Commercial spyware: the invisible threat in your pocket
Commercial spyware — from nation-state tools to consumer stalkerware — can silently compromise mobile devices and expose sensitive data without any visible sign of infection. Learn more.
What is commercial spyware?
Commercial spyware refers to a software designed to monitor activity on mobile devices without the device owner’s knowledge. This software could collect data like
- Communication
- Location
- Contacts
- Files
Types of commercial spyware
Stalkerware: monitoring apps typically disguised as parental controls or tracking tools
Enterprise spyware: sophisticated surveillance tools sold to governments, intelligence agencies and large enterprises; capable of remote, zero-click installation exploiting zero-day vulnerabilities
Consumer-grade spyware: commodity surveillance tools sold cheaply to individual buyers via app stores and gray-market vendors; generally requires user interaction rather than zero-day exploits.
Trojan spyware: malware disguised as a legitimate application; once installed, it silently collects and transmits data without the user’s knowledge
Adware: software that tracks behavior and browsing habits primarily to serve targeted ads
Keyloggers: tools that record every keystroke made on a device, capturing passwords, messages and sensitive information
Banking trojans: specialized malware targeting financial credentials, intercepting banking sessions and capturing login details
Remote Access Trojans (RAT): the most invasive class with full remote control of infected devices, including live access to files, camera and microphone
Should businesses care about commercial spyware?
The threat of commercial spyware is no longer limited to high-profile political targets. A user in your organization can become a target, putting your employee and company data at risk.
Malwarebytes recorded a 147% increase in Android spyware detections in the first half of 2025, and its use has expanded with private intelligence contractors, corporate espionage operations targeting executives and R&D teams, and political sabotage campaigns.
During investigations, we regularly find these tools already installed and still looking entirely legitimate i.e., reachable, downloadable, plausibly there for a good reason. That is what makes them difficult to identify. Nothing marks the app as hostile, but it exposes the daily life of people have it installed including personal and professional information.
In government and defense, the targeting is far more deliberate. In August 2026, according to TechCrunch, Apple notified users in 110 countries that they had been targeted by mercenary spyware, among them a Ukrainian soldier who said he never thought he was important enough to target.
For organizations, the risk is real: a compromised mobile device can expose sensitive communications, credentials, internal documents and location data without any visible sign of infection.
Consumer-grade spyware in the wild
FlexiSPY
FlexiSPY is one of the most feature-rich commercial surveillance tools available, compatible with Android, iOS, Windows and macOS. It is designed to be covertly installed on a target device, running in the background to capture a wide range of data. Its capabilities include call recording, ambient environment recording, message monitoring across major platforms and remote access features. To evade detection, FlexiSPY hides its icon, disguises its processes under innocuous names, and encrypts captured data using AES and RSA.
Crocodilus
Crocodilus is an Android banking trojan first discovered in March 2025 that has quickly grown into one of the more technically sophisticated consumer threats on the mobile landscape. Once installed — typically through fake app downloads or malicious advertisements on social media — it requests Accessibility Services permissions, which grant it deep visibility into everything happening on the device. It then silently monitors which banking or cryptocurrency apps the user opens, instantly overlaying them with pixel-perfect fake login screens to capture credentials without the user suspecting anything is wrong. Beyond credential theft, Crocodilus employs a social engineering trick to steal cryptocurrency wallet seed phrases: it displays an urgent on-screen warning instructing the user to back up their wallet key within a short time window or risk losing access. Victims who comply hand over the seed phrase directly. The trojan also intercepts OTPs, making it capable of bypassing two-factor authentication entirely.
BTMOB RAT
BTMOB RAT represents a shift in how mobile malware is distributed and used. Rather than being deployed by a single threat actor, it operates as a fully commercialized malware-as-a-service platform, essentially a customizable RAT builder where buyers configure their own payload through a no-code interface, selecting the capabilities they want, without writing a single line of code. Once deployed on an Android device, BTMOB goes far beyond typical banking trojans: it gives the operator live screen sharing, keylogging, audio recording, file access, and the ability to inject fake overlays into banking apps. It self-propagates by exfiltrating the victim's contact list and using the infected device to send phishing messages outward, expanding its reach automatically.
mSpy
mSpy is a widely used monitoring tool marketed primarily as a parental control application. It provides access to call logs, SMS, GPS location, email and social media activity. Unlike FlexiSPY, mSpy does not require device jailbreaking for basic functionality on iOS, making it more accessible to non-technical users. mSpy has suffered multiple data breaches, exposing sensitive data collected from monitored devices.
Spyzie, Cocospy and Spyic
Researchers found a vulnerability affecting these three closely related stalkerware apps that exposed victim device data, including messages, photos and location, and allowed collection of millions of customer email addresses from their backend systems. This illustrates a recurring pattern in the stalkerware industry: poor security practices that put both victims and customers at risk.
Enterprise spyware
Pegasus
Pegasus is widely regarded as the most advanced commercial spyware tool in existence. Pegasus is capable of infectingdevices through zero-click exploits, requiring no interaction from the target and gaining access to messages, calls, passwords and location data. One of its documented attack vectors is the exploitation of WhatsApp, which is used to silently target users. Jamf Threat Labs has analyzed Pegasus-infected devices first-hand, documenting indicators of compromise on the iPhone of a human rights activist and disclosing a new detection indicator to Apple.
Further reading: Threat advisory: mobile spyware continues to evolve >>
Graphite
Graphite is a mercenary spyware platform developed by Paragon and sold to government agencies. Like Pegasus, it is capable of zero-click infection, compromising a device through a maliciously crafted photo or video delivered over a messaging app without the target opening anything. Graphite has been used against journalists, including on devices that were fully up to date at the time.
Landfall
Landfall is commercial-grade Android spyware used in a targeted campaign against Samsung Galaxy devices. It was delivered inside malformed image files sent through a messaging app, exploiting a vulnerability in Samsung's image processing to infect devices with no user interaction. Once installed, it gave operators access to the microphone, precise location, photos, contacts and call logs, and it operated undetected for close to a year before the flaw was patched.
How commercial spyware gets onto devices
Physical access: requires the attacker to physically handle the target device, disable security settings and manually install applications
Phishing and malicious links: target is tricked into clicking a link that silently installs the spyware through a browser or application vulnerability
Zero-click exploits: allows a device to be infected simply by visiting a website or receiving a specially crafted message, without the user clicking or tapping anything.
Sideloading: apps that are distributed directly from developer websites, often with instructions to disable built-in device protections and third-party security tools
What can spyware actually do?
Spyware includes a number of dangerous features observed in the wild, like:
- Real-time GPS location tracking
- Call recording and interception
- SMS, email and messaging app monitoring (WhatsApp, Telegram, iMessage)
- Ambient microphone and camera access
- Keylogging
- Application activity and browser history monitoring
- Silent operation with hidden icon and background processes
How spyware gains access to this information varies. For example, Landfall reached Samsung Galaxy devices inside malformed image files and rewrote the device's own security policy to grant the spyware elevated permissions and help it persist.
Crocodilus takes a far simpler route to comparable access: it requests Android's Accessibility Services to gain visibility into everything rendered on screen. It uses that create fake login screens and to capture one-time passcodes as they appear, defeating two-factor authentication regardless of whether the code arrives by SMS or from an authenticator app.
BTMOB RAT applies the same class of access to live screen streaming and keylogging, then exfiltrates the victim's contact list and sends phishing messages onward from the infected device.
Signs a device may be compromised: what to look for
The following indicators may suggest a device has been compromised by spyware:
Unusual battery drain: Background collection and transmission burns power even when the phone looks idle.
Overheating: Persistent hidden activity keeps the device running warm with no obvious cause.
Unexpected data usage: Spyware phones home constantly, showing up as unexplained spikes in mobile data.
Unfamiliar profiles or certificates: On iOS, spyware may install configuration profiles or developer certificates to persist and expand access.
Sluggish performance: A device that has become noticeably slow may be sharing resources with hidden processes.
Unrecognized apps: Unknown apps, especially those demanding microphone, camera, location or contacts, deserve immediate suspicion.
How to defend your mobile devices from spyware
Commercial spyware represents a growing and evolving threat to organizations of all sizes, capable of silently compromising devices and exposing sensitive data without any visible indication. Protecting your mobile fleet requires a combination of proactive measures:
- Scan at-risk devices: Jamf Mobile Forensics detects indicators of compromise, so when a device shows any of the signs above, your team can confirm an infection and respond before more data is exposed.
- Enforce OS updates: Many spyware tools exploit known vulnerabilities that are patched in OS updates. Set minimum OS versions and update deadlines through your device management solution instead of relying on users to update.
- Consider Lockdown Mode: While not recommended for standard use, Lockdown Mode on iOS restricts functionality for the sake of security and is best for high-risk users such as executives, legal teams or anyone handling sensitive data. If there’s reason to suspect a user was targeted, Lockdown Mode provides protection until the device can be analyzed.
- Prevent sideloading: Only allow applications from official app stores such as the App Store and Google Play, and be cautious with app permissions.
- Educate users: Phishing attempts and suspicious links are common delivery methods for consumer-grade spyware. Train users to recognize these attempts, keep a strong passcode on their devices and report any of the warning signs above to IT.
Make sure your corporate devices are free from spyware.