logo

Why you shouldn't trust "safe" spying apps!

ID: 6887e1c4-6f2d-5d15-a1e8-e1a769295f70

STIX ID: report--6887e1c4-6f2d-5d15-a1e8-e1a769295f70

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ discovered SPYMIE, a malicious Android keylogger previously available on Google Play that leverages Accessibility Services to capture keystrokes and UI actions, hides itself behind a dialer-triggered PIN (default **00##**), writes sensitive data to SpyLogger.xml and logcat (insecure storage), and includes code to email collected data (including a hard-coded recipient). The app had 10,000+ installs, was removed from Google Play after reporting, and poses a significant privacy risk to users of infected or borrowed devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.