logo
Stealth app Catwatchful caught spying on thousands of phones, leak reveals emails, passwords and its own admin

Stealth app Catwatchful caught spying on thousands of phones, leak reveals emails, passwords and its own admin

India Today03-07-2025
A stealth app called Catwatchful has allegedly been caught in its own trap after a major security flaw exposed sensitive data of both its users and victims. The app, which disguises itself as a child-monitoring tool, has been silently stealing data from thousands of Android phones – including photos, messages, location details, and even live audio from microphones and cameras. But a newly discovered vulnerability has turned the tables. advertisementCanadian security researcher Eric Daigle found that Catwatchful's database was completely exposed online due to a misconfigured, unauthenticated API. This meant that anyone could access sensitive data, including the email addresses and plain-text passwords of over 62,000 customers, along with private phone data from more than 26,000 victims. The majority of affected devices were located in countries like India, Mexico, Colombia, Peru, Argentina, Ecuador, and Bolivia. The exposed data includes records stretching back as early as 2018. In a blog post, Daigle explained that Catwatchful operates by being manually installed on a victim's device by someone with physical access – often a romantic partner or family member – making it a form of stalkerware.
Daigle's investigation also revealed that Catwatchful used Google Firebase to host stolen data, like users' photos and real-time audio recordings. Upon being alerted, Google said it had added Catwatchful to its Play Protect tool to warn Android users of the spyware. advertisementThe breach didn't just expose victims, it also revealed the identity of Catwatchful's operator. The developer behind the spyware was identified as Omar Soca Charcov, a software engineer residing in Uruguay, according to a report by TechCrunch. Charcov's details, including his personal email, phone number, and even the Firebase web address used to store stolen data, were found in the database. Charcov's LinkedIn profile used the same email address found in the spyware data, as per the report. He reportedly also linked his personal email account to the administrator account for Catwatchful, making it easy to trace him as the operator. Following the discovery, Daigle informed the hosting provider for Catwatchful's API, which briefly suspended the spyware's services. However, the API later returned via HostGator. Google is apparently reviewing whether Catwatchful violated its Firebase terms, but at the time of writing the story, the app's database remains online.- Ends
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

India, US seek to futureproof trade agreement amid tax and tariff concerns
India, US seek to futureproof trade agreement amid tax and tariff concerns

Business Standard

timean hour ago

  • Business Standard

India, US seek to futureproof trade agreement amid tax and tariff concerns

Starting April 1, India abolished the 6 per cent equalisation levy on online advertising services provided by non-resident entities, also known as Google tax premium Asit Ranjan Mishra Listen to This Article The US is pressing India to commit to not reintroducing the so-called 'Google tax', while New Delhi is seeking protection from potential future tariffs on pharmaceutical exports as part of the ongoing trade-deal negotiations. Starting April 1, India abolished the 6 per cent equalisation levy on online advertising services provided by non-resident entities, also known as Google tax. The move, announced in March, was aimed at sending a positive signal to US President Donald Trump, who had threatened reciprocal tariffs on high-tariff nations. Apart from Google, the decision also benefited other US-based tech majors, such as Meta and X (formerly

Defamation Case: Sacked AGM goes on LinkedIn rant, booked, Hr News, ETHRWorld
Defamation Case: Sacked AGM goes on LinkedIn rant, booked, Hr News, ETHRWorld

Time of India

time2 hours ago

  • Time of India

Defamation Case: Sacked AGM goes on LinkedIn rant, booked, Hr News, ETHRWorld

Advt Join the community of 2M+ industry professionals. Subscribe to Newsletter to get latest insights & analysis in your inbox. All about ETHRWorld industry right on your smartphone! Download the ETHRWorld App and get the Realtime updates and Save your favourite articles. Surat: A recently terminated assistant general manager of Surat-based green energy firm KP Group has been booked for defamation and criminal intimidation after he allegedly abused and threatened the company and its employees on accused, Ashish Gupta , was employed with KP Group's subsidiary, KPI Green Energy Ltd, on June 16 but was relieved from his duties on July 5 due to unsatisfactory performance. According to the FIR filed by company representative Manoj Shahu, Gupta's technical knowledge and work output were found lacking, prompting management to terminate his services just 20 days into his after his dismissal, Gupta allegedly took to LinkedIn and posted defamatory content targeting the company and its staff. He was also accused of using abusive language and tagging the company in multiple the company's HR head contacted him to address the matter, Gupta reportedly became aggressive and issued threats. According to the complaint, he warned that any employee who stood in his way would be 'killed' and demanded to be July 9, Gupta allegedly posted three more defamatory messages on LinkedIn, claiming KP Group owed him Rs 10 lakh and continuing his verbal attacks on the company's personnel. The company clarified that it had already credited Rs 4.54 lakh into Gupta's bank account, which included salary for 20 days, one month's advance salary, and reimbursement for hotel police have registered a case against Gupta under Sections 365(2) and 351(3) of the Bharatiya Nyaya Sanhita (BNS) for defamation and criminal intimidation. An investigation has been initiated.

WhatsApp to show ads in status and promote channels in new Beta update
WhatsApp to show ads in status and promote channels in new Beta update

Time of India

time2 hours ago

  • Time of India

WhatsApp to show ads in status and promote channels in new Beta update

Meta is taking a big step to make money from WhatsApp by testing new ad features and in its latest Android beta update (version 2.25.21.11), the messaging platform has introduced two new tools - ' Status Ads ' and ' Promoted Channels '. These features are now available to select beta users on Android, according to WABetaInfo. Status Ads are similar to the ads you see on Instagram Stories. Business accounts can now post sponsored content that will appear in users' Status feeds. These ads will show up between updates from friends and family but will have a clear "sponsored" label, so users can easily tell them apart from personal posts. WhatsApp is also giving users control over what they see. If someone doesn't want to see ads from a particular advertiser, they can block them, and those ads won't appear again. The second feature, Promoted Channels, will help public channels become more visible in WhatsApp's channel directory. Just like Status Ads, these promoted channels will be marked as "sponsored". When a business or creator pays to promote their channel, it will appear higher in search results, making it easier for users to find and follow them. These changes could be very useful for brands, creators, and organisations who want to grow their audience quickly. It also signals WhatsApp's serious entry into the world of advertising and creator monetisation -- something already common on platforms like Instagram and YouTube. Meta has assured that these ads won't affect users' privacy. The company says all promotional content will only be shown in public areas like Status and Channels, not in private chats. So, your personal messages will remain ad-free. Earlier, in a previous beta update (2.25.19.15), WhatsApp also started testing a feature that lets users download detailed ad activity reports. These reports show which ads were displayed, who the advertisers were, and when the ads were seen. This adds more transparency compared to traditional ad platforms

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store