ESET Research reported 158 security and privacy flaws across 58 of 86 analyzed Android stalkerware applications from 86 vendors, warning that the weaknesses could expose both victims and operators to compromise. According to the report, the issues could allow third parties to intercept stolen data, hijack stalker accounts, fabricate uploaded evidence, remotely control monitored devices, and in some cases achieve remote code execution. ESET also said telemetry showed stalkerware use was increasing, with many products presenting themselves as child- or employee-monitoring tools while remaining hidden from victims.
The most common problems included transmission of sensitive data over insecure HTTP, storage of sensitive files on external media, unauthenticated exposure of victim or operator data from backend servers, and weak authorization controls in mobile apps and web-based admin panels. ESET said it began coordinated disclosure under a 90-day policy on December 19, 2020, but only a small minority of vendors had fixed the reported issues by the time of publication, underscoring persistent risks in an ecosystem already associated with covert surveillance and abuse.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
ESET Research published a white paper describing its analysis of 86 Android stalkerware apps from 86 vendors and 158 security and privacy issues across 58 of them. The report said the flaws could enable interception of victim data, takeover of stalker accounts, fabricated uploads, remote control of victim devices, and possible remote code execution.
ESET started coordinated vulnerability disclosure to affected Android stalkerware vendors under a 90-day policy, making up to three notification attempts per vendor. The disclosure covered serious security and privacy flaws found across dozens of products.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.