Catwatchful is an Android spyware/stalkerware operation. Reporting in the provided content states that its website contained an SQL injection vulnerability that exposed data on more than 62,000 customers, including emails and plaintext passwords, and that the service had been deployed on more than 26,000 Android smartphones. The content explicitly describes Catwatchful as a spyware app and Android stalkerware operation. High-confidence details in the source are limited to this exposure and its scale; no additional malware capabilities, delivery vectors, specific victim sectors, or technical indicators of compromise are provided beyond its operation against Android devices and the exposure of customer data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android stalkerware/spyware app used for monitoring and data theft from target devices.
Spyware app for Android used to monitor and collect data from infected devices. Exposed due to a website vulnerability leaking user data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.