Inside the Stalkerware Factory: Reversing C2 Protocols and Building Mock Servers for Three Commercial Stalkerware Families
Commercial stalkerware—apps marketed as "parental control" or "employee monitoring" tools—are a primary digital weapon in intimate partner violence (IPV). Despite their prevalence, their internals remain under-documented: most research focuses on detection or prevalence studies, while the actual C2 protocols, crypto implementations, and evasion techniques stay in vendor black boxes.
We selected three major commercial stalkerware families that offer a free trial period (typically one week), giving us a legitimate window to obtain fresh APKs, register test devices against the real C2 infrastructure, and observe the full infection lifecycle—from installation wizard to live data exfiltration—before diving into static and dynamic reverse engineering with JADX, Frida, and Corellium:
- Hoverwatch / Snoopza (Refog Inc.): a single codebase compiled into two brands via Gradle build variants. We decrypted all DES/ECB-obfuscated strings (hardcoded key: 8 bytes derived from
"val"+ padding), extracted six C2 domains seeded in-binary, discovered a"refog"attribution canary hidden in the HTTP client's static initializer, identified YouTube Kids deliberately concealed via encryption among 100+ surveillance targets, reverse-engineered the full multipart exfiltration protocol, built a functional mock C2 server (FastAPI), and demonstrated live data exfiltration on Corellium. We also uncovered a cross-install device fingerprinting mechanism persisting the Android ID on shared storage (/sdcard/dev_<model>) to track devices across reinstalls—a post-uninstall forensic IOC. - Mobile Tracker Free: a two-stage infection chain (dropper + payload) with 60+ Firebase Cloud Messaging commands, WebRTC live video/audio/screen streaming, a remote file explorer, three camera capture services, a Device Admin-based anti-uninstall, and a secret dialer code (
*1234*) for hidden access. The payload masquerades as "Wi-Fi Service" and supports remote device wipe. - iKeyMonitor: REST + WebSocket (XML-encapsulated) dual C2 channels, RTMP screen mirroring with hardcoded signing secrets, Triple DES authentication with embedded keys, and distinctive
uoloadtypos in four API endpoints serving as accidental network fingerprints. The app impersonates Samsung system packages and uses ProcessPhoenix for crash-resilient persistence.
For each family, we produced: (1) a complete C2 protocol specification, (2) a working mock C2 server enabling dynamic analysis without connecting to the real infrastructure, (3) network IOCs (domains, User-Agents, endpoint patterns) with ready-to-deploy Suricata signatures, (4) host-based IOCs (package names, filesystem artifacts, SharedPreferences keys), and (5) forensic triage checklists for CSIRT teams and victim-support organizations.
Key cross-cutting findings include: universal absence of certificate pinning (enabling trivial MITM for analysis and victim protection), symmetric crypto with hardcoded keys (DES, 3DES), deliberately hidden surveillance of children's apps, and remote kill switches that let operators destroy evidence before forensic acquisition.
All mock C2 servers and IOCs will be released as open-source tools
his talk presents a deep comparative reverse engineering of three commercial stalkerware families—Hoverwatch/Snoopza, Mobile Tracker Free, and iKeyMonitor—at the C2 protocol level. For each family, we fully reversed the command-and-control protocol, built a working mock C2 server, and produced actionable IOCs.
Talk outline:
- Context & motivation — Stalkerware as an IPV weapon; the gap between detection research and protocol-level understanding; why reversing the C2 matters for forensics and victim protection.
- Methodology — Sample selection via free trial periods; toolchain (JADX MCP, Frida, Corellium); the static-to-dynamic pipeline from string decryption to live traffic interception.
- Hoverwatch / Snoopza deep dive — Multi-brand architecture via Gradle build variants; DES/ECB crypto with a hardcoded key; the
"refog"binary attribution canary; YouTube Kids deliberately hidden among 100+ surveillance targets; 8-disguise camouflage system; cross-install device fingerprinting via/sdcard/dev_<model>; live demo of mock C2 capturing exfiltrated data. - Mobile Tracker Free & iKeyMonitor highlights — MTF's two-stage dropper kill chain, 60+ FCM commands, and WebRTC live streaming; iKeyMonitor's WebSocket XML protocol, RTMP screen mirroring, and
uoloadtypo as an accidental IOC. Comparative capability matrix. - IOCs & detection — Network signatures (Suricata rules, User-Agent patterns, C2 domains); host artifacts (filesystem traces, SharedPreferences, post-uninstall remnants); crypto weaknesses as detection vectors. Contributions to stalkerware-indicators.
- Forensic implications for victims — What data has already been stolen before discovery; triage checklist for CSIRTs and support organizations; kill switch risks; post-uninstall IOCs.
- Conclusion & open-source release — Mock C2 servers, IOC feeds, and Suricata signatures released as open-source tools.
Stuff released with the talk: mock C2 servers (FastAPI), Suricata signatures, YARA rules, host/network IOC lists, forensic triage checklists.
Sébastien Larinier began his career in SOC teams working on intrusion detection and founded the CERT Sekoia. Now a lecturer-researcher at ESIEA and an independent Cyber Threat Intelligence consultant, he contributes to several open-source projects such as MISP and Yeti. He is also the author of numerous articles, an international conference speaker, and teaches malware analysis, digital forensics, and Cyber Threat Intelligence at ESIEA while pursuing his PhD about the stalkerware at LORIA. He is co-author of Cybersécurité and Malware, published by Éditions ENI.