported issues.
“I haven't checked these companies in a while, so you would know better than me.”
The Ongoing Challenge of Stalkerware
21:18 to 22:39
Understand the persistent problem of stalkerware despite increased awareness and tech responses.
“And this is affecting people with relatively modern devices, modern apps.”
Profiles of Stalkerware Developers: Insights and Patterns
27:50 to 28:00
Examine the characteristics and backgrounds of individuals and companies behind stalkerware.
“Thanks Raycon for sponsoring this episode.”
Exploring Surveillance App Developers
28:00 to 29:20
Learn about the profiles and operations of developers creating spyware apps.
Show all 17 chapters
The Business of Stalkerware
29:20 to 31:36
Discover the illicit business practices of stalkerware companies.
“side load and install on people's phones.”
Consequences for Stalkerware Companies
31:36 to 34:28
Understand the legal and regulatory repercussions faced by stalkerware firms.
“operation, they're money laundering, they're using identity theft.”
Reporting on Cyber Exploitation
34:28 to 37:18
Examine the importance of persistent reporting on breaches and their impacts.
“But that was a really rare case of a stalker operation actually facing justice.”
Real Cases of Spyware Impact
37:18 to 42:00
Learn about notable cases of spyware usage and their implications for victims.
“and it's not really, you know, it does seem to be proliferating.”
The Easy Accessibility of Stalkerware
42:00 to 46:02
Learn about the alarming ease with which stalkerware can be accessed and purchased online.
“And I think one of the reasons why it's so problematic is because anyone can really access it if they look enough on the internet.”
Hacking Back: The Risks of Stalkerware
46:02 to 47:26
Discover the paradox of stalkerware companies being hacked and the implications for users.
“And you've said this a few times, so I will stress, there's like a disproportionate off balance or imbalance between the number of these companies that get hacked.”
Newsletter Recommendation and Closing Remarks
47:26 to 48:32
Hear a recommendation for a valuable security newsletter and closing thoughts from the hosts.
“of essentially covering some of these operations is to discourage them from continuing to operate in the surveillance space.”
Transcript
Automatic transcript. May contain errors.0:00Study and play. Come together on a Windows 11 PC. And for a limited time, college students get the best of both worlds. Get the Unreal College Deal. Everything you need to study and play with select Windows 11 PCs. Eligible students get a year of Microsoft 365 Premium and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com slash student offer. While supplies last, ends June 30th. Terms at aka.ms slash college PC. This company made like$2 million plus. They're money laundering, they're using identity theft. It's a whole cybercrime operation.
0:37You see sometimes the photos of their retreats that they go on. They drink and they take photos and they're so happy that they're working at this small startup, but not realizing that their software potentially is infecting hundreds of thousands of people around the world.
0:53Hello, welcome to the 404 Media Podcast, where we bring you unparalleled access to hidden worlds, both online and IRL. 404 Media is a journalist-founder company and needs your support. To subscribe, go to 404media.co. As well as bonus content every single week, subscribers also get access to additional episodes where we respond to their best comments. And they get early access to our interview series too, just like this episode. Gain access to that content at 404media.co. Hello. This week, I'm speaking to Zach Whittaker. He's an editor over at TechCrunch. I've known him for a very, very long time.
1:31He's also the editor of Lorenzo Franceschi Bicari, you know, a longtime and dear friend of mine. And Lorenzo was previously on the podcast talking about government, spyware, malware, all of that sort of thing. i'm also talking to zach about malware for mobile phones but it's on the other side of the spectrum in a way in that is very much focused on stalkerware or spouseware and i'll let zach sort of define more of what that is but it's a really really pressing threat i think it's way more prevalent than people probably understand or even i understand sometimes and zach has been leading coverage on stalkerware and spouseware for the last few years.
2:20I hope you enjoy the conversation.
2:26All right, Zach, welcome to the show. Thank you so much for joining us. Hey, thanks so much for inviting me. I really appreciate that. Of course, of course. So let's just start basic. For you, what is stalkerware? Like, how do you define it when someone asks you, hey, what is this thing called stalkerware? So I would say that stalkerware is its most basic fundamental level phone spyware. But the reason why we call it stalkerware is because in part, because of how it's used and also the people who use it as well. So as you can imagine, it's very secretive and stealthy in terms of the way that it's kind of planned on people's phones.
3:02For the most part, it affects Android users because you can easily plant an Android app, a stalkerware app on someone's phone. But it also does affect iOS users, iPhone users, iPad users as well in a slightly different way. It usually just takes their account credentials and accesses their data in a different way to the cloud. But we call it stalkerware specifically because of the way that it's used and the people who use it. So it's primarily people who are in close or romantic domestic relationships. And people use this spyware. They buy it commercially online using a credit card like anyone can do.
3:40And then they buy it, plant it on someone's phone, usually with knowledge of their passcode or a way to get into their phone. And this is, as I say, it's often close familial kind of settings, partners, domestic spouses. And that's also why we also call it spouseware as well. It lends itself to different names because of the way it's used. But this kind of software is really nasty. It can be used to grab people's messages and their photos and their real-time location. and it can be really, really invasive and acquire all kinds of people's information in real time and allow whoever planted the app or accessed their device account settings to get their information in real time to see what they're up to, where they're going and who they're meeting.
4:23So this is really invasive and nasty software. Yeah, it captures all sorts of data. I mean, essentially everything that's on a mobile phone and usually we wouldn't talk that broadly or that generally, but that's basically the case because as you say to install this piece of software you typically have to be in a in a privileged position with the target which is a very fancy way of saying you're an abusive husband or an abusive wife or an abusive spouse or whatever and in that position you're going to have physical access to the device and i mean when me and lorenzo were covering stalkerware spouseware like something like 10 years ago at this point there was a sort of a feeling in infosec that i don't think is the case anymore to be clear so i should probably stop making this point because i think it's a bit it's a bit out of date but at the time people weren't really paying attention to it because it wasn't like sexy in an infosec way it's not a zero day exploit being delivered by Paragon or NSO Group or anything like that, it's on a technical level, actually pretty basic.
5:31You log into the phone, you download the app, maybe you sideload it, you install it, and that's it. Again, maybe after this interview, I'm going to retire making this point because it does seem out of touch now when companies like Kaspersky actually, I take this shit very seriously now. Just briefly, what do you think of that argument that maybe InfoSec historically didn't really pay attention to this because of the lack of technical sophistication. I think that might actually be in part why stalkerware I think is so dangerous actually. Because it's kind of everywhere. It permeates like a lot of society, different societies all over the world.
6:07And it really is one of those kind of like silent kind of like things that affects a lot of people, but I don't think we get a huge amount of visibility into it. So over the past few years, these stalkerware companies have been breached and hacked and they have exposed so much people's data. By nature, these apps will grab and steal people's information. But the added consequence to that is a lot of these companies don't keep that data secure. So they leak and they have all this information on the internet for other people to find. And so that has allowed us over the years to give us some idea, some understanding of how big of an issue this is.
6:50And we think that this affects millions of people, potentially every single day around the world. And we just don't get that much visibility into it. Lorenzo and I have been covering, just like you, stalkerware over the past few years. And I think the last count that we came to, I think it was in the region of 28 or 29 stalkerware operations or companies that have been exposed or they have been hacked or breached people's information over the course of the last 10 years. And some of these operations have had millions of people who have had their phones compromised at any given time. So we're able to see that some of these operations are actually quite large, even though we don't necessarily see the amount of scale that some of the attacks might have.
7:36But this is a huge problem. We just don't get to see it as much as I think we should. Yeah. So you're getting that sort of sense of scale from all of these different breaches or data exposures by stalkerware companies. And correct me if I'm wrong, I'm just going to say this for the sake of argument, but let's just say that, oh, 29 were exposed or hacked or whatever. Each one of those had a million users. I know that's not the case. I'm just doing it to build the example. But to get the sense of scale, have you basically like added up how many different user accounts were exposed and all of that, just to get a general sense of, oh, wow, this is like millions of people potentially impacted by this malware.
8:17We've tried over the years, and it's really difficult sometimes to actually gauge just how big these operations are, because every single time a company is breached or exposed or had a security lapse, it's a different kind of incident. So the amount of data that we see might vary from time to time, from place to place. But a lot of the time, because these stalker operations rely on grabbing people's location data. Oftentimes, this data is collected, stored by these stalkerware servers, and then they are leaked and exposed. And that allows us to maybe plot out where the locations are seen on a map, for example.
8:51This gives us some visibility into how big these things are. So some of these operations will, as I say, will have a few thousand users here or there. Some of the bigger operations will have maybe a million or plus victims who have had their phones compromised at any given time. And there will be some overlap over these different operations over time because sometimes they evolve, sometimes they get shut down, sometimes they get exposed by reporters like me and you who write about them and they shut down and move on to new operations. But I think the scale is really important to kind of put into perspective because we think that there are probably millions of people who are being compromised every day by this very easy to buy consumer grade spyware.
9:32Whereas, for example, if you look at, say, government-backed spyware, which targets people with powerful zero days and spyware that compromises vulnerabilities on their phone, generally speaking, those are a small number of people. We're talking probably tens, maybe even hundreds of thousands of people who are being spied on by their governments. But the problem, what I think is one of the larger problems with stalker and spyware is that it just affects so many people. and it's so easy for people to use and to buy and to plant on people's phone. I think that in itself is the real danger here. Yeah, and there's the additional very complicated threat that this software, this malware is being deployed often in the context of an abusive relationship.
10:18So of course, where you're mentioning the government spyware there, the threat of course is that, well, the government, generally speaking, has the power to arrest you. they have the legal monopoly over the use of violence all of that sort of thing uh very very concerning for all sorts of different reasons obviously depending on the context activists journalists dissidents whatever right and then also against criminals who should be investigated as well there's all that nuance there here it's not just that people are being hacked and their data taken by this spouseware it's that i don't know when i was speaking to domestic violence experts when I was covering this a while back, you would think that coming from the perspective of InfoSec, oh, it'd be great if we made a tool that automatically removes this malware.
11:05And it's like, no, no, no. If you do that, the man might get angry and stab or attack or something else horrible to this person. And the security considerations around this technology are like way more complicated than And people may assume, because it's not like it's tech first, then domestic violence. It is a domestic violence situation and then tech is involved in on it. Like, what do you make of that? I completely agree with you. And I think that is, you know, notifying people of this kind of activity is really hard. It's actually really, really difficult. And there are a lot of, as you say, a lot of considerations that I think folks don't necessarily think about when, you know, covering and reporting and investigating spyware, like stalkerware, especially when it has this very, very close kind of knit domestic family setting.
11:55Over the years, we found it really difficult to notify victims of stalkerware. And this has been a consistent challenge. And I think you may have experienced this as well. Because when we find that in the cases where we've had identifiable information about victims who've had stalkerware plans on that phone, we may have an email address, we may have some kind of information that could potentially notify them. But if we reach out to them and notify them, say, hey, you might have Spyro on your phone, the added consequence of that is that the person who planted the app on their phone may also see that.
12:30So that could put them in a potentially unsafe situation. And that's really something that we've been thinking about a great deal over time. One of the bigger challenges that we had was with a project called The Truth Spy, which was a a significant stalker operation that we covered several years ago at TechCrunch because it had a serious security vulnerability that allowed anyone to basically download the stolen data from someone's victim's phone. This was a major vulnerability that we managed to write about in the end because it was of such public kind of interest. But when we were able to peruse some of the data and look at some of the victims involved to try and understand more about the business side of these stalker operations, because they do make a lot of money that allows them to continue perpetually making more victims and more money out of this.
13:17We found that some of the victims, we couldn't notify because if we were to notify them, then they would also be potentially put at risk by their partners. So we built a tool that essentially allowed people to search for their own IMEI number, which is unique to their phone, so they can look for themselves in a safe setting to check and see if their phone was compromised by the spyware. Now, that was something that required a lot of time. Resources were at a big company at the time, so we had to go through software security testing of our own. But in the end, it was something that we thought we could do to help people, give them agency to essentially find out if they've been falling victim themselves, rather than us reach out.
13:58But again, that's a very complicated process, and it's not something that can easily or feasibly be done. So that's why I think there has to be a lot more done to support victims of stalkerware and also help folks identify on their own phones so they can remove it in a way that's safe so long as they have a safety plan in place themselves. Yeah, it's a really, really hard problem. And I think your solution is a very novel one in that you almost made like a heavily been pwned site, but just for this sort of branch of stalkerware. Is that site still up and stuff? That's still very much there, yeah.
14:34Yeah, it's still there. Yeah. So we still have it located at techcrunch.com. So you can essentially, for a period of time, when we had that slice of data, there was about 400 or so thousand people whose phones we had identified as being compromised by this suite of different stalkerware tools under the TruthSpy family. And so we purposely built that so that we didn't collect any information and we tried to essentially minimize as much, tracking things like that so people could freely use it. But we found over time that the actual page, people visited that page hundreds of thousands of times. So we hope that there are folks that were able to essentially identify the spiral on their own devices and also remove it in a safe way.
15:24We've written guides of how folks can essentially identify and remove it on their phones. But one of the real challenges with Stalker is that it also deliberately hides something else and it's so stealthy. So it's designed to look like a system app or a system settings app to blend in. And it doesn't visually get seen on the phone. It hides the app. So you can't just swipe through and delete the app because you don't know it's there. And that's one of the real challenges here is that these apps often abuse settings in the phone, like Android settings, accessibility settings, notification settings.
15:58So they can just access all the information at any given time. And a very similar thing with iPhones as well, is that even though you can't necessarily plant a malicious app on an iPhone so easily, if you have access to their email address or their password for their Apple account, you can just pull essentially the downloaded data from their account at any given time. So that's another situation that people need to think about. It's not just Android users who have their phones compromised, it's iPhones as well. So taking those precautions are also really important for users to prevent stalkerware from being planted or misused against someone.
16:33Yeah, you did explain most of it, but maybe just to spell it out for people who haven't heard about this before. Can you explain the Apple attack a little bit more? What does the attacker need exactly? And to the best of your knowledge, what is happening there with Apple-focused tools? So over the past few years, we've found a few stalker operations that have specifically targeted iPhones and iPad users. And we've known this because they themselves have had a data breach. And we've seen the data and we've seen, for example, these are account tokens. These are little pieces of information that essentially allows a user, like an iPhone user, to log in to an Apple service.
17:14And you have one of these by entering your username and password, sets a token. But if you steal that token, then you can essentially access an account as if you were that user. And this is what Stalkerware does. It essentially takes an account victim's username and password, and then it logs in stealthily as if it was that user. It pulls a copy of their backup from their phone from iCloud, and then it passes that data and then presents it in a visually understandable way for whoever tried to essentially access that account. so they can access things like their location data and their photos, their messages, and all the usual sort of data that you would expect Spyware to be able to obtain.
17:56But instead of actually planting something on their phone, it's taking the information directly from their cloud, which a lot of users can also prevent this from happening by enabling two-factor on their account, which I think is mandatory now for Apple accounts. But also, for those who are really particularly mindful of this, ensuring that they don't have any system profiles in their system settings, and ensuring that they don't have any devices that are attached to their iCloud that you don't recognize. That's usually one way to identify that your data might have been accessed. Yeah, because of course, as you say, the software manufacturers aren't sophisticated or frankly rich enough to develop software they can actually install on the iPhone or the iPad.
18:38So they have to attack this other thing, which is, as you say, the backup mechanism. And that's basically controlled by an Apple ID and password. I remember I covered stalkware at first with Lorenzo like 10 years ago. The first couple of years were all about Android. And then we started to see like iCloud cloning tools. I think that was the marketing at the time. Now I feel like... I haven't checked these companies in a while, so you would know better than me. But I feel like they don't even get that specific anymore. They don't say iCloud cloning. They just say, get data from iPhone. They don't even want to explain it really to the user because it's like, I mean, these people might not be super technically minded when they're just trying to steal their spouse's Apple ID and password or whatever.
19:24But yes, I've definitely seen that marketed. Just because we're talking about sort of that marketing, I remember I wrote a story about how Google was having adverts in Google search for stalkerware or something like that. So you would search something and then like a top ad would be like for a really abusive piece of software. There's the Apple case we're just talking about there. My question to you is like, what role do Apple and Google play here as the sort of platform providers of these mobile operating systems? Do they have a responsibility here? Is it kind of out of their hands? I appreciate it's very complicated, but just sort of what are your thoughts on that?
20:02I think on a number of fronts. I think Apple has done a fair amount of work and trying to combat things on their end to a degree. Over the years where we have identified Apple accounts that have been compromised by stalkerware, we've reached out to let them know that they have this issue. They have customers who are compromised. Can we provide them information to essentially help secure their accounts? They've received information and secured potentially hundreds of customers over the period of however long to essentially get them secured. So there is some kind of good reaction there. Similar things have happened with Google over time.
20:40They do react and they do try and essentially react when we flag things. But I think there is an underlying issue with Android apps. Android apps do allow this kind of thing to happen. I think by nature, it's a bit of a trade-off because folks appreciate the open nature of Android to a degree. But it can be abused in a way that can allow malicious people to get access to people's information. So I think there is a bit of a responsibility on both to both react, but also try and do things to prevent this kind of thing from happening. You know, Google has made some strides in locking down Android over time.
21:14But I think that this is still something that we continue to see. We still see stalker operators and companies setting up and creating new apps, new Android apps that allow people to plant them on people's phones. And this is affecting people with relatively modern devices, modern apps. It's still a problem that is continuing to happen. We're still seeing it in large numbers. But it doesn't really seem to have much sign of slowing down. But I would say that on the flip side of it, we have, as I said, exposed, I think, in the region of a dozen or so individual operations over the past few years on top of the other dozen or so that have been exposed for longer.
21:58So this issue is getting more light. There is more sunlight to this. So we are seeing more effort to tackle this broader issue from the tech companies, but also from the security researchers who are trying to essentially get the word out about this. And also the antivirus makers, the anti-malware providers, who are essentially trying to block this kind of software from running on people's phones as well. So there is a concerted effort all around. But I think that one of the best things that can be done is more education about this topic. Making people aware that this kind of thing happens, I think is a really big part of that.
22:39You know that moment where you're lying awake at like 1 in the morning and you suddenly think, wait, this could actually be a business. Maybe it's a product idea. Maybe it's merch. Maybe it's something you've wanted to launch forever, but you haven't acted on it yet. The hard part isn't usually the idea. It's figuring out how to actually build a thing to go from idea to execution. That's why people use Shopify. Shopify is the commerce platform behind millions of businesses worldwide and about 10 % of all e-commerce in the US. From huge brands to people just getting started to 404 Media's merch store.
23:11You can build a storefront with ready-to-use templates that actually look professional. And they have all sorts of tools to help you write product descriptions, improve your product photos, and make launching way faster. On Shopify, you can run email and social campaigns to actually reach customers instead of just hoping people find you. And everything, inventory, payments, shipping, analytics, all lives in one place, which makes the whole thing feel way less overwhelming. Just speaking for myself, using Shopify's backend makes our front end look good and honestly makes it really easy to manage all of our inventory, do the shipping, all that sort of thing.
23:46I've also found that if you ever need help, Shopify has 24-7 support. So if you've been sitting on an idea for months, or if you just came up with it last night, this might be your time to actually launch it. Start your business today with the industry's best business partner, Shopify, and start hearing. Sign up for your$1 per month trial today at shopify.com slash media. Go to shopify.com slash media. That's shopify.com slash media. So I've talked before about this hoodie that I thought would just be for specific situations, but then somehow it became the thing I wore pretty much all winter long.
24:25That's what happens to me with Paka, spelled P-A-K-A, pronounced Paka. I originally thought it would be my travel hoodie or my outdoor hoodie, but I wore it pretty much constantly all winter and fall and spring. But now it's summer and I wanted to tell you about Paka t-shirts and these pack of socks that I have as well. Honestly, they are amazing. They're ridiculously comfortable. They're made from alpaca fiber, which is softer than cashmere, warmer than wool, and somehow still breathable. The hoodie didn't feel bulky or heavy like a lot of hoodies do. And then the t-shirt I find is really breathable.
25:02It's thermoregulating, odor-resistant, durable, and it actually holds up over time. And I love the socks also. They have amazing designs and then they're super comfortable. They keep my feet not so sweaty, which is great. And I most appreciate that Paka uses one of the world's most sustainable and natural fibers. Each hoodie, if you decide to go that way, is made start to finish in Peru and comes with an Inca ID that's hand woven by artisans, which is a really cool way to connect to where your clothing actually comes from. Over 250 ,000 people have already picked one up. And after wearing it all winter, all fall, when it starts getting cold again here in Los Angeles, I'll be wearing it again.
25:43I totally understand why people do that. So this summer, I'm wearing Paka t-shirts for most of the summer, I assume. But if you've been thinking about leveling up your hoodie game or your t-shirt or your sock game, this is probably your sign. To grab your Paka hoodie or t-shirt or socks, go to www.pakaapparel.com. That's www.pakaapparel.com P-A-K-A-apparel.com This message is sponsored by Raycon. I feel like most days I'm constantly moving, walking somewhere, running errands, grabbing coffee, walking my dog, doing stuff around the house. And I pretty much always want to listen to something while I'm doing it, whether it's a podcast, music, audiobook.
Read the full transcript
26:24But the problem I find with regular earbuds is they make you feel weirdly disconnected from what's happening around you. I feel that way even in my house, I'll put regular traditional earbuds on and feel like I don't know what's going on. That's why I've been using Raycon's Essential Open Earbuds. They're open ear, so they sit just outside your ear canal, which means I can listen to podcasts or music while still hearing traffic, people around me, or whatever's happening nearby, which is especially important if you live in a big city where cars don't necessarily respect pedestrians or bikers. It makes being out and about feel way easier and honestly a lot safer too.
27:01And the sound quality is still super clear and balanced. So it really feels like the best of both worlds. They're also super lightweight and the rotating ear hook keeps them locked in place. I've worn them on walks, while cleaning, running errands, even out at the gym. They stay comfortable and they don't fall out even when I'm bending over or running or jumping or doing whatever. And Raycon has over 3 million customers with a sound quality that competes with brands that cost way more. If you try them and they're not for you, they offer a 30-day money-back guarantee. I've been using my Raycons pretty much constantly because they fit into my everyday routine so easily.
27:37The Essential Open Earbuds are the perfect addition to your everyday routine. Go to buyraycon.com slash 404open to get 15 % off. That's buyraycon.com slash 404open to get 15 % off. Thanks Raycon for sponsoring this episode.
28:00we'll talk more about the breaches in a second but i remember when i covered it at the time i was focused very much on the company called flexi spy just because they got hacked and i got sent a bunch of information about it and it wasn't i think just user-related data it was actually a lot of information about the company itself and its founders its creators its developers all of that and we found links between flexi spy and i think some of the government malware vendors like there was a finfisher connection as well that was very interesting it was run by this guy i think in thailand if i'm remembering correctly my question is what have you learned about the people who make these apps who run these companies are there any notable examples is there sort of like a stereotypical profile of someone who runs a company like this like what have you learned about the people behind these?
28:53I think this is a really interesting question, actually, because over the past few years, we have been very fortunate to look inside some of these larger and smaller startups, essentially, that are making these surveillance products and apps. And they range from single developers who are essentially creating this kind of Android app and allowing people to download it, side load and install on people's phones. And we've seen cases like that. We've also seen some of the smaller teams and startups. And I think it's actually really interesting to actually see it from this kind of perspective because we might think of these as like one or two teams, really, like small groups of people.
29:37But in some cases, these are startups. These are teams of 10 or 15 people who are all working for the same goal of making Android software or making other kinds of like surveillance tooling and making web dashboards and making payment systems. And actually, the Truth Spy is a great example of this because over the last few years, we're very fortunate in that we got a data breach through. They actually got breached quite a few times over the past few years. But one of the breaches that we got was from their internal servers. We actually got a huge snapshot of information from how the business actually ran itself.
30:16And this company is based out of Vietnam. They have a team of about 10 or 15 people, as I say. And they had spreadsheets, meticulously detailed spreadsheets of transactions, of logs, of customers. They also had PowerPoints and decks and things like that, business documents, and all kinds of very meticulously organized files and folders of how they essentially ran their operation. It was a perfect view into how these companies essentially operate at a business point of view. This company made like$2 million plus in making the software and tricking credit card makers and credit card vendors into accepting credit card payments for spyware.
30:58These credit card companies don't allow customers to buy spyware with credit cards because they think it's like a banned product. But by using fake identities of people, by using fake IDs, by using bank statements that are meant to look like proof of address. By using all these things, they can create PayPal accounts, they can create bank accounts, they can use proof of address to essentially create a real identity of a person to then funnel money through and then funnel money into the bank accounts of the operators. So you can see how they're essentially skirting the credit card checks, they're skirting your customer checks.
31:35They're doing all these incredible things to essentially support this illicit operation, they're money laundering, they're using identity theft. It's a whole cybercrime operation beyond just surveillance. It's kind of fascinating to see these operations run as small businesses. You see sometimes their photos of their retreats that they go on. And they go on, they drink and they take photos and they're so happy that they're working at this small startup, but not realizing that their software potentially is infecting hundreds of people, hundreds of thousands of people around the world. Yeah, that dichotomy is so strange where, yeah, it's a startup vibe and we're just devs doing a thing.
32:18And then I think we didn't really know about that basically criminal infrastructure until you started highlighting that sort of thing. Like when I did FlexiSpy, I don't think it was that sophisticated. Like we got the inner workings of the company. It showed like the SEO terms they were trying to use, all of that sort of thing. We got a lot of the payment stuff, but not the, we're going to basically spin up fraudulent infrastructure, payment infrastructure to facilitate this. Because if the credit card companies get wind of it, well, they're going to fucking kick us off because we're basically running a criminal enterprise at this point.
32:56If whether they face any criminal repercussions is sort of something else, but that does go to another question they had, which is what have been some of the consequences against some of these companies, both when it comes to breaches, but then also maybe like legal stuff or regulatory stuff as well. Yeah. So I actually wrote a little bit about this for my blog and newsletter. It's paywalled, alas. But essentially, I wrote about some of the things I've learned over the last few years of covering Stalkerware. And one of the things I thought about at length was the repercussions that people face or don't really face.
33:33And over the last few years that we've been able to expose some of these operations as doing illegal things. These are legal operations doing illegal things. They have sometimes shut down. Sometimes they have rebranded. But for the most part, it's kind of like a whack-a-mole kind of situation where you essentially have to try and do what you can to report on these harms. But then on the flip side to that, we've seen a rash of enforcement actions of late, which is kind of surprising really because in the last like few years the FTC took action against one actor named as Scott Zuckerman essentially banned him from the surveillance industry he was the creator of a spyware kind of consortium so to speak the FTC has also taken action against I think Retina X Flexi Spy was in there as well so there has been some kind of enforcement action which is good to see but this is mostly civil enforcement it's like the government saying you know don't do this and and we'll come after you if you continue to spy.
34:31The other side is that earlier this year, there was one, for the first time, I think, in the last 10 or so years, the first conviction of a US spyware maker, and that was Brian Fleming, the CEO and founder of PC Tattletail, which was a stalkerware operation based out of Michigan, where he lived, and then went defunct after a data breach. But that was a really rare case of a stalker operation actually facing justice. And he was convicted in the end. He wasn't jailed. He got time served in the end, but he got a$5 ,000 fine. But I think it was a significant enforcement action from the US government on the rare occasion that it takes these kinds of action.
35:13Because it essentially says that, you know, you can't do this. You shouldn't do this. And spying on people is not only, you know, illegal because it violates wiretapping laws, but it's also just morally just so wrong. And probably more so the fact that it happens, you know, between, you know, often domestic partners where there should be, you know, such trust. But it is good to see that there has been some enforcement action of the way. And my hope is that we'll continue to see it. But for the most part, I think one of the more important things that folks can do in the reporting world and cybersecurity at large is to keep exposing these operations when they come up.
35:49Because these are bad actors doing bad activity. And that needs to come to light. Yeah, I would say on sort of the treating as a beat thing, which you've absolutely done, and I think you're right to do that, in that, you know, there will be a data exposure or a hack or breach of one of these companies, you'll cover it. Then there'll be another one, another one, another one. And then literally, you might have written like about six different breaches in like five or six months or something like that. and a lot of outlets, we wouldn't be able to do that. A lot of other journalists wouldn't be able to do that.
36:25If you're working at, I don't know, let's say the New York Times for the sake of it, they would probably be like, well, we already did this. You know, we've already covered it. When, no, no, no, you don't understand. Here's another one. And this might have another 200 ,000 people exposed or maybe a million if it's a big one. So I don't know. I think there's benefit to the beat reporting and just doing it over and over and over again because yes, it's a very similar story, but this is a different breach and it does impact different people and all of that sort of thing as well. It is a chronic issue for sure.
36:57And it's a chronic issue that continues to get almost seemingly worse over time. I think it's always important to try and bring new and kind of fresh ground. So whenever we cover these kinds of stories, because although we do cover the harms, we think it's important to kind of keep noting the fact that this is a chronic issue. It's not going away. and it's not really, you know, it does seem to be proliferating. And I think, you know, on the flip side is that we're able to educate people about it. And whenever we do report on these things, we at least try to guide folks to the resources to remove the spyware if it's safe to do so and to reach out to the right people who know, you know, more about this than us.
37:39So we at least try and give folks the opportunity to do something about it rather than just like meeting them in a situation where it's like, well, now what do I do, essentially? Yeah, that makes sense. Have you come across sort of cases through these breaches, and there might be a company, there might be a particular victim, it might be a particular user, that was especially interesting to you? One for me was that when I think I got the FlexiSpy data, I was going through it, and there was clearly a metropolitan police officer in there. We did a freedom of information request to the Met in London, obviously.
38:18Didn't get anywhere. We then did whatever the UK equivalent is of sort of a FOIA lawsuit, and that didn't get anywhere either because it's the UK, and it's incredibly difficult to get any fucking information out of agencies. in the UK. But that was a very interesting case to me. Not that the countless other cases are not interesting. It was just that, huh, a government official is using this and I wonder why they did that. I'm just wondering if there are any cases across all of those breaches you've covered that sort of stood out to you or left questions you couldn't quite answer or anything like that.
38:53Yeah, I will say that over the many years I've covered this, I've had very few interactions with victims during the course of my reporting because it's very difficult, as I said previously, to actually reach out to chat with folks. So there have been times when folks have reached out to me after the fact and they said, you know, I had this spot on my phone and it was my husband or my partner and now we're getting a divorce and hearing these kinds of things is like, it's kind of horrifying and it's painful. But it's important, I think, that folks know that this kind of thing happens. Over the last few years, we've seen a lot of cases where spyware doesn't always identify people that well.
39:47And even when people like customers and abusers sign up for these services, it doesn't always verify or validate their email addresses. So it's not always possible to confirm in every single case where a customer, for example, has bought spyware, maybe using a false email address. In some cases, there have been cases where we've been able to identify people, customers who have used their spyware in their own familial kind of setting. And there was one case where I believe it was a sitting appeals court judge in the United States was a paying customer of one particular spyware. when we reached out to the US courts for comment, if I remember rightly, they essentially confirmed, but they did not comment on the matter any further.
40:32But one of the things that we try and do whenever we get a spyware leak through is we try and visualize it with GPS data to kind of see how far wide it kind of goes. If we can try and learn anything geographically from these kinds of things. Some spy operations are specific languages. I think one of them was a Brazilian Portuguese language operation. And as you would imagine, much of the victims were kind of like focused and located in kind of Brazil and in Portuguese speaking countries. But oftentimes we see location data everywhere all over the world. One of the things we sometimes try and do is look for location data in sensitive areas like military bases, government buildings and things like that.
41:18And over the years, we've seen cases where location data is visually clear at places like military bases. Diego Garcia, for example, the island nation has a military base, a very large military base. And you can see little dots where people's locations are on a map. And so I've made the argument before that this can also be a national security issue. When you've got stalkerware planted on the phones or hooked into the phones or accounts of people who are on military bases or overseas or serving, it can put them at risk. It can put other people at risk as well. So this can be really, really dangerous and powerful software.
42:02And I think one of the reasons why it's so problematic is because anyone can really access it if they look enough on the internet. And it's unfortunately not that difficult to find. Yeah, I think just briefly on that. I mean, we're not trying to give people instructions, but to be honest, it is so easy that you don't need us to really. So I'm just, how would you characterize the ease in which someone can buy this? They literally just Google it, enter the credit card details, and it's literally that simple? Yeah, it's that easy, Joe. Yeah, it really is. And it's really kind of concerning just how easy it can be to download and buy the software.
42:41So you mentioned earlier that Google, for example, allowed briefly advertising in its search results. So if you typed in stalkerware, one of the first things that would appear would be one of these operations. And they would also market it specifically under the category of stalkerware. So they would say, catch your cheating spouse, catch your cheating partner. And this would appear as the search engine results. So it's very easy to get. And over time, Google essentially banned those stalkerware adverts. but we actually found that they kept coming back. It was almost like a whack-a-mole on itself.
43:14And I think one of the problems there is that Google and other tech companies, advertising companies, they profit from these adverts because they essentially get paid to put these ads there. So I would say that that in itself is kind of a major problem. Yeah. Yeah. You mentioned sort of some of the search results saying catch cheating spouse or whatever. What has happened, I think a couple of times, I mean, it definitely happened with FlexiSpy was that I would cover FlexiSpy, I would go through their marketing material and would say, catch a cheating spouse or whatever. And then around the time that we're reporting it, that marketing suddenly disappears.
43:54And now it's all about, well, monitor your family and keep them safe. Make sure you don't lose your phone. And there's been a big shift from at least quite a few of these companies to move away from the cheating spouse rhetoric to the, actually want to keep your family safe. The technology is exactly the same. The tool has not changed. It's just the marketing around it. What do you think of that, frankly, tactic by some of these companies? I personally find it frustrating because it is, as you say, it's the same technology. It's doing the same thing, causing the same kind of harms. And so that in itself is a real problem.
44:28Yeah. What I would say is that for the people who think, you know, I'm going to maybe use this software, I'm going to try and use it. I'm sure it's fine. Yeah, it's not. It's not fine. and it's not good to use. It's illegal to use it because it violates people's, you know, it violates wiretapping laws. But also it's morally wrong to use it. And if you do use it, statistically speaking, there's a very good chance that someone like me is going to find out about it because these companies get hacked and leak people's data and expose people's data so much and so frequently that if you use this kind of software, there's a very good chance a greater than non-chance that your information will get leaked and you will get caught by someone else who sees this data online.
45:17Whether it's a reporter publishing something like that, or whether the data is just published online by someone who just hacks a stalker web company for shits and giggles, which in some cases happens. There's been an increase in the last few years of stalker-ware companies being actively hacked by people who do this for hacktivism or out of a vindictive kind of nature to essentially uncover and to expose these companies. And that's a tactic that we've also seen. I don't have any thoughts about that necessarily, but I do think that this kind of activity and these kinds of operations essentially market themselves as these companies that allow people to hack into those phones.
45:59but then they don't realize that they're going to get hacked themselves. Yeah. And you've said this a few times, so I will stress, there's like a disproportionate off balance or imbalance between the number of these companies that get hacked. It's just like insane. Like essentially every company, broadly speaking, in this space has been hacked at some point. It's nuts. Like I don't know whether they're just very bad at security, they have a bigger target on their back, they're just kind of shit at development work. It's probably a combination of all of those. It's all of them, yeah. It really is.
46:30And that's the thing. A lot of this software and a lot of the apps, these have been around largely the same code, the same code base. And these kind of apps have kind of traded companies over time, but it's largely the same stuff from like 10 to 15 years ago. And so the software hasn't changed. The actual fundamental infrastructure of how these operations function hasn't changed. And because these are often sole proprietors, sole developers, or small teams that are just ultimately focused on making money, they don't necessarily have to care about security because they can just retool and restart a new operation somewhere else.
47:08So it's actually, there's not really much of a downside in getting hacked, unless of course, you have information in there that allows someone like me or a reporter to identify the operations owner. and we've done that in the past as well and I feel like that's one of the more effective ways of essentially covering some of these operations is to discourage them from continuing to operate in the surveillance space. Yeah, they don't like it when you do that in my experience. Well, Zach, that was an amazing conversation. Before we go, I would just give a shout out to your newsletter this week in security.
47:45I will put a link in the show notes. Literally everybody listening to this, if you even have a passing interest in information security, I would highly recommend you sign up for this newsletter. I never promo newsletters like this. But this is the one where I try to log off Friday 5pm. And then I try to log back on Monday 9am. I haven't done that for 10 years. I'm really trying to get better at it. But yours is a newsletter that I open and go, Okay, I'm caught up on all the shit I have to care about now. and then I can actually go and get on and then go do my work on ice or whatever. So I really appreciate it and everybody should sign up for that.
48:24But Zach, thank you so much for joining us and really, really appreciate it. Yeah, thank you so much for having me. This was a great conversation. Thanks for everything. Of course. As a reminder, 404 Media is generally founded and supported by subscribers. If you do wish to subscribe to 404 Media and directly support our work, please go to 404media.co. You'll get unlimited access to our articles and an entry version of this podcast. You'll also get to listen to the subscribers only section where we talk about a bonus story each week. This podcast is produced by Alyssa Midcalf. Another way to support us is by leaving a five-star rating and review for the podcast.
49:01That stuff really does help us out. This has been 404 Media. We'll see you again next time.
From the publisher
This week Joseph speaks to Zack Whittaker, an editor at TechCrunch. Zack has been leading coverage into the spouseware or stalkerware industry. This is malware sold to ordinary people, which they then often install on their girlfriend’s or someone else’s phone. Zack talks about the crazy scope of this problem.
Behind the stalkerware network spilling the private phone data of hundreds of thousands
Spyzie stalkerware is spying on thousands of Android and iPhone users
Stalkerware tag on TechCrunch
This Week In Security Newsletter
YouTube Version: https://youtu.be/BLb46310iLs
Subscribe at 404media.co
Learn more about your ad choices. Visit megaphone.fm/adchoices
