November 9, 2016 By Larry Loeb 2 min read

Spyware packages for mobile phones have existed for a while, but the malware type is changing how it spreads.

Skycure Research Labs found one nasty piece of spyware known as Exaspy that works on Android phones and is rather complete in how it sucks up data. Most worryingly, it is available as a commodity service online — spyware-as-a-service, so to speak.

A Sophisticated Snooper

According to Threatpost, Exaspy spyware can intercept messages from all manner of communications, including SMS, MMS, Facebook Messenger, Google Hangouts, Skype, Gmail, native email, Viber, WhatsApp and more. It can also record background audio and telephone calls.

Additionally, the malware has the ability to access the device’s picture library and take secret screenshots on infected devices. This is a sophisticated snooper, for sure.

Physical Access Required

“Interestingly, this malware actually requires an end user to perform the initial installation steps, meaning physical access to the device is required at installation time,” security researcher Elisha Eshed wrote on the Skycure Research Labs blog.

It is possible that Exaspy requests access to device admin rights upon booting. Granting that kind of request likely requires a click action. The malware also installs itself as a system package to prevent the user from removing it, among other tricks to promote its effectiveness.

In any case, Skycure found this malware on an Android 6.0.1 device. It showed up as a fake app called Google Services running with full administrative rights. According to the researchers, the phone belonged to the vice president of a global technology company.

Classic antivirus detection software usually misses this kind of spyware. It doesn’t seem to contain a static signature that can be used for detection. This may be because the malware changes as its command-and-control (C&C) server issues different instructions for different kinds of information it seeks to steal.

Stopping Exaspy Spyware

Skycure advised users to set up PIN codes and fingerprint authentication on their phones. Users should also disable USB debugging and original equipment manufacturer (OEM) unlocking to protect their mobile devices from unwanted apps.

In short, phones need to be hardened to resist this kind of spyware.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today