Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The app also abuses Android’s Accessibility Service permission, which grants it the ability to read any content shown on the screen and intercept passwords as they are typed, giving the attacker full visibility across the entire device.
A BootReceiver component ensures the spyware restarts automatically every time the device is rebooted.
The most telling feature is described as “Impossible Anti-Uninstall”: the app can only be removed via the operator’s dashboard... Block all uninstallation attempts by registering itself as a Device Administrator, the app cannot be removed through normal means.
The app also abuses Android’s Accessibility Service permission, which grants it the ability to read any content shown on the screen and intercept passwords as they are typed, giving the attacker full visibility across the entire device.
Analysis of the APK shows the app is installed under the name “WiFi Service” or “WiFiService Installer” — a generic, innocuous-sounding name designed to avoid arousing suspicion on the device’s home screen. Additionally, its accessibility service is labelled “WiFiService Assistant”, and its notification listener is called “WiFiService Monitor”.
The most telling feature is described as “Impossible Anti-Uninstall”: the app can only be removed via the operator’s dashboard... Block all uninstallation attempts by registering itself as a Device Administrator, the app cannot be removed through normal means.
From a single web dashboard, an operator can: ... Log every keystroke typed on the device.
Once granted, it gives KidsProtect the ability to read the contents of any app on the screen, intercept passwords as they are typed, and monitor activity across the entire device.
The most telling feature is described as “Impossible Anti-Uninstall”: the app can only be removed via the operator’s dashboard... Block all uninstallation attempts by registering itself as a Device Administrator, the app cannot be removed through normal means.
The tool, branded KidsProtect, is an Android Remote Access Trojan (RAT) that, once installed on a target device, operates entirely in the background without the owner’s knowledge. From a web-based dashboard, an operator can secretly record calls, stream live audio from the device’s microphone, track GPS location in real time, read SMS messages and notifications from apps including WhatsApp and Viber, log keystrokes, access contacts and photos, and remotely trigger the front and rear cameras.
Crucially, the app’s website instructs users to “disable Google Play Protect” before installing the APK — a significant red flag. Play Protect is Android’s built-in malware scanner; disabling it is a prerequisite for installing software that would otherwise be detected and blocked.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware/stalkerware sold openly online as a purported parental monitoring app. It operates stealthily in the background, abuses Accessibility Service, collects extensive device data, can intercept on-screen content and passwords, persists across reboots, resists removal via Device Administrator privileges, and is offered through a white-label reseller model.
Android surveillance malware/stalkerware that provides covert remote access and monitoring of a victim device, including call recording, live microphone streaming, GPS tracking, SMS and notification interception, keylogging, camera access, screen viewing, persistence across reboot, and anti-uninstall via Device Administrator abuse.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.