Spyic is an Android spyware/stalkerware service. The provided content identifies it as a sibling spyware service to Spyzie and Cocospy and states that Spyic was exposed in February 2025. The content further states that Spyic and Cocospy used the same backend infrastructure and the same AccessibilityService-based approach to device monitoring. Reported monitoring capabilities associated with this approach include broad device surveillance without root by abusing Android accessibility features, including access to UI content across apps, real-time event monitoring, contextual keylogging, browser URL/history capture, screenshot capture, gesture injection, overlays, permission-granting automation, persistence, and self-hiding. The content also states that the 2025 exposure involving Cocospy and Spyic leaked 3.2 million customer email addresses and that both apps went offline shortly afterward. Mentioned exposed victim data in the related spyware-service breach context included captured messages, photos, and call logs. High-confidence associations in the content are limited to Spyic being spyware/stalkerware, its shared infrastructure and accessibility-based monitoring model with Cocospy, and its exposure in 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyic is identified as a sibling spyware service to Spyzie and Cocospy that was involved in the same breach event.
Stalkerware app referenced as using AccessibilityService-based monitoring; noted in context of a 2025 exposure of customer emails and shared backend with Cocospy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.