Featured Article

Hackers uncover new TheTruthSpy stalkerware victims: Is your Android device compromised?

TechCrunch adds 50,000 new Android device identifiers to spyware lookup tool

Comment

eyes on a blue background with a phone featured prominently with location markers falling out of it, suggestive of a leak
Image Credits: Bryce Durbin / TechCrunch

A consumer-grade spyware operation called TheTruthSpy poses an ongoing security and privacy risk to thousands of people whose Android devices are unknowingly compromised with its mobile surveillance apps, not least due to a simple security flaw that its operators never fixed.

Now, two hacking groups have independently found the flaw that allows the mass access of victims’ stolen mobile device data directly from TheTruthSpy’s servers.

Switzerland-based hacker maia arson crimew said in a blog post that the hacking groups SiegedSec and ByteMeCrew identified and exploited the flaw in December 2023. Crimew, who was given a cache of TheTruthSpy’s victim data from ByteMeCrew, also described finding several new security vulnerabilities in TheTruthSpy’s software stack.

SPYWARE LOOKUP TOOL

You can check to see if your Android phone or tablet was compromised here.

In a post on Telegram, SiegedSec and ByteMeCrew said they are not publicly releasing the breached data, given its highly sensitive nature.

Crimew provided TechCrunch with some of the breached TheTruthSpy data for verification and analysis, which included the unique device IMEI numbers and advertising IDs of tens of thousands of Android phones recently compromised by TheTruthSpy.

TechCrunch verified the new data is authentic by matching some of the IMEI numbers and advertising IDs against a list of previous devices known to be compromised by TheTruthSpy as discovered during an earlier TechCrunch investigation.

The latest batch of data includes the Android device identifiers of every phone and tablet compromised by TheTruthSpy up to and including December 2023. The data shows TheTruthSpy continues to actively spy on large clusters of victims across Europe, India, Indonesia, the United States, the United Kingdom and elsewhere.

TechCrunch has added the latest unique identifiers — about 50,000 new Android devices — to our free spyware lookup tool that lets you check if your Android device was compromised by TheTruthSpy.

Security bug in TheTruthSpy exposed victims’ device data

For a time, TheTruthSpy was one of the most prolific apps for facilitating secret mobile device surveillance.

TheTruthSpy is one of a fleet of near-identical Android spyware apps, including Copy9 and iSpyoo and others, which are stealthily planted on a person’s device by someone typically with knowledge of their passcode. These apps are called “stalkerware,” or “spouseware,” for their ability to illegally track and monitor people, often spouses, without their knowledge.

Apps like TheTruthSpy are designed to stay hidden on home screens, making these apps difficult to identify and remove, all the while continuously uploading the contents of a victim’s phone to a dashboard viewable by the abuser.

But while TheTruthSpy touted its powerful surveillance capabilities, the spyware operation paid little attention to the security of the data it was stealing.

As part of an investigation into consumer-grade spyware apps in February 2022, TechCrunch discovered that TheTruthSpy and its clone apps share a common vulnerability that exposes the victim’s phone data stored on TheTruthSpy’s servers. The bug is particularly damaging because it is extremely easy to exploit, and grants unfettered remote access to all of the data collected from a victim’s Android device, including their text messages, photos, call recordings and precise real-time location data.

But the operators behind TheTruthSpy never fixed the bug, leaving its victims exposed to having their data further compromised. Only limited information about the bug, known as CVE-2022-0732, was subsequently disclosed, and TechCrunch continues to withhold details of the bug due to the ongoing risk it poses to victims.

Given the simplicity of the bug, its public exploitation was only a matter of time.

TheTruthSpy linked to Vietnam-based startup, 1Byte

This is the latest in a streak of security incidents involving TheTruthSpy, and by extension the hundreds of thousands of people whose devices have been compromised and had their data stolen.

In June 2022, a source provided TechCrunch with leaked data containing records of every Android device ever compromised by TheTruthSpy. With no way to alert victims (and without potentially alerting their abusers), TechCrunch built a spyware lookup tool to allow anyone to check for themselves if their devices were compromised.

The lookup tool looks for matches against a list of IMEI numbers and advertising IDs known to have been compromised by TheTruthSpy and its clone apps. TechCrunch also has a guide on how to remove TheTruthSpy spyware — if it is safe to do so.

But TheTruthSpy’s poor security practices and leaky servers also helped to expose the real-world identities of the developers behind the operation, who had taken considerable efforts to conceal their identities.

TechCrunch later found that a Vietnam-based startup called 1Byte is behind TheTruthSpy. Our investigation found that 1Byte made millions of dollars over the years in proceeds from its spyware operation by funneling customer payments into Stripe and PayPal accounts set up under false American identities using fake U.S. passports, Social Security numbers and other forged documents.

Our investigation found that the false identities were linked to bank accounts in Vietnam run by 1Byte employees and its director, Van Thieu. At its peak, TheTruthSpy made over $2 million in customer payments.

PayPal and Stripe suspended the spyware maker’s accounts following recent inquiries from TechCrunch, as did the U.S.-based web hosting companies that 1Byte used to host the spyware operation’s infrastructure and store the vast banks of victims’ stolen phone data.

After the U.S. web hosts booted TheTruthSpy from their networks, the spyware operation is now hosted on servers in Moldova by a web host called AlexHost, run by Alexandru Scutaru, which claims a policy of ignoring U.S. copyright takedown requests.

Though hobbled and degraded, TheTruthSpy still actively facilitates surveillance on thousands of people, including Americans.

For as long as it remains online and operational, TheTruthSpy will threaten the security and privacy of its victims, past and present. Not just because of the spyware’s ability to invade a person’s digital life, but because TheTruthSpy cannot keep the data it steals from spilling onto the internet.

Read more on TechCrunch:

https://techcrunch.com/2022/02/22/remove-android-spyware/

More TechCrunch

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version of AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Bankruptcy lawyers representing customers impacted by the dramatic crash of cryptocurrency exchange FTX 17 months ago say that the vast majority of victims will receive their money back — plus interest. The…

FTX crypto fraud victims to get their money back — plus interest

On Wednesday, Google launched its digital wallet in India with local integrations, nearly two years after the app was relaunched as a digital wallet platform in the U.S. As TechCrunch exclusively reported last month,…

Google Wallet is now available in India

Bluesky has launched a new product roadmap for the coming months. The decentralized social network said on Tuesday that it is planning to introduce direct messages, support for videos, improved…

Bluesky to add DMs, video support and in-app custom feed curation