mSpy is a commercial mobile spyware/stalkerware product sold for covert surveillance of target devices. The provided content links it to the broader consumer spyware ecosystem alongside products such as FlexiSpy and MobileSpy, and notes that Hacking Team was a customer of mSpy and similar services to study features and intrusion techniques. The reporting also states that mSpy has been discussed in the context of overlap between consumer spouseware and government-grade surveillance tooling.
Based on the content, mSpy is associated with monitoring capabilities on mobile devices, including so-called “IM capture” functionality. One source explicitly states that commercial stalkerware products such as FlexiSpy and mSpy use Android AccessibilityService for non-root monitoring features such as instant-message capture. The content further references an infrastructure overlap allegation in which an Android spyware sample believed to belong to Aglaya received commands from a server hosting the domain mobilebugstore.com, which redirected to an mSpy website; mSpy said the domain was operated by an affiliate and denied a business relationship with Aglaya.
The content also highlights a major June 2024 breach affecting mSpy. Hacktivists reportedly obtained and published a large trove of stolen data from the company, including 142GB of user data and support tickets and 176GB of attachments comprising more than half a million files. The exposed data reportedly contained 2.4 million unique email addresses as well as IP addresses, names, and photos. Much of the support-ticket material reportedly involved requests for help installing mSpy on target devices, and the attachments included highly sensitive material such as screenshots of financial transactions, photos of credit cards, and nude selfies.
High-confidence associations in the content are therefore: commercial stalkerware/mobile spyware; use against target mobile devices; Android non-root monitoring via AccessibilityService for IM capture; presence in the consumer surveillance market discussed alongside abusive partner surveillance; customer interest from Hacking Team for feature study; and a significant 2024 data breach exposing customer/support data. No additional verified malware-family technical indicators or specific infection-chain details beyond installation on target devices are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hacking Team, which has sold services to the FBI, Mexico and many others for up to and over $1 million per contract, was a customer of multiple consumer services too, including FlexiSpy, mSpy and MobileSpy.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware used to monitor target devices; the leaked data included support tickets about installing the spyware and attachments containing sensitive victim data.
Commercial stalkerware referenced as leveraging Android AccessibilityService for monitoring/IM capture without root.
Consumer surveillance/spouseware platform referenced as both a commercial monitoring tool and as linked via infrastructure to government surveillance tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.