A security flaw in Catwatchful, an Android spyware disguised as a parental control app, exposed the credentials of more than 62,000 customer accounts, according to security researcher Eric Daigle.
See also: Android spyware targets Russian military

The surveillance app in question allows users to view the contents of the victim's device in real time, activate the microphone and cameras, as well as access photos, videos, chat logs, and location data .
Catwatchful essentially functions as powerful spyware or stalkware, running in the background for constant monitoring and hiding its presence so that it cannot be uninstalled by the victim. In fact, while it is advertised as a parental control app for Android, its creators make it clear that it is undetectable.
As explains , Catwatchful works as advertised: it stays hidden on victims' devices, uploads content to a database , and allows registered users to access it through an online dashboard.
See also: North Korean hackers "uploaded" spyware to Google Play
Upon registration, users receive an APK file pre-populated with their credentials, which requires physical access to the device to install. Once installed and running, the spyware activates real-time monitoring capabilities.

By investigating the spyware's functionality, the security researcher discovered that it was vulnerable to SQL Injection attacks and that it was possible to retrieve the Firebase database—which contained personal information—through the user dashboard.
As Daigle explains, the leaked file contained in plain text the usernames and passwords of all 62,050 Catwatchful accounts, as well as information linking the accounts to specific devices and administrative data.
According to the researcher, the exposed data can be used to fully access and take over any account on the service.
See also: Amazon Appstore: Android spyware was disguised as a health app
In response to the findings, Google enhanced Play Protect to notify users when Catwatchful is detected on their device. The company that hosted the Catwatchful API suspended the account, but the API was moved to another provider.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
