logo

New EagleMsgSpy Android spyware used by Chinese police, researchers say

ID: e7cf4cf5-3968-5b4c-acbb-0c94f179b9db

STIX ID: report--e7cf4cf5-3968-5b4c-acbb-0c94f179b9db

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-11

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Lookout researchers uncovered EagleMsgSpy, a powerful Android surveillanceware active since at least 2017 and attributed to Wuhan Chinasoft Token Information Technology and likely operated by Chinese public security bureaus. The spyware, apparently installed manually on seized/unlocked devices, can exfiltrate chat messages, call logs, SMS, contacts, location data, screenshots, screen recordings, audio, browser data and files; researchers linked samples to the developer through code, encryption strings, admin panel screenshots and C2 domain/IP overlaps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.