TheTruthSpy stalkerware, still insecure, still leaking data
ID: 51db1288-6eeb-5697-8d61-d9cfbefe238c
STIX ID: report--51db1288-6eeb-5697-8d61-d9cfbefe238c
Feed Name: Malwarebytes Blog
Threat Score
Malwarebytes reports that the stalkerware app TheTruthSpy (and numerous clones) continues to collect highly sensitive data and remains vulnerable to an unpatched IDOR (CVE-2022-0732). Research and hacker groups recently re-discovered and exploited this flaw, exposing victim data (including device IMEIs and photos) across multiple regions; the article warns users, lists affected clone apps, and provides detection/removal guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
