About Me

Jimmy Shah

Jimmy Shah
Jimmy Shah is a Mobile Security Researcher for McAfee, specializing in analysis of mobile threats on existing ...

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Shopping for spyware

Wednesday, November 7, 2007 at 6:24am by Jimmy Shah
Jimmy Shah

People will sell you almost anything for your mobile on eBay, headsets, cases, replacement power adapters. Recently while looking for a data cable for a phone I ran across mobile “spying” software for sale.

We’ve run across relatively expensive commercial mobile spyware before. This was being offered at a tenth of the price with a lot of similar features. The software claims to allow:

  • call monitoring
  • reading text messages
  • copying phonebook entries
Figure 1
Fig 1 – Capabilities claimed by the software

Other claims of compatibility with and control of a wide range of phones may just be hype on the part of the seller. Some of the sellers suggest that buyers install the software on phones and offer them as gifts or for sale to the unsuspecting. It’s interesting that dozens of sellers were offering nearly identical software. This is usually an indication that the item being auctioned comes from a common source. Buyers should be wary of such auctions.

eBay will take down auctions with objectionable or malicious content if requested. Some auctions may not actually break the rules or just come very close to the line.

Sellers will sometimes repackage publicly available information or open source software and set up an auction with terms like “Brand New” or “latest Pro version” in order to convince buyers that they’re getting a good value. There are also sellers offering CDs full of J2ME games. The prices for those collections imply that the included games are either freely available or pirated.

The cost of the software might be attractive, but none of the sellers offer any support. If it won’t run on your phone, there are no refunds. Even when the software is delivered on CD, no replacements are offered if its damaged in the mail. Occasionally pirated software is also sold in this manner. A number of the spying software auctions are actually selling links to download the software.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (1)

  • Brad Antoniewicz November 7, 2007 7:04AM

    Nice Post! It brings to mind a talk Corey Benninger recently gave at the NYNJMetro OWASP meeting about mobile phone security,
    he was showing how this type of software is becoming more and more available. He specifically used FlexiSPY (http://www.flexispy.com/) as an example, pointing out the “Catch Cheating Spouses” marketing campaign that seems to be constant across these types of commercial spyware and that the interesting thing is that these types of software are getting valid certificates which is provided by the mobile phone OS vendor!