Security

Hacked phone spyware shuts down… again

Comment

spyware illustrated; blank smartphone screen over a pink background of multiple eyes
Image Credits: Bryce Durbin / TechCrunch

A short-lived spyware operation called Oospy, which emerged earlier this year after its predecessor Spyhide was hacked, is no longer operational and has shut down.

Oospy appeared online in late July as a rebrand of a phone monitoring app called Spyhide, which was facilitating the surveillance of tens of thousands of Android device owners around the world. Spyhide shut down after a breach exposed the operation and its administrators who were profiting from it.

Although Spyhide’s website disappeared from the internet after the hack burned the operation, the spyware’s back-end server stayed online and was still communicating with the tens of thousands of phones it was monitoring since the server was hosted on an entirely different domain. That allowed the administrators to rebrand Spyhide to Oospy without affecting the spyware operation itself.

That back-end server, which stored the victim’s stolen phone data from thousands of Android devices around the world, was taken offline Thursday by the web host Hetzner, which said the service violated its terms of service.

“In addition, we have terminated the customer’s server contract in due time,” Christian Fitz, a spokesperson for Hetzner, told TechCrunch.

In their time online, Spyhide and Oospy had at least 60,000 victims across the world, including thousands of victims in the United States. These stalkerware (also known as spouseware) apps are planted on a victim’s phone, often by someone with knowledge of their passcode. Once planted, these apps continually steal a victim’s contacts, messages, photos, call logs and recordings, and granular location history.

Following the Spyhide hack, TechCrunch identified two of the administrators behind Spyhide and Oospy. One of the administrators, Mohammad (also goes by Mojtaba) Arasteh, confirmed to TechCrunch that he worked on the project “several years ago as a programmer,” but denied involvement with Oospy.

But a mistake on Oospy’s checkout page, which used PayPal to process customer payments, exposed the name of the PayPal account holder, who shares the same family name as Arasteh.

It’s not uncommon for spyware operations to rely on payment services like PayPal to handle customer payments, despite PayPal’s policies broadly prohibiting customers from using its service to buy or sell software that facilitate illegal activity, like spyware. PayPal spokesperson Caitlin Girouard did not comment on the accounts when reached by TechCrunch. Oospy stopped accepting PayPal for payments a short time later, though it’s not known if PayPal took action against the account.

Arasteh did not comment on the PayPal account when contacted by TechCrunch. Soon after contacting Arasteh, Oospy’s website went offline altogether.

The shutdown of the spyware’s back-end server marks the end of Spyhide and Oospy’s ability to operate, for now.

Oospy and Spyhide are the latest phone surveillance operations to drop off the internet in recent months. Polish-made stalkerware LetMeSpy shut down after an earlier data breach in June. And last year, one of the largest known Android spyware apps, SpyTrac, disappeared following a TechCrunch investigation linked the spyware operation to Support King, which was banned from the surveillance industry by the FTC following an earlier data breach.

Spyhide stalkerware is spying on tens of thousands of phones

More TechCrunch

Apple Intelligence features are not available in the developer beta, which is available now.

Without Apple Intelligence, iOS 18 beta feels like a TV show that’s waiting for the finale

Apple released the public betas for its next generation of software on the iPhone, Mac, iPad, and Apple Watch on Monday. You can now test out iOS 18 and many…

Apple’s public betas for iOS 18 are here to test out

One major dissenter threatens to upend Fisker’s apparent best chance at offloading its unsold EVs, a deal that would keep the startup’s bankruptcy proceeding alive and pave the way for…

Fisker has one major objector to its Ocean SUV firesale

Payments giant Stripe has delayed going public for so long that its major investor Sequoia Capital is getting creative to offer returns to its limited partners. The venture firm emailed…

Major Stripe investor Sequoia confirms $70B valuation, offers its investors a payday

Alphabet, Google’s parent company, is in advanced talks to acquire Wiz for $23 billion, a person close to the company told TechCrunch. The deal discussions were previously reported by the…

Google’s Kurian approached Wiz, $23B deal could take a week to land, source says

Name That Bird determines individual members of a species by identifying distinguishing characteristics that most humans would be hard-pressed to spot.

Bird Buddy��s new AI feature lets people name and identify individual birds

YouTube Music is introducing two new ways to boost song discovery on its platform. YouTube announced on Monday that it’s experimenting with an AI-generated conversational radio feature, and rolling out…

YouTube Music is testing an AI-generated radio feature and adding a song recognition tool

Tesla had internally planned to build the dedicated robotaxi and the $25,000 car, often referred to as the Model 2, on the same platform.

Elon Musk confirms Tesla ‘robotaxi’ event delayed due to design change

What this means for the space industry is that theory has become reality: The possibility of designing a habitation within a lunar tunnel is a reasonable proposition.

Moon cave! Discovery could redirect lunar colony and startup plays

Get ready for a prime week of savings at TechCrunch Disrupt 2024 with the launch of Disrupt Deal Days! From now to July 19 at 11:59 p.m. PT, we’re going…

Disrupt Deal Days are here: Prime savings for TechCrunch Disrupt 2024!

Deezer is the latest music streaming app to introduce an AI playlist feature. The company announced on Monday that a select number of paid users will be able to create…

Deezer chases Spotify and Amazon Music with its own AI playlist generator

Real-time payments are becoming commonplace for individuals and businesses, but not yet for cross-border transactions. That’s what Caliza is hoping to change, starting with Latin America. Founded in 2021 by…

Caliza lands $8.5 million to bring real-time money transfers to Latin America using USDC

Adaptive is a platform that provides tools designed to simplify payments and accounting for general construction contractors.

Adaptive builds automation tools to speed up construction payments

When VanMoof declared bankruptcy last year, it left around 5,000 customers who had preordered e-bikes in the lurch. Now VanMoof is up and running under new management, and the company’s…

How VanMoof’s new owners plan to win over its old customers

Mitti Labs aims to transform rice farming in India and other South Asian markets by reducing methane emissions by 50% and water consumption by 30%.

Mitti Labs aims to make rice farming less harmful to the climate, starting in India

This is a guide on how to check whether someone compromised your online accounts.

How to tell if your online accounts have been hacked

There is a general consensus today that generative AI is going to transform business in a profound way, and companies and individuals who don’t get on board will be quickly…

The AI financial results paradox

Google’s parent company Alphabet might be on the verge of making its biggest acquisition ever. The Wall Street Journal reports that Alphabet is in advanced talks to acquire Wiz for…

Google reportedly in talks to acquire cloud security company Wiz for $23B

Featured Article

Hank Green reckons with the power — and the powerlessness — of the creator

Hank Green has had a while to think about how social media has changed us. He started making YouTube videos in 2007 with his brother, novelist John Green, at a time when the first iPhone was in development, Myspace was still relevant and Instagram didn’t exist. Seventeen years later, posting…

Hank Green reckons with the power — and the powerlessness — of the creator

Here is a timeline of Synapse’s troubles and the ongoing impact it is having on banking consumers. 

Synapse’s collapse has frozen nearly $160M from fintech users — here’s how it happened

Featured Article

Helixx wants to bring fast-food economics and Netflix pricing to EVs

When Helixx co-founder and CEO Steve Pegg looks at Daisy — the startup’s 3D-printed prototype delivery van — he sees a second chance. And he’s pulling inspiration from McDonald’s to get there.  The prototype, which made its global debut this week at the Goodwood Festival of Speed, is an interesting proof…

Helixx wants to bring fast-food economics and Netflix pricing to EVs

Featured Article

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

India is struggling to get new smartphone buyers, as millions of Indians don’t go for an upgrade and continue to be on feature phones.

India clings to cheap feature phones as brands struggle to tap new smartphone buyers

Roboticists at The Faboratory at Yale University have developed a way for soft robots to replicate some of the more unsettling things that animals and insects can accomplish — say,…

Meet the soft robots that can amputate limbs and fuse with other robots

Featured Article

If you’re an AT&T customer, your data has likely been stolen

This week, AT&T confirmed it will begin notifying around 110 million AT&T customers about a data breach that allowed cybercriminals to steal the phone records of “nearly all” of its customers. The stolen data contains phone numbers and AT&T records of calls and text messages during a six-month period in…

If you’re an AT&T customer, your data has likely been stolen

In the first half of 2024 alone, more than $35.5 billion was invested into AI startups globally.

Here’s the full list of 28 US AI startups that have raised $100M or more in 2024

Whistleblowers have accused OpenAI of placing illegal restrictions on how employees can communicate with government regulators, according to a letter obtained by The Washington Post. Lawyers representing anonymous whistleblowers sent…

Whistleblowers accuse OpenAI of ‘illegally restrictive’ NDAs

Business email compromise attacks are on the rise. Here’s how you can stay ahead of the hackers.

How to protect your startup from email scams

Featured Article

What exactly is an AI agent?

Regardless of how they’re defined, the agents are for helping complete tasks in an automated way with as little human interaction as possible.

What exactly is an AI agent?

Meta announced former President Donald Trump’s Facebook and Instagram accounts will no longer be subject to heightened suspension penalties, according to an updated blog post on Friday. The company says…

Meta removes special restrictions for Trump’s account ahead of 2024 elections

A Castro Valley resident was charged Thursday for allegedly slashing the tires of 17 Waymo robotaxis in San Francisco between June 24 and June 26, according to the city’s district…

Waymo cameras capture footage of person charged in alleged robotaxi tire slashings