

The cache included a list of every Android device that was compromised by any of the spyware apps in TheTruthSpy’s network, including Copy9, MxSpy, iSpyoo, SecondClone, TheSpyApp, ExactSpy, GuestSpy and FoneTracker.


Then, in June, a source provided TechCrunch with a cache of files dumped from the servers of TheTruthSpy’s internal network. But the stealthy nature of the spyware means that most victims will have no idea that their device was compromised unless they know where on their device to look. Our investigation found victims in virtually every country, with large clusters in the United States, Europe, Brazil, Indonesia and India. A TechCrunch investigation in February 2022 revealed that a fleet of consumer-grade spyware apps, including TheTruthSpy, share a common security vulnerability that is exposing the personal data of hundreds of thousands of Android users.
