Cocospy is an Android spyware/stalkerware service and a sibling service to Spyzie and Spyic. Reporting cited in the provided content states that Cocospy was exposed in February 2025 alongside Spyzie and Spyic, and that Cocospy and Spyic used the same backend infrastructure and the same Accessibility-based approach to device monitoring. The content associates this monitoring model with Android AccessibilityService abuse to achieve extensive surveillance without root or exploits, including access to live UI content and events, contextual keystroke capture, browser URL/history capture, gesture-driven interaction with the device, overlays, screenshot capture, persistence, and self-hiding. The broader breach reporting states that the related Spyzie incident exposed customer email addresses and reportedly enabled unauthorized access to highly sensitive victim data such as captured messages, photos, and call logs; the content identifies Cocospy as one of the sibling spyware services affected by the February 2025 breaches. Additional reporting in the content states that Cocospy and Spyic were exposed in 2025 due to a vulnerability that leaked 3.2 million customer email addresses and that both apps went offline shortly afterward. High-confidence indicators from the content are limited to the malware name/alias Cocospy and its relationship to Spyic and Spyzie; no specific file hashes, domains, or other technical IOCs are provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cocospy is identified as a sibling spyware service to Spyzie and Spyic that was involved in the same breach event.
Stalkerware app referenced as using AccessibilityService-based monitoring; noted in context of a 2025 exposure of customer emails and shared backend with Spyic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.