Have you ever heard of stalkerware?

It is a portmanteau of "stalker" and "software." These are spyware programs that allow someone to spy on an individual, entity, or organization without their knowledge. Stalkerware is software that anyone can purchase. Products on the market include FlexiSpy, mSpy, PhoneSpector, and more.

Everyone is at risk, whether they are public figures, everyday people, or organizations.

These programs are proliferating so rapidly that it is essential to take precautions to protect yourself from these threats. Following a few digital hygiene rules is necessary to learn how to identify and defend against them.

Table of Contents

How does it work?

How it works

Spyware can be bundled into free software. Some can be controlled remotely and do not require physical access. Another key feature is that these programs run in the background, making them difficult to detect.

Spyware requires:

  • An infection mechanism, such as a virus, phishing, or even a program that appears legitimate.

  • A collection mechanism. If the spyware is installed on a smartphone, it will harvest passwords, photos, conversations, location data, call logs, visited websites, downloaded files, and more. To achieve this, it uses password stealers, keyloggers, audio and video recorders, and cookie trackers.

  • A transmission mechanism.

Detection

You might suspect a device is being monitored if you notice:

  • Issues connecting to secure websites.
  • A slowdown in device performance.
  • The device suddenly turning on and off.
  • The appearance of new applications.
  • An increase in advertisements.
  • The battery draining faster than usual.

In addition to these signs detectable by the phone user, a protection tool such as TEHTRIS Mobile Threat Defense allows you to detect the installation of a malicious application, automatically scan mobile devices in the background, and verify the permissions granted to each application. Upon installation and with every update, the TEHTRIS MTD solution analyzes applications within the CTI (Cyber Threat Intelligence, TEHTRIS's cyber intelligence database). If applications are blacklisted in the CTI, the MTD agent will trigger an alert, visible on the unified XDR platform and on the compromised mobile device.

Use Case: Installation of FlexiSpy Spyware

Upon installation of FlexiSpy, an application hash is automatically analyzed in the TEHTRIS CTI, which benefits from antivirus analyses containing millions of signatures (on average, 4,000 new viruses are added for mobile platforms every day).

Analysis result:

FlexiSpy receives a high viral analysis score because it is flagged in antivirus databases, which generates an alert in the unified TEHTRIS XDR console and on the user's mobile device.

Alert following the installation of a malicious APK in the
TEHTRIS XDR

FlexiSpy can be removed from the XDR console.

Furthermore, when combined with the DNS Firewallmodule, any request to a domain name blacklisted in the TEHTRIS database will be automatically blocked. Consequently, if spyware is installed on a mobile device and attempts to communicate with its Command and Control (C2) server to exfiltrate data, the connection will be terminated.

Good digital hygiene

There are several countermeasures and precautions that can help reduce the threat; here are a few:

  • Install a minimum number of applications and only use apps certified by trusted developers.

  • Check access permissions. Obviously, never share your password.

  • Perform updates on your digital tools. This is important to ensure you benefit from the latest and most optimal protection.

  • Schedule automated scans.
  • Use a reliable protection toolThere are also tools capable of protecting against intrusions: "Mobile Threat Defense" applications (see the following section), antivirus software, antimalware, and firewalls.

  • Restart your device regularly.

  • Maintain physical control of your device as much as possible. Protect the camera and microphone, disable geolocation, etc.

  • Turn off Bluetooth when not in use.

  • Be careful with message content. It is important to prioritize end-to-end encrypted messaging services.

  • Ensure that every tooland piece of hardware connected to your phone is secure (headphones, charging systems).

  • Never connect your devices to public USBcharging stations.

  • Avoid public Wi-Fi networks.

  • Prioritize secure websites.

  • Delete "SyncManager" and "IphoneInternalService" if these applications are installed on your smartphone.

We recommend following the advice from ANSSI: https://www.ssi.gouv.fr/particulier/guide/recommandations-relatives-a-lauthentification-multifacteur-et-aux-mots-de-passe/

And from the CNIL: https://www.cnil.fr/fr/mots-de-passe-ouverture-dune-consultation-publique-sur-la-nouvelle-recommandation-de-la-cnil

Go further with TEHTRIS

At TEHTRIS, your security is our priority.
We offer tools dedicated to smartphone security. TEHTRIS MTD has the ability to identify and detect known or unknown threats in real time.

Our MTD enables:

  • analysis of application rights & permissions.
  • scheduling regular scans.
  • detection of brute-force attempts.

It allows you to extend protection to mobile devices running Android, iOS, iPadOS, and Chromebook.

TEHTRIS MTD, natively integrated into the TEHTRIS XDR Platform, protects your mobile fleet, allowing you to benefit from our latest innovative technologies and ensure defense-in-depth. This solution guarantees optimal device security.

Learn more: Discover TEHTRIS MTD

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all