HomeSecurityAndroid spyware Catwatchful leaks 62,000 user logins

Android spyware Catwatchful leaks 62,000 user logins

A security flaw in Catwatchful, an Android spyware disguised as a parental control app, exposed the credentials of more than 62,000 customer accounts, according to security researcher Eric Daigle.

See also: Android spyware targets Russian military

Catwatchful spyware

The surveillance app in question allows users to view the contents of the victim's device in real time, activate the microphone and cameras, as well as access photos, videos, chat logs, and location data .

Catwatchful essentially functions as powerful spyware or stalkware, running in the background for constant monitoring and hiding its presence so that it cannot be uninstalled by the victim. In fact, while it is advertised as a parental control app for Android, its creators make it clear that it is undetectable.

As explains , Catwatchful works as advertised: it stays hidden on victims' devices, uploads content to a database , and allows registered users to access it through an online dashboard.

See also: North Korean hackers "uploaded" spyware to Google Play

Upon registration, users receive an APK file pre-populated with their credentials, which requires physical access to the device to install. Once installed and running, the spyware activates real-time monitoring capabilities.

Android spyware Catwatchful leaks 62,000 user logins
Android spyware Catwatchful leaks 62,000 user logins

By investigating the spyware's functionality, the security researcher discovered that it was vulnerable to SQL Injection attacks and that it was possible to retrieve the Firebase database—which contained personal information—through the user dashboard.

As Daigle explains, the leaked file contained in plain text the usernames and passwords of all 62,050 Catwatchful accounts, as well as information linking the accounts to specific devices and administrative data.

According to the researcher, the exposed data can be used to fully access and take over any account on the service.

See also: Amazon Appstore: Android spyware was disguised as a health app

In response to the findings, Google enhanced Play Protect to notify users when Catwatchful is detected on their device. The company that hosted the Catwatchful API suspended the account, but the API was moved to another provider.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS