PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

This is what happens when your phone is spying on you

Study reveals smartphone spyware apps are hard to detect and remove

This is what happens when your phone is spying on you
2023-03-14
(Press-News.org) Smartphone spyware apps that allow people to spy on each other are not only hard to notice and detect, they also  will easily leak the sensitive personal information they collect,  says a team of computer scientists from New York and San Diego. 

While publicly marketed as tools to monitor underage children and employees using their employer’s equipment, spyware apps are also frequently used  by abusers to covertly spy on a spouse or a partner. These apps  require little to no technical expertise from the abusers; offer detailed installation instructions; and only need temporary access to a victim’s device. After installation, they covertly record the victim’s device activities — including any text messages, emails, photos, or voice calls — and allow abusers to remotely review this information through a web portal.

Spyware has become an increasingly serious problem. In one recent study from Norton Labs, the number of devices with spyware apps in the United States increased by 63% between September 2020 and May 2021. A similar report from Avast in the United Kingdom recorded a stunning 93% increase in the use of spyware apps over a similar period.

If you want to know if your device has been infected by one of these apps, you should check your privacy dashboard and the listing of all apps in settings, the research team says. 

“This is a real-life problem and we want to raise awareness for everyone, from victims to the research community,” said Enze Alex Liu, the first author of the paper No Privacy Among Spies: Assessing the Functionality and Insecurity of Consumer Android Spyware Apps and a computer science Ph.D. student at the University of California San Diego.

Liu and the research team will present their work at the Privacy Enhancing Technologies Symposium in summer 2023 in Zurich, Switzerland.

Researchers performed an in-depth technical analysis of 14 leading spyware apps for Android phones. While Google does not permit the sale of such apps on its Google Play app store, Android phones commonly allow such invasive apps to be downloaded separately via the Web.  The iPhone, in comparison, does not allow such “side loading” and thus consumer spyware apps on this platform tend to be far more limited and less invasive in capabilities. 

What are spyware apps?

Spyware apps surreptitiously run on a device, most often without the device owner’s awareness. They collect a range of sensitive information such as location, texts and calls, as well as audio and video. Some apps can even stream live audio and video. All this information is delivered to an abuser via an online spyware portal. 

Spyware apps are marketed directly to the general public and are relatively cheap–typically between $30 and $100 per month. They are easy to install on a  smartphone and require no specialized knowledge to deploy or operate. But users need to have temporary physical access to their target’s device and the ability to install apps that are not in the pre-approved app stores.

How do spyware apps gather data?

Researchers found that spyware  apps use a wide range of techniques to surreptitiously record data. For example, one app uses an invisible browser that can stream live video from the device’s camera to a spyware server. Apps also are able to record phone calls via the device’s microphone, sometimes activating the speaker function in hopes of capturing what interlocutors are saying as well. 

Several apps also exploit accessibility features on smartphones, designed to read what appears on the screen for vision-impaired users. On Android, these features effectively allow spyware to record keystrokes, for example. 

Researchers also found several methods the apps use to hide on the target’s device. 

For example, apps can specify that they do not appear in the launch bar when they initially open. App icons also masquerade as “Wi-Fi” or “Internet Service.” 

Four of the spyware apps accept commands via SMS messages. Two of the apps the researchers analyzed didn’t check whether the text message came from their client and executed the commands anyway. One app could even execute a command that could remotely wipe the victim’s phone. 

Gaps in data security

Researchers also investigated how seriously spyware apps protected  the sensitive user data they collected. The short answer is: not very seriously. Several spyware apps use unencrypted communication channels to transmit the data they collect, such as photos, texts and location. Only four out of the 14 the researchers studied did this. That data also includes login credentials of the person who bought the app. All this information could be easily harvested by someone else over WiFi. 

In a majority of the applications the researchers analyzed, the same data is stored in public URLs accessible to anyone with the link. In addition, in some cases, user data is stored in predictable URLs that make it possible to access data across several accounts by simply switching out a few characters in the URLs.  In one instance, the researchers identified an authentication weakness in one leading spyware service that would allow all the data for every account to be accessed by any party.

Moreover, many of these apps retain sensitive data without a customer contract or after a customer has stopped using them.  Four out of the 14 apps studied don’t delete data from the spyware servers even if the user deleted their account or the app’s license expired. One app captures data from the victim during a free trial period, but only makes it available to the abuser after they paid for a subscription. And if the abuser doesn’t get a subscription, the app keeps the data anyway.

 

How to counter spyware

 

“Our recommendation is that Android should enforce stricter requirements on what apps can hide icons,” researchers write. “Most apps that run on Android phones should be required to have an icon that would appear in the launch bar.”

Researchers also found that many spyware apps resisted attempts to uninstall them. Some also automatically restarted themselves after being stopped by the Android system or after device reboots. “We recommend adding a dashboard for monitoring apps that will automatically start themselves,” the researchers write.

To counter spyware, Android devices use various methods, including a visible indicator to the user that can’t be dismissed while an app is using the microphone or camera. But these methods can fail for various reasons. For example, legitimate uses of the device can also trigger the indicator for the microphone or camera. 

“Instead, we recommend that all actions to access sensitive data be added to the privacy dashboard and that users should be periodically notified of the existence of apps with an excessive number of permissions,” the researchers write. 

Disclosures, safeguards and next steps

Researchers disclosed all their findings to all the affected app vendors. No one replied to the disclosures by the paper’s publication date.  

In order to avoid abuse of the code they developed, the researchers will only make their work available upon request to users that can demonstrate they have a legitimate use for it. 

Future work will continue at New York University, in the group of associate professor Damon McCoy, who is a UC San Diego Ph.D. alumnus. Many spyware apps seem to be developed in China and Brazil, so further study of the supply chain that allows them to be installed outside of these countries is needed. 

“All of these challenges highlight the need for a more creative, diverse and comprehensive set of interventions from industry, government and the research community,” the researchers write. “While technical defenses can be part of the solution, the problem scope is much bigger. A broader range of measures should be considered, including payment interventions from companies such as Visa and Paypal, regular crackdowns from the government, and further law enforcement action may also be necessary to prevent surveillance from becoming a consumer commodity.”

The work was funded in part by the National Science Foundation and had operational support from the UC San Diego Center for Networked Systems.
 

No Privacy Among Spies: Assessing the Functionality and INsecurity of Consumer Android Spyware Apps

UC San Diego: Enze Liu, Sumath Rao, Grant Ho, Stefan Savage and Geoffrey M. Voelker
Cornell Tech: Sam Havron
New York University: Damon McCoy



 

END

[Attachments] See images for this press release:
This is what happens when your phone is spying on you This is what happens when your phone is spying on you 2 This is what happens when your phone is spying on you 3

ELSE PRESS RELEASES FROM THIS DATE:

New, non-invasive imaging tool maps uterine contractions during labor

2023-03-14
Researchers funded by the National Institutes of Health have developed a new imaging tool, called electromyometrial imaging (EMMI), to create real-time, three-dimensional images and maps of contractions during labor. The non-invasive imaging technique generates new types of images and metrics that can help quantify contraction patterns, providing foundational knowledge to improve labor management, particularly for preterm birth. The small study is supported in part by NIH’s Eunice Kennedy Shriver National Institute of Child Health and Human Development (NICHD) through its Human ...

Regional ECT, lithium, and clozapine use linked to lower suicide rates in male adolescents

2023-03-14
A new study from Karolinska Institutet suggests that electroconvulsive therapy (ECT), lithium, and clozapine may reduce suicide rates in adolescent men with severe mental illness, consistent with previous findings in adults. The study, published in Nature Communications, compared treatment and suicide rates across different regions in Sweden. Annually, there are 800,000 suicide deaths worldwide. Suicide is the leading cause of death among teenagers and young adults, with up to 90 percent of those affected having a serious psychiatric illness ...

Imaging tech produces real-time 3D maps of uterine contractions during labor

Imaging tech produces real-time 3D maps of uterine contractions during labor
2023-03-14
Researchers at Washington University School of Medicine in St. Louis have developed new imaging technology that can produce 3D maps showing the magnitude and distribution of uterine contractions in real time and across the entire surface of the uterus during labor. Building on imaging methods long used on the heart, this technology can image uterine contractions noninvasively and in much greater detail than currently available tools, which only indicate the presence or absence of a contraction. The ...

Tech could help BC farmers reach customers, mitigate climate change impacts

2023-03-14
Technology exists that the BC government could leverage to help small farmers connect directly with consumers and also mitigate climate change impacts, say new findings from UBC Okanagan. Dr. John Janmaat and Dr. Joanne Taylor co-authored new research that examines how farmers in the Okanagan and Cariboo regions of BC are adapting compared to farmers in China’s Shaanxi province. One of the key differences was how Chinese farmers used technology and social media, an option that’s not as widely used in ...

High winds can worsen pathogen spread at outdoor chicken farms

High winds can worsen pathogen spread at outdoor chicken farms
2023-03-14
PULLMAN, Wash. – Farmers who keep their chickens outdoors may want to watch the weather. A study of chicken farms in the West found that high winds increased the prevalence of Campylobacter in outdoor flocks, a bacterial pathogen in poultry that is the largest single cause of foodborne illness in the U.S. Researchers found that about 26% of individual chickens had the pathogen at the “open environment” farms in the study, which included organic and free-range chicken farms. High winds the week prior to sampling and the farms’ location in more intensive agricultural settings were linked to a greater prevalence of ...

Environmental justice scholar Joan Martinez-Alier named 2023 Holberg Prize Laureate

Environmental justice scholar Joan Martinez-Alier named 2023 Holberg Prize Laureate
2023-03-14
Joan Martinez-Alier is Professor Emeritus at the Institute of Environmental Science and Technology, at the Universitat Autònoma de Barcelona (ICTA-UAB). He will receive the award of NOK 6,000,000 (approx. EUR 550,000) during an 8 June ceremony at the University of Bergen, Norway. Martinez-Alier receives the Holberg Prize for his ground-breaking research in ecological economics, political ecology and environmental justice. He is known for criticizing established economic theory and traditional approaches to economic growth. Martinez-Alier is also a major figure and leading public intellectual in the burgeoning movement for ’degrowth’. Degrowth ...

Glucose-dependent insulinotropic polypeptide prevents diet-induced obesity in mice

Glucose-dependent insulinotropic polypeptide prevents diet-induced obesity in mice
2023-03-14
The hormone glucose-dependent insulinotropic polypeptide (GIP) is considered obesogenic. In contrast, GIP receptor agonists (GIPRAs) have shown reduced feeding and body weight in an obese mouse model. Therefore, the precise effects exerted by GIP and GIPRAs remain elusive. Recently, researchers demonstrated acute feeding inhibition and lowered body weight in mice with diet-induced obesity treated with GIPFA-085, a long-acting GIPRA. Their findings provide a scientific basis for GIP therapy for diabetes and obesity. Obesity, ...

Protecting messengers of the gods: Conservation of Nara Park deer has resulted in unique genetic lineage

Protecting messengers of the gods: Conservation of Nara Park deer has resulted in unique genetic lineage
2023-03-14
The existing wildlife of a region is heavily shaped over generations by environmental factors and human activity. Activities like urbanization and hunting are known to reduce wildlife populations. However, some cultural or religious practices have, on occasion, preserved local animal populations. For instance, the forests around religious shrines in Japan have historically forbidden hunting and, as a consequence, provide refuge for certain animal species. A well-known example of this is the Japanese sika deer (Cervus nippon), which has historically been considered a holy creature.   A revered ...

British public back ban on selling junk foods at checkouts study shows

British public back ban on selling junk foods at checkouts study shows
2023-03-14
Shoppers join food industry and health experts in backing UK plans to ban high fat, salt and sugar products from checkouts, store entrances and aisle ends Consumers and retailers were asked about the impact of new government legislation aiming to restrict how unhealthy food is sold Scientists behind investigation say ban can curb impulse buys that cause obesity – but warn of loopholes and limited resources that could undermine health benefits   A ban on selling junk foods from store entrances, aisle ends and checkouts should continue after a new study found the plans were largely backed by the British public and food industry. Legislation ...

EPND launches its Cohort Catalogue, facilitating discovery of over 60 neurodegeneration research cohorts from 17 countries across Europe

EPND launches its Cohort Catalogue, facilitating discovery of over 60 neurodegeneration research cohorts from 17 countries across Europe
2023-03-14
On 14 March, the European Platform for Neurodegenerative Diseases (EPND) launched its Cohort Catalogue. Featuring an extensive list of international cohorts across the neurodegenerative disease spectrum, the Cohort Catalogue is a central, open, accessible repository for researchers to discover ongoing studies and search metadata by disease area, biosample availability, imaging and cognitive data, and more.  The EPND consortium brings together experts in neurodegeneration research, data science, diagnosis and treatment from 29 public and private organisations. Funded by ...

LAST 30 PRESS RELEASES:

Study examines how African farmers are adapting to mountain climate change

Exposure to air pollution associated with more hospital admissions for lower respiratory infections

Microscopy approach offers new way to study cancer therapeutics at single-cell level

How flooding soybeans in early reproductive stages impacts yield, seed composition

Gene therapy may be “one shot stop” for rare bone disease

Protection for small-scale producers and the environment?

Researchers solve a fluid mechanics mystery

New grant funds first-of-its-kind gene therapy to treat aggressive brain cancer

HHS external communications pause prevents critical updates on current public health threats

New ACP guideline on migraine prevention shows no clinically important advantages for newer, expensive medications

Revolutionary lubricant prevents friction at high temperatures

Do women talk more than men? It might depend on their age

The right kind of fusion neutrons

The cost of preventing extinction of Australia’s priority species

JMIR Publications announces new CEO

NCSA awards 17 students Fiddler Innovation Fellowships

How prenatal alcohol exposure affects behavior into adulthood

Does the neuron know the electrode is there?

Vilcek Foundation celebrates immigrant scientists with $250,000 in prizes

Age and sex differences in efficacy of treatments for type 2 diabetes

Octopuses have some of the oldest known sex chromosomes

High-yield rice breed emits up to 70% less methane

Long COVID prevalence and associated activity limitation in US children

Intersection of race and rurality with health care–associated infections and subsequent outcomes

Risk of attempted and completed suicide in persons diagnosed with headache

Adolescent smartphone use during school hours

Alarming rise in rates of advanced prostate cancer in California

Nearly half of adults mistakenly think benefits of daily aspirin outweigh risks

Cardiovascular disease medications underused globally

Amazon Pharmacy's RxPass program improves medication adherence, helps prime members save money, study finds

[Press-News.org] This is what happens when your phone is spying on you
Study reveals smartphone spyware apps are hard to detect and remove