pwshub.com

Stalkerware company Spytech compromised, data reveals thousands of remotely controlled devices

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

Facepalm: Stalkerware programs are frequently used to monitor, control, or track PC and mobile device users. These tools are employed with varying degrees of legitimacy by relatives or law enforcement agencies, but things go completely haywire when a manufacturing company gets targeted by hackers.

Spytech Software, a Minnesota-based company that produces SpyAgent and similar programs, has been breached. TechCrunch was able to access a cache of files taken from Spytech's servers by unknown hackers, and has exposed the company's activities and the devices targeted by its stalkerware products.

Spytech has been providing monitoring software for concerned spouses and parents for over 24 years. The company states that its "award-winning" solution combines over 20 essential (and theoretically invisible) monitoring tools with cloud and email-based remote activity logs. With SpyAgent, the corporation claims, customers can record, see, and respond to everything happening on a computer.

Stalkerware programs are usually very effective at concealing their presence. According to data exfiltrated by the hackers, Spytech was able to infect various types of devices, including Android phones, Chromebooks, Mac systems, and PCs. The file cache includes data about more than 10,000 remotely controlled devices, with the earliest records dating back to 2013.

The devices compromised by Spytech programs had their entire activity saved in logs stored on the company's servers. Most of these devices were Windows-based PCs, TechCrunch explains, and the activity logs didn't use any form of encryption. When plotted on an offline mapping tool, the location data provided a clear picture of where the compromised devices were located around the world.

Most of the mobile, Android-based devices infected with Spytech tools were located in Europe and the US. Even Spytech executive Nathan Polencheck was among the compromised, though he likely installed his company's monitoring software on his own phone. When contacted by TechCrunch, Polencheck said he had no knowledge of the breach. The exfiltrated data can seemingly reveal the precise location of his house in Red Wing, Minnesota.

So far, Spytech has made no public statement about the security incident. By all accounts, the company may be forced to notify customers who installed the stalkerware tools on people's devices or even inform US federal authorities.

Another spyware manufacturer, pcTattletale, was breached earlier this year, but the company chose to shut everything down rather than provide any public notice about its activities or databases.

Source: techspot.com

Related stories
1 month ago - No mention of malware or ransomware – somewhat of a rarity these days HealthEquity, a US fintech firm for the healthcare sector, admits that a "data security event" it discovered at the end of June hit the data of a substantial 4.3...
1 month ago - Plus: More stalkerware exposure; a $16M TracFone fine; Ransomware victims don't use MFA, and more Infosec in brief Protecting computers' BIOS and the boot process is essential for modern security – but knowing it's important isn't the...
Other stories
39 minutes ago - Experts at the Netherlands Institute for Radio Astronomy (ASTRON) claim that second-generation, or "V2," Mini Starlink satellites emit interference that is a staggering 32 times stronger than that from previous models. Director Jessica...
40 minutes ago - The PKfail incident shocked the computer industry, exposing a deeply hidden flaw within the core of modern firmware infrastructure. The researchers who uncovered the issue have returned with new data, offering a more realistic assessment...
40 minutes ago - Nighttime anxiety can really mess up your ability to sleep at night. Here's what you can do about it right now.
40 minutes ago - With spectacular visuals and incredible combat, I cannot wait for Veilguard to launch on Oct. 31.
40 minutes ago - Finding the perfect pair of glasses is difficult, but here's how to do so while considering your face shape, skin tone, lifestyle and personality.