Hack.lu 2026

Sébastien Larinier

Sébastien Larinier began his career in SOC teams working on intrusion detection and founded the CERT Sekoia. Now a lecturer-researcher at ESIEA and an independent Cyber Threat Intelligence consultant, he contributes to several open-source projects such as MISP and Yeti. He is also the author of numerous articles, an international conference speaker, and teaches malware analysis, digital forensics, and Cyber Threat Intelligence at ESIEA while pursuing his PhD about the stalkerware at LORIA. He is co-author of Cybersécurité and Malware, published by Éditions ENI.


Session

10-20
10:15
30min
Inside the Stalkerware Factory: Reversing C2 Protocols and Building Mock Servers for Three Commercial Stalkerware Families
Sébastien Larinier

Commercial stalkerware—apps marketed as "parental control" or "employee monitoring" tools—are a primary digital weapon in intimate partner violence (IPV). Despite their prevalence, their internals remain under-documented: most research focuses on detection or prevalence studies, while the actual C2 protocols, crypto implementations, and evasion techniques stay in vendor black boxes.

We selected three major commercial stalkerware families that offer a free trial period (typically one week), giving us a legitimate window to obtain fresh APKs, register test devices against the real C2 infrastructure, and observe the full infection lifecycle—from installation wizard to live data exfiltration—before diving into static and dynamic reverse engineering with JADX, Frida, and Corellium:

  • Hoverwatch / Snoopza (Refog Inc.): a single codebase compiled into two brands via Gradle build variants. We decrypted all DES/ECB-obfuscated strings (hardcoded key: 8 bytes derived from "val" + padding), extracted six C2 domains seeded in-binary, discovered a "refog" attribution canary hidden in the HTTP client's static initializer, identified YouTube Kids deliberately concealed via encryption among 100+ surveillance targets, reverse-engineered the full multipart exfiltration protocol, built a functional mock C2 server (FastAPI), and demonstrated live data exfiltration on Corellium. We also uncovered a cross-install device fingerprinting mechanism persisting the Android ID on shared storage (/sdcard/dev_<model>) to track devices across reinstalls—a post-uninstall forensic IOC.
  • Mobile Tracker Free: a two-stage infection chain (dropper + payload) with 60+ Firebase Cloud Messaging commands, WebRTC live video/audio/screen streaming, a remote file explorer, three camera capture services, a Device Admin-based anti-uninstall, and a secret dialer code (*1234*) for hidden access. The payload masquerades as "Wi-Fi Service" and supports remote device wipe.
  • iKeyMonitor: REST + WebSocket (XML-encapsulated) dual C2 channels, RTMP screen mirroring with hardcoded signing secrets, Triple DES authentication with embedded keys, and distinctive uoload typos in four API endpoints serving as accidental network fingerprints. The app impersonates Samsung system packages and uses ProcessPhoenix for crash-resilient persistence.
    For each family, we produced: (1) a complete C2 protocol specification, (2) a working mock C2 server enabling dynamic analysis without connecting to the real infrastructure, (3) network IOCs (domains, User-Agents, endpoint patterns) with ready-to-deploy Suricata signatures, (4) host-based IOCs (package names, filesystem artifacts, SharedPreferences keys), and (5) forensic triage checklists for CSIRT teams and victim-support organizations.

Key cross-cutting findings include: universal absence of certificate pinning (enabling trivial MITM for analysis and victim protection), symmetric crypto with hardcoded keys (DES, 3DES), deliberately hidden surveillance of children's apps, and remote kill switches that let operators destroy evidence before forensic acquisition.

All mock C2 servers and IOCs will be released as open-source tools

topic: hack.lu
Europe