Featured Article

Support King, banned by FTC, linked to new phone spying operation

SpyTrac is one of the largest known Android surveillance apps

Comment

Blue eyes on a black background titled at an angle
Image Credits: Getty Images

A year after it was banned by the Federal Trade Commission, a notorious phone surveillance company is back in all but name, a TechCrunch investigation has found.

A groundbreaking FTC order in 2021 banned the stalkerware app SpyFone, its parent company Support King, and its chief executive Scott Zuckerman from the surveillance industry. The order, unanimously approved by the regulator’s five sitting commissioners, also demanded that Support King delete the phone data it illegally collected and notify victims that its app was secretly installed on their device.

Stalkerware, or spouseware, are apps that are surreptitiously planted by someone with physical access to a person’s phone, often under the guise of family tracking or child monitoring, except that these apps are designed to stay hidden from home screens, all the while silently uploading the contents of a person’s phone, including their text messages, photos, browsing history, and granular location data.

But many stalkerware apps — like KidsGuard, TheTruthSpy and Xnspy — have security flaws that put thousands of people’s personal phone data at risk of further compromise.

That also includes SpyFone, whose unsecured cloud storage server spilled the personal data stolen from more than 2,000 victims’ phones, prompting the FTC to investigate and subsequently ban Support King and its CEO Zuckerman from offering, distributing, promoting, or otherwise assisting in the sale of surveillance apps.

Since then, TechCrunch has received further tranches of data, including from the internal servers of a stalkerware app called SpyTrac, which is run by developers with ties to Support King.

Meet Aztec Labs

With more than a million user records, SpyTrac is one of the biggest known active Android stalkerware operations, surpassing the number of victims ensnared by TheTruthSpy more than threefold. Despite its vast international reach, U.S. visitors to SpyTrac’s website are blocked with an abrupt message stating that “your country is not supported.”

But SpyTrac is like any other stalkerware app, including its ability to stay hidden on a victim’s device. SpyTrac’s website also makes no mention of the individuals running the operation, likely to shield the developers from legal and reputational risks associated with running a stalkerware operation.

According to the data and other public records seen by TechCrunch, SpyTrac is managed by developers who work for both Support King and an outfit of developers called Aztec Labs, which builds and maintains the SpyTrac stalkerware operation. Aztec Labs also maintains a near-identical Spanish-language stalkerware app called Espía Móvil (which translates to “spy mobile”), and another clone stalkerware app called StealthX Pro, the data shows.

Some of the data found on SpyTrac’s server directly connects SpyTrac to Support King.

One of the server files contained a set of Amazon Web Services private keys that allow access to cloud storage associated with Support King and GovAssist, a website that claims to help immigrants obtain U.S. visas and permanent residency permits. The keys also allow access to cloud storage for OneClickMonitor, a clone stalkerware app that Support King shut down at the same time as SpyFone.

Both Support King and GovAssist are headed by chief executive Scott Zuckerman.

When reached by email, Zuckerman told TechCrunch: “We are investigating your claims that SpyTrac internal data was storing AWS keys that may be connected to S3 buckets relating to Support King, GovAssist, and OneClickMonitor. We take this very seriously and will comply with all provisions of the FTC Order.”

A redacted screenshot from a SpyTrac video, which references SpyFone, a Support King surveillance app banned by the FTC a year earlier. Image Credits: TechCrunch (screenshot)

Access logs seen by TechCrunch show at least two Aztec Labs developers logging in to SpyTrac’s servers using different sets of credentials, but each from the same IP addresses. Both of the developers logged in from IP addresses registered to a Bosnian residential broadband provider using credentials associated with Aztec Labs, SpyTrac, and Support King email addresses.

One of the developers is Aztec Labs’ technical lead, whose LinkedIn says he is based in Sarajevo. His other public freelance portfolios list his work as a program manager at Support King, a role that he describes as “managing the entire IT team.”

According to LinkedIn profiles and other work portfolios, the technical lead and other SpyTrac developers also work on Zuckerman’s latest venture, GovAssist.

The access logs also show a third developer logging in to SpyTrac’s servers, also from their home IP address in Sarajevo, using different sets of credentials associated with Support King, Aztec Labs, and GovAssist email addresses.

In response, Zuckerman told TechCrunch: “Neither I, nor any of my businesses, are affiliated with Aztec Labs, SpyTrac, or [the technical lead, who] worked as an independent contractor for Support King between June 2019 and October 2021. Nor do we have access to SpyTrac’s servers.”

The SpyFone connection

SpyFone, the stalkerware app banned by the FTC in September 2021, no longer operates.

The internal SpyTrac data we have seen shows that SpyFone issued its last customer license just days before it was banned by the FTC. SpyFone’s domain name was sold to another phone surveillance maker, SpyPhone. Customers trying to log in to SpyFone’s web dashboard, used for accessing a victim’s stolen data, were redirected to SpyPhone’s website instead.

The FTC’s 2021 order also demanded that Support King delete the data it had illegally collected from SpyFone. But the internal SpyTrac data seen by TechCrunch still contains thousands of records associated with SpyFone licenses assigned to the email addresses of buying customers.

Every SpyFone license was sold by a reseller with a Support King email address, the data showed.

SpyTrac also came to the attention of security researchers Vangelis Stykas and Felipe Solferini, whose months-long research identified common and easy-to-find security flaws in several stalkerware families, including SpyTrac. Their findings, which they presented at BSides London this month, involved decompiling the apps and mapping out their server infrastructure using public internet data. Their evidence links SpyTrac to Support King.

Zuckerman said in response: “Support King deleted all data in its servers connected with SpyFone and OneClickMonitor customers pursuant to the FTC Order.”

A short time after TechCrunch contacted Zuckerman for comment, SpyTrac’s website went offline with a message saying the “product is temporarily not available.” The websites for SpyTrac’s clone stalkerware apps, StealthX Pro and its Spanish-language clone Espía Móvil, also went offline. Aztec Labs’ website also stopped loading.

After TechCrunch published this piece, Support King’s website also went offline.

A screenshot of the FTC notice on Support King's website.
A screenshot of the FTC notice on Support King’s website. Image Credits: TechCrunch (screenshot)

Stalkerware is a difficult problem to combat. These operations are clandestine by design, making it difficult for regulators to investigate or know under whose jurisdiction they fall.

In 2020, the FTC took its first ever action against a stalkerware operator, Retina-X, which was hacked several times and later shut down. The FTC’s second action was against Support King a year later.

Companies that violate FTC orders can face considerable civil penalties. Earlier this year, Twitter was ordered to pay $150 million for violating an FTC order from 2011.

Instead, much of the effort against stalkerware and other commercial surveillance has been taken up by the tech industry, including device makers Apple and Google, which have banned stalkerware apps. In 2020, Google also banned ads in its search results that promote stalkerware. Anti-malware providers who are members of the Coalition Against Stalkerware, which launched in 2019 to support victims and survivors of stalkerware, collectively share signatures of known stalkerware apps and networks to block them from working on their customers’ phones.

A former FTC attorney, who reviewed our findings ahead of publication, told TechCrunch that the evidence points to a likely breach of the FTC’s ban. As to whether Support King broke its agreement with the FTC will ultimately be for the agency to decide.

When reached, a spokesperson for the FTC declined to comment.


If you or someone you know needs help, the National Domestic Violence Hotline (1-800-799-7233) provides 24/7 free, confidential support to victims of domestic abuse and violence. If you are in an emergency situation, call 911. The Coalition Against Stalkerware also has resources if you think your phone has been compromised by spyware. You can contact this reporter on Signal and WhatsApp at +1 646-755-8849 or zack.whittaker@techcrunch.com by email.

Read more:

FTC bans spyware maker SpyFone, and orders it to notify hacked victims

More TechCrunch

U.S. President Joe Biden has announced he no longer plans to seek reelection, a decision that follows weeks of growing pressure from some Democratic Party supporters, including high-profile tech investors…

Joe Biden drops out of presidential race

Google is expected to announce four Pixel devices: the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL and Pixel 9 Pro Premium, running Android 15.

Made by Google 2024: Pixel 9, Gemini, a new foldable and other things to expect from the event

WazirX, one of India’s largest cryptocurrency exchanges, has “temporarily” suspended all trading activities on its platform days after losing about $230 million, nearly half of its reserves, in a security…

WazirX halts trading after $230 million ‘force majeure’ loss

Featured Article

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Subject to shareholder approval, Yandex N.V. is adopting the name of one of its few remaining assets, an AI cloud platform called Nebius AI which it birthed last year.

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Employees at Bethesda Game Studios — the Microsoft-owned game developer that produces the Elder Scrolls and Fallout franchises — are joining the Communication Workers of America. Quality assurance testers at…

Bethesda Game Studios employees form a ‘wall-to-wall’ union

This week saw one of the most widespread IT disruptions in recent years linked to a faulty software update from popular cybersecurity firm CrowdStrike. Businesses across the world reported IT…

CrowdStrike’s update fail causes global outages and travel chaos

Alphabet, the parent company of Google, is in advanced talks to acquire cybersecurity startup Wiz for $23 billion, the Wall Street Journal reported on Sunday. TechCrunch’s sources heard similar and…

Unpacking how Alphabet’s rumored Wiz acquisition could affect VC

Around 8.5 million devices — less than 1 percent Windows machines globally — were affected by the recent CrowdStrike outage, according to a Microsoft blog post by David Weston, the…

Microsoft says 8.5M Windows devices were affected by CrowdStrike outage

Featured Article

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Trump is an advocate for a number of policies that could be harmful to people of color.

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Featured Article

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

TechCrunch sat down with Strava’s new CEO in London for a wide-ranging interview, delving into what the company is prioritizing, and what we can expect in the future as the company embarks on its “next chapter.”

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

Featured Article

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

All week at the RNC, I saw an event defined by Silicon Valley. But I also saw the tech elite experience flashes of discordance.

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

Featured Article

Tracking the EV battery factory construction boom across North America

A wave of automakers and battery makers — foreign and domestic — have pledged to produce North American–made batteries before 2030.

Tracking the EV battery factory construction boom across North America

Featured Article

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

Security giant CrowdStrike said the outage was not caused by a cyberattack, as businesses anticipate widespread disruption.

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

CISA confirmed the CrowdStrike outage was not caused by a cyberattack, but urged caution as malicious hackers exploit the situation.

US cyber agency CISA says malicious hackers are ‘taking advantage’ of CrowdStrike outage

The global outage is a perfect reminder how much of the world relies on technological infrastructure.

These startups are trying to prevent another CrowdStrike-like outage, according to VCs

The CrowdStrike outage that hit early Friday morning and knocked out computers running Microsoft Windows has grounded flights globally. Major U.S. airlines including United Airlines, American Airlines and Delta Air…

CrowdStrike outage: How your plane, train and automobile travel may be affected

Prior to the ban, Trump’s team used his channel to broadcast some of his campaigns. With the ban now lifted, his channel can resume doing so.

Twitch reinstates Trump’s account ahead of the 2024 presidential election

This week, Google is in discussions to pay $23 billion for cloud security startup Wiz, SoftBank acquires Graphcore, and more.

M&A activity heats up with Wiz, Graphcore, etc.

CrowdStrike competes with a number of vendors, including SentinelOne and Palo Alto Networks but also Microsoft, Trellix, Trend Micro and Sophos, in the endpoint security market.

CrowdStrike’s rivals stand to benefit from its update fail debacle

The IT outage may have an unexpected effect on the climate: clearer skies and maybe lower temperatures this evening

CrowdStrike chaos leads to grounded aircraft — and maybe an unusual weather effect

There’s a man in Florida right now who wants to propose to his girlfriend while they’re on a beach vacation. He couldn’t get the engagement ring before he flew down…

The CrowdStrike outage is a plot point in a rom-com 

Here’s everything you need to know so far about the global outages caused by CrowdStrike’s buggy software update.

What we know about CrowdStrike’s update fail that’s causing global outages and travel chaos

This serves as an example for how easy it is to spread inaccurate information online during a time of immense global confusion and panic.

From the Sphere to false cyberattack claims, misinformation runs rampant amid CrowdStrike outage

Today is the final chance to save up to $800 on TechCrunch Disrupt 2024 tickets. Disrupt Deal Days event will end tonight at 11:59 p.m. PT. Don’t miss out on…

Last chance today: Secure major savings for TechCrunch Disrupt 2024!

Indian fintech Paytm’s struggles won’t seem to end. The company on Friday reported that its revenue declined by 36% and its loss more than doubled in the first quarter as…

Paytm loss widens and revenue shrinks as it grapples with regulatory clampdown

J. Michael Cline, the co-founder of Fandango and multiple other startups over his multi-decade career, died after falling from a Manhattan hotel, New York’s Deputy Commissioner of Public Information tells…

Fandango founder dies in fall from Manhattan skyscraper

Venture capital giant a16z fixed a security vulnerability in one of the firm’s websites after being warned by a security researcher.

Researcher finds flaw in a16z website that exposed some company data

Apple on Thursday announced its upcoming lineup of immersive video content for the Vision Pro. The list includes behind-the-scenes footage of the 2024 NBA All-Star Weekend, an immersive performance by…

Apple Vision Pro debuts immersive content featuring NBA players, The Weeknd and more

Biden centering Musk in his campaign is a notable escalation, considering he spent most of his presidency seemingly pretending the billionaire didn’t exist.

Elon Musk is now a villain in Joe Biden’s presidential campaign

Waymo would need a ground transportation permit to operate at SFO, which has yet to be approved.

Waymo wants to bring robotaxis to SFO, emails show