{"id":24573,"date":"2024-05-28T13:10:07","date_gmt":"2024-05-28T21:10:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/05\/28\/news-18303\/"},"modified":"2024-05-28T13:10:07","modified_gmt":"2024-05-28T21:10:07","slug":"news-18303","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/05\/28\/news-18303\/","title":{"rendered":"pcTattleTale spyware leaks database containing victim screenshots, gets website defaced"},"content":{"rendered":"\n<p>The idea behind the software is simple. When the spying party installs the stalkerware, they grant permission to record what happens on the targeted Android or Windows device. The observer can then log in on an online portal and activate recording, at which point a screen capture is taken on the target&#8217;s device.<\/p>\n<p>What goes around comes around, you might say. As you may have read many times before on our blog, some spyware companies have a surprisingly low standard of security .<\/p>\n<p>In 2021, we <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2021\/09\/phone-screenshots-accidentally-leaked-online-by-stalkerware-company\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> that \u201cemployee and child-monitoring\u201d software vendor pcTattleTale hadn\u2019t been very careful about securing the screenshots it sneakily took from its victims\u2019 phones. A <a href=\"https:\/\/x.com\/LukasStefanko\/status\/1441012690827231244\">security researcher<\/a> found an issue while using a trial version of pcTattleTale, noticing that the company uploaded the screenshots to an unsecured online database (meaning anyone could view the screenshots as they weren&#8217;t protected by any form of authentication\u2014such as a user name and password).<\/p>\n<p>Last week another security researcher, Eric Daigle, <a href=\"https:\/\/www.ericdaigle.ca\/pctattletale-leaking-screen-captures\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">found<\/a> the company appears to have learned nothing from its previous security issue. Daigle found that pcTattleTale&#8217;s Application Programming Interface (API) allows any attacker to access the most recent screen capture recorded from any device on which the spyware is installed. Despite repeated warnings from Daigle and others, no improvements were made. <\/p>\n<p>Then, yet another researcher found yet another bug in pcTattletale which allowed them to gain full access to the backend infrastructure. This allowed them to deface the website and steal the AWS credentials which turned out to be the same for all devices. Amazon has now locked pcTattletale&#8217;s entire AWS infrastructure.<\/p>\n<p>After a quick sweep, stalkerware researcher, Maia Crimew <a href=\"https:\/\/maia.crimew.gay\/posts\/fuckstalkerware-6\/\">stated<\/a>:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cpcTattletale currently holds over 17 terabytes of victim device screenshots (upwards of 300 million of them from over 10 thousand devices), with some of them dating back to 2018.\u201d<\/p>\n<\/blockquote>\n<p>According to&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/10\/gen-z-fears-physical-violence-from-being-online-more-than-anyone-else-malwarebytes-finds\">2023 research from Malwarebytes<\/a>, 62 percent of people in the United States and Canada admitted to monitoring their romantic partners online in one form or another, from looking through a spouse\u2019s or significant other\u2019s text messages, to tracking their location, to rifling through their search history, to even installing monitoring software onto their devices.<\/p>\n<p>Given the <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/02\/thetruthspy-stalkerware-still-insecure-still-leaking-data\">low security of the apps available<\/a> to home users, this is extremely concerning. Installing monitoring software is not just a huge invasion of privacy, there is a big chance that it will backfire. <\/p>\n<h2 class=\"wp-block-heading\" id=\"h-removing-stalkerware\">Removing stalkerware<\/h2>\n<p>Malwarebytes, as one of the founding members of the&nbsp;<a href=\"https:\/\/stopstalkerware.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Coalition Against Stalkerware<\/a>, makes it a priority to detect and remove stalkerware-type apps from your device. It is good to keep in mind however that by removing the stalkerware-type app you will alert the person spying on you that you know the app is there.<\/p>\n<p>Because the apps install under a different name and hide themselves from the user, it can be hard to find and remove them.\u00a0That is where\u00a0<a href=\"https:\/\/www.malwarebytes.com\/premium\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes<\/a>\u00a0can help you.<\/p>\n<ol start=\"1\">\n<li>Open your Malwarebytes dashboard<\/li>\n<li>Tap&nbsp;<strong>Scan<\/strong>&nbsp;<strong>now<\/strong><\/li>\n<li>It may take a few minutes to scan your device.<\/li>\n<\/ol>\n<p>&nbsp;If malware is detected you can act on it in the following ways:<\/p>\n<ul>\n<li><strong>Uninstall<\/strong>. The threat will be deleted from your device.<\/li>\n<li><strong>Ignore Always<\/strong>. The file detection will be added to the Allow List, and excluded from future scans. Legitimate files are sometimes detected as malware. We recommend reviewing scan results and adding files to Ignore Always that you know are safe and want to keep.<\/li>\n<li><strong>Ignore Once<\/strong>: A file has been detected as a threat, but you are not sure whether to add it to your Allow List or delete. This option will ignore the detection this time only. It will be detected as malware on your next scan.<\/li>\n<\/ul>\n<p>On Windows machines Malwarebytes detects pcTattleTale as PUP.Optional.PCTattletale.<\/p>\n<hr class=\"wp-block-separator alignfull has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don\u2019t just report on phone security\u2014we provide it<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by\u00a0<a href=\"https:\/\/www.malwarebytes.com\/ios\">downloading Malwarebytes for iOS<\/a>, and <a href=\"https:\/\/www.malwarebytes.com\/android\">Malwarebytes for Android<\/a> today.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/05\/pctattletale-spyware-leaks-database-containing-victim-screenshots-gets-website-defaced\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Stalkerware app pcTattleWare had its websites defaced and databases leaked after researchers found several security flaws. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10462,32,31465,19409],"class_list":["post-24573","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-android","tag-news","tag-pctattletale","tag-stalkerware"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24573"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24573\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}