TrackView is identified in the provided content as Program.TrackView, a monitoring/surveillance application categorized as riskware rather than a malware family. The content states it can be used to monitor users by tracking a target device’s location, taking photos and video, eavesdropping via the microphone, and recording audio. These capabilities indicate use for covert surveillance of Android device users. No specific threat actor, campaign, infection vector, targeted industry, or indicators of compromise are provided in the content beyond its surveillance functionality and naming.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Potentially dangerous monitoring app that can be abused for surveillance (location tracking, camera/mic access, recording).
Monitoring/stalkerware-style program enabling location tracking, camera access, microphone eavesdropping, and audio recording when misused by malicious actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.