BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//JA8RSF
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251020T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Inside the Stalkerware Factory: Reversing C2 Protocols and Buildin
 g Mock Servers for Three Commercial Stalkerware Families - Sébastien Lari
 nier
DTSTART;TZID=Europe/Luxembourg:20261020T101500
DTEND;TZID=Europe/Luxembourg:20261020T104500
DTSTAMP:20261009T054102Z
UID:pretalx-hack-lu-2026-JA8RSF@pretalx.com
DESCRIPTION:Commercial stalkerware—apps marketed as "parental control" o
 r "employee monitoring" tools—are a primary digital weapon in intimate p
 artner violence (IPV). Despite their prevalence\, their internals remain u
 nder-documented: most research focuses on detection or prevalence studies
 \, while the actual C2 protocols\, crypto implementations\, and evasion te
 chniques stay in vendor black boxes.\n \nWe selected three major commercia
 l stalkerware families that offer a free trial period (typically one week)
 \, giving us a legitimate window to obtain fresh APKs\, register test devi
 ces against the real C2 infrastructure\, and observe the full infection li
 fecycle—from installation wizard to live data exfiltration—before divi
 ng into static and dynamic reverse engineering with JADX\, Frida\, and Cor
 ellium:\n \n- **Hoverwatch / Snoopza** (Refog Inc.): a single codebase com
 piled into two brands via Gradle build variants. We decrypted all DES/ECB-
 obfuscated strings (hardcoded key: 8 bytes derived from `"val"` + padding)
 \, extracted six C2 domains seeded in-binary\, discovered a `"refog"` attr
 ibution canary hidden in the HTTP client's static initializer\, identified
  YouTube Kids deliberately concealed via encryption among 100+ surveillanc
 e targets\, reverse-engineered the full multipart exfiltration protocol\, 
 built a functional mock C2 server (FastAPI)\, and demonstrated live data e
 xfiltration on Corellium. We also uncovered a cross-install device fingerp
 rinting mechanism persisting the Android ID on shared storage (`/sdcard/de
 v_<model>`) to track devices across reinstalls—a post-uninstall forensic
  IOC.\n- **Mobile Tracker Free**: a two-stage infection chain (dropper + p
 ayload) with 60+ Firebase Cloud Messaging commands\, WebRTC live video/aud
 io/screen streaming\, a remote file explorer\, three camera capture servic
 es\, a Device Admin-based anti-uninstall\, and a secret dialer code (`*123
 4*`) for hidden access. The payload masquerades as "Wi-Fi Service" and sup
 ports remote device wipe.\n- **iKeyMonitor**: REST + WebSocket (XML-encaps
 ulated) dual C2 channels\, RTMP screen mirroring with hardcoded signing se
 crets\, Triple DES authentication with embedded keys\, and distinctive `uo
 load` typos in four API endpoints serving as accidental network fingerprin
 ts. The app impersonates Samsung system packages and uses ProcessPhoenix f
 or crash-resilient persistence.\nFor each family\, we produced: (1) a comp
 lete C2 protocol specification\, (2) a working mock C2 server enabling dyn
 amic analysis without connecting to the real infrastructure\, (3) network 
 IOCs (domains\, User-Agents\, endpoint patterns) with ready-to-deploy Suri
 cata signatures\, (4) host-based IOCs (package names\, filesystem artifact
 s\, SharedPreferences keys)\, and (5) forensic triage checklists for CSIRT
  teams and victim-support organizations.\n \nKey cross-cutting findings in
 clude: universal absence of certificate pinning (enabling trivial MITM for
  analysis and victim protection)\, symmetric crypto with hardcoded keys (D
 ES\, 3DES)\, deliberately hidden surveillance of children's apps\, and rem
 ote kill switches that let operators destroy evidence before forensic acqu
 isition.\n \nAll mock C2 servers and IOCs will be released as open-source 
 tools
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/JA8RSF/
END:VEVENT
END:VCALENDAR
