This Android spyware collects all your data, and you might not even know it

Updated on 13-Dec-2024
HIGHLIGHTS

Cybersecurity researchers have uncovered a spyware called EagleMsgSpy being used by law enforcement in China to monitor mobile devices.

This spyware has been active since 2017 and was developed by Wuhan Chinasoft Token Information Technology.

It can access third-party chat messages, record screens and audio, take screenshots, track locations, and even monitor call logs and SMS messages.

Cybersecurity researchers have uncovered a powerful spyware called EagleMsgSpy being used by law enforcement in China to monitor mobile devices. According to a report by cybersecurity firm Lookout, this spyware has been active since 2017 and was developed by Wuhan Chinasoft Token Information Technology.

The spyware is designed to gather a vast amount of personal information from infected devices. It can access third-party chat messages, record screens and audio, take screenshots, track locations, and even monitor call logs and SMS messages. It can also collect details about the device’s contacts, browser bookmarks, installed apps, and files stored on external storage.

Also read: Researchers warn: Hackers can exploit 5G baseband flaws to spy on cell phone users

How EagleMsgSpy operates

According to BleepingComputer, Lookout’s investigation linked the spyware to its developers and operators through evidence such as IP addresses of command-and-control (C2) servers, domain records, internal references in documentation, and public contracts.

The spyware is not available on Google Play or third-party app stores, suggesting that it is distributed manually. According to Lookout, authorities likely install the spyware on unlocked devices during incidents like arrests or confiscations.

An important part of the spyware’s operation is its ability to collect sensitive data silently. The collected information is stored in a hidden folder on the device and is then compressed and password-protected before being sent to the C2 server for further use.

Possible iOS version

While Lookout’s findings focus on Android, researchers believe there may also be an iOS version of EagleMsgSpy. However, they haven’t obtained a sample to confirm this yet.

Also read: Data of 375 million Airtel India users allegedly put on sale on Dark Web, telco denies report

What EagleMsgSpy collects

EagleMsgSpy is capable of gathering:

  • Messages from apps like QQ, Telegram, WhatsApp, Viber, and WeChat.
  • Screen recordings and screenshots using the Media Projection service.
  • Audio recordings of phone conversations and ambient sounds.
  • Detailed call logs, contacts, SMS messages, GPS coordinates, and network data.
  • A list of installed apps and files on external storage.
  • Browser bookmarks and Wi-Fi connection details.
Ayushi Jain

Tech news writer by day, BGMI player by night. Combining my passion for tech and gaming to bring you the latest in both worlds.

Connect On :