AssoEchap / stalkerware-indicators

Indicators of stalkerware apps
258 stars 42 forks source link

Stalkerware Indicators of Compromise

Indicators of compromise (IOC) for Stalkerware and Watchware applications for Android and iOS

Warning: these indicators are not providing a complete detection of stalkerware applications. They are based on research from a few people on their free time and many apps are likely missing. Use it carefully. No detection based on these indicators should not be understood as having no stalkerware installed.

If you think you may be victim of a stalkerware application, check this page

This repository is maintained by Julien Voisin, and Tek for the Echap non-profit organisation.

What's a stalkerware?

We're using the definition of the Coalition Against Stalkerware:

Stalkerware refers to tools – software programs, apps and devices – that enable someone to secretly spy on another person’s private life via their mobile device. The abuser can remotely monitor the whole device including web searches, geolocation, text messages, photos, voice calls and much more. Such programs are easy to buy and install. They run hidden in the background, without the affected person knowing or giving their consent. Regardless of stalkerware’s availability, the abuser is accountable for using it as a tool and hence for committing this crime.

We are classifying as watchware any application that is developed for surveillance and is not trying to hide its activity (like a child monitoring application).

IOC

Main files:

Files generated automatically from previous Stalkerware IOC files:

Stalkerware

This repository includes indicators for 167 applications (141 stalkerware and 26 watchware) and 2976 samples

List of stalkerware apps:

Notable users

Contributions

Contributors include:

These indicators are largely based on research and analysis using APKlab, Koodous and VirusTotal.

Please Contribute

This repository is not complete, new stalkerware apps appear and disappear all the time. Feel free to contribute to this database by opening an issue or submitting a Pull Request.

If you want to contribute, fork this repository, make your changes into the branch research and submit a Pull Request. Once merged, a GitHub Action will automatically generate the different files available on the master branch.

If you want to do further research on some apps and need access to the samples, feel free to send us an email at contact AT echap.eu.org.

Other stalkerware repositories

There are other repositories gathering stalkerware indicators:

References

License

The content of this repository is licensed under CC-BY. If this license is a problem for you, please reach out (contact AT echap.eu.org), we are happy to figure something out.

Please note that while we're doing our very best, there is no guarantee that it is accurate. If it is useful to you, consider giving money to an organisation supporting violence against women in your country.