{"id":39102,"date":"2021-03-19T11:09:31","date_gmt":"2021-03-19T15:09:31","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=39102"},"modified":"2021-03-23T05:26:53","modified_gmt":"2021-03-23T09:26:53","slug":"stalkerware-in-2020","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/stalkerware-in-2020\/39102\/","title":{"rendered":"Stalkerware in 2020 is still a burning issue"},"content":{"rendered":"<p>These days, spying on people has gotten far too easy. Anyone can buy stalkerware apps, which can look like parental control software or a smartphone antitheft solution. The classification may help developers avoid legal trouble; the software\u2019s real purpose is to collect a great deal of highly sensitive information from devices without their users\u2019 knowledge.<\/p>\n<p>Although the legal status of stalkerware is gray, the use of such apps is not only unethical but also <a href=\"https:\/\/www.kaspersky.com\/blog\/stalkerware-spouseware\/26292\/\" target=\"_blank\" rel=\"noopener nofollow\">dangerous<\/a>. We believe in countering the threat, in particular by raising awareness about it and any protective measures available to concerned citizens.<\/p>\n<h2>The scale of the scourge<\/h2>\n<p>Stalkerware apps\u2019 features vary, but most enable total surveillance of the victim\u2019s smartphone. Moreover, to install the app on the target device, the attacker simply needs to gain physical access to it once. Many people trust their partners enough to give them that access.<\/p>\n<p>Among other things, stalkerware users can, without alerting their target in any way:<\/p>\n<ul>\n<li>Track a victim\u2019s location;<\/li>\n<li>Read messages in messaging apps and social networks;<\/li>\n<li>View photos, videos, and other files on the device;<\/li>\n<li>Eavesdrop on telephone conversations;<\/li>\n<li>See everything typed on the keypad, including passwords and two-factor authentication codes.<\/li>\n<\/ul>\n<p>Stalkerware typically hides itself from the list of installed programs and does not display any activity notifications.<\/p>\n<p>Knowing their victim\u2019s every move, an attacker can control, threaten, and psychologically pressure them. According to a 2017 <a href=\"https:\/\/eige.europa.eu\/news\/cyber-violence-growing-threat-especially-women-and-girls\" target=\"_blank\" rel=\"nofollow noopener\">report by the European Institute for Gender Equality<\/a> (EIGE), seven of ten women affected by online stalking have experienced physical violence, sexual violence, or both at the hands of the perpetrator.<\/p>\n<p>The scale of the problem continues to grow. For example, an Australian <a href=\"https:\/\/wesnet.org.au\/wp-content\/uploads\/sites\/3\/2020\/11\/Wesnet-2020-2nd-National-Survey-Report-72pp-A4-FINAL.pdf\" target=\"_blank\" rel=\"nofollow noopener\">study on technology abuse and domestic violence<\/a> showed that, since 2015, attackers have become far more likely to track the locations of current and former partners, and almost twice as likely to monitor them with cameras. The Centre Hubertine Auclert in France reports that one in five victims of relationship violence has encountered spyware. Germany also notes a rise in the use of stalkerware in recent years.<\/p>\n<h2>54,000 stalkerware victims in 2020<\/h2>\n<p>What has changed since 2019, when we teamed up with like-minded companies and nonprofits in the <a href=\"https:\/\/stopstalkerware.org\/\" target=\"_blank\" rel=\"nofollow noopener\">fight against stalkerware<\/a>? Data from Kaspersky Security Network <a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/100\/2020\/03\/25175212\/EN_The-State-of-Stalkerware-2020.pdf\" target=\"_blank\" rel=\"noopener\">indicates almost 54,000 users worldwide<\/a> were affected by stalkerware apps in 2020. Is that high or low? The figure in 2018 was almost 40,000, but in 2019 it topped 67,000.<\/p>\n<div id=\"attachment_39103\" style=\"width: 1470px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2021\/03\/19110625\/stalkerware-in-2020-unique-users.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-39103\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2021\/03\/19110625\/stalkerware-in-2020-unique-users.png\" alt=\"Unique users worldwide affected by stalkerware, 2018\u20132020\" width=\"1460\" height=\"700\" class=\"size-full wp-image-39103\"><\/a><p id=\"caption-attachment-39103\" class=\"wp-caption-text\">Unique users worldwide affected by stalkerware, 2018\u20132020. <a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/100\/2020\/03\/25175212\/EN_The-State-of-Stalkerware-2020.pdf\">Source<\/a><\/p><\/div>\n<p>This much is clear: The fight against online stalking is far from won. First, when it comes to threats of violence, 54,000 is a big number, however you slice it. Second, the pandemic and its consequences are factors, holding people house-bound in 2020 \u2014 and household members (spouses, roommates) are by far the most likely to use stalkerware apps. Isolation is likely to skew the numbers; with a victim stuck at home, a stalker may not monitor their smartphone\u2019s whereabouts.<\/p>\n<p>With that in mind, it is unsurprising that the yearly curve of users affected by stalkerware globally shows a decline in reports from March to June 2020. That period coincides with the beginning of worldwide lockdowns. Later, when many countries around the world began to ease restrictions, the numbers began to rebound and stabilize.<\/p>\n<p>As for geography, our solutions most often detected stalkerware in Russia, Brazil, and the US, all of which landed in the Top 5 in 2019 as well. Among Asian countries, the problem was most acute in India, and the hardest hit in Europe were Germany, Italy, and the UK.<\/p>\n<h2>2020\u2019s most common stalkerware families<\/h2>\n<p>As for stalkerware apps, the most common specimen in 2020 was the one our solutions call Monitor.AndroidOS.Nidb.a. Its developers allow the app to be resold under other names, so it is prominent in the market. The iSpyoo, TheTruthSpy, and Copy9 apps, for example, are all Nidb. Interestingly, until just a year ago, this stalkerware family was only the third most prevalent.<\/p>\n<p>Another very popular piece of spyware is Cerberus, which is sold as antitheft smartphone protection and hides itself to avoid notice. What\u2019s more, like genuine phone-finding apps, Cerberus has access to geolocation, can take photos and screenshots, and records sound.<\/p>\n<p>Other high-ranking stalking apps include Track My Phone (which our solutions detect as Agent.af), MobileTracker (which enables remote control of the victim\u2019s device), and the stalkerware program Anlost. The latter, like Cerberus, appears to be an antitheft tool, but it\u2019s available on Google Play, which declared war on stalkerware last year, because it meets the store\u2019s requirements.<\/p>\n<h2>How to detect stalkerware<\/h2>\n<p>One of the main problems with stalkerware is that it can\u2019t just be found and removed. Removing stalkerware could alert an abuser that the victim is aware of being spied on. Some of the samples actually send a notification to the stalker, in which case deleting the app could escalate conflict and further endanger the victim.<\/p>\n<p>But stalkerware can, and must, be detected \u2014 for starters, knowing you are being watched can lead you to <a href=\"https:\/\/stopstalkerware.org\/get-help\/\" target=\"_blank\" rel=\"nofollow noopener\">take precautions<\/a> or seek help. There are <a href=\"https:\/\/www.kaspersky.com\/blog\/tinycheck-detects-spyware-stalkerware\/38030\/\" target=\"_blank\" rel=\"noopener nofollow\">several ways<\/a> to sniff out a spy.<\/p>\n<ul>\n<li>Keep an eye on battery and mobile data usage. Stalkerware runs in the background, sending constant streams of data to its server and eating up resources;<\/li>\n<li>Check which apps have been given <a href=\"https:\/\/www.kaspersky.com\/blog\/android-8-permissions-guide\/23981\/\" target=\"_blank\" rel=\"noopener nofollow\">dangerous permissions<\/a> such as geolocation access or Accessibility (a set of Android features that lets an app control phone settings, read on-screen text, and more). If an unfamiliar app is using such permissions, it is likely to be stalkerware;<\/li>\n<li>Use a <a href=\"https:\/\/www.kaspersky.com\/mobile-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____da04049114cf37d2\" target=\"_blank\" rel=\"noopener nofollow\">security solution<\/a> that identifies and warns you about stalkerware. However, bear in mind that some types of stalkerware notify their operators if their target installs antivirus protection;<\/li>\n<li>Use <a href=\"https:\/\/github.com\/KasperskyLab\/TinyCheck\/\" target=\"_blank\" rel=\"nofollow noopener\">TinyCheck<\/a>, a solution designed to find stalkerware without its operator knowing.<\/li>\n<\/ul>\n<p>You can learn more about the tools and techniques mentioned above and how effective they are on <a href=\"https:\/\/www.kaspersky.com\/blog\/stalkerware-detection-tactics\/\" target=\"_blank\" rel=\"noopener nofollow\">our blog<\/a>.<\/p>\n<h2>How to reduce the risk of stalkerware infection<\/h2>\n<p>You can reduce the risk of someone sneaking stalkerware onto your devices, too:<\/p>\n<ul>\n<li>Never give your phone to anyone and, if possible, don\u2019t even leave it unattended;<\/li>\n<li>Protect your device with a strong alphanumeric password that you never share with anyone;<\/li>\n<li>Block the installation of apps from third-party sources in your device settings, and use only the official app stores;<\/li>\n<li>Protect your device with a reliable <a href=\"https:\/\/www.kaspersky.com\/mobile-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____da04049114cf37d2\" target=\"_blank\" rel=\"noopener nofollow\">mobile antivirus utility<\/a> that detects and warns you about stalkerware.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic\">\n","protected":false},"excerpt":{"rendered":"<p>Stalkerware activity dropped off during the pandemic, but it\u2019s picking up again. How to deal with the threat.<\/p>\n","protected":false},"author":2477,"featured_media":39104,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1788,2683],"tags":[423,4059,43,714,3181],"class_list":{"0":"post-39102","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-privacy","8":"category-threats","9":"tag-mobile-devices","10":"tag-online-stalking","11":"tag-privacy","12":"tag-spyware","13":"tag-stalkerware"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/stalkerware-in-2020\/39102\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/stalkerware-in-2020\/22645\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/stalkerware-in-2020\/18136\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/stalkerware-in-2020\/24428\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/stalkerware-in-2020\/22465\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/stalkerware-in-2020\/21440\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/stalkerware-in-2020\/24948\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/stalkerware-in-2020\/24216\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/stalkerware-in-2020\/30296\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/stalkerware-in-2020\/9449\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/stalkerware-in-2020\/16606\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/stalkerware-in-2020\/17192\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/stalkerware-in-2020\/14605\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/stalkerware-in-2020\/26430\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/stalkerware-in-2020\/26825\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/stalkerware-in-2020\/23690\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/stalkerware-in-2020\/29029\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/stalkerware-in-2020\/28830\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/stalkerware\/","name":"stalkerware"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/39102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2477"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=39102"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/39102\/revisions"}],"predecessor-version":[{"id":39120,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/39102\/revisions\/39120"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/39104"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=39102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=39102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=39102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}