Is Someone Spying On Your Cell-Phone Calls?

Spy v. Spy

How suspicious spouses, protective parents, and concerned companies are turning to cheap and hard-to-detect commerical spyware apps to monitor your mobile communications.

By Reader Supported News – Sometime in early 2007, Richard Mislan, an assistant professor of cyberforensics at Purdue University, started getting phone calls and e-mails from people around the world—all looking for help with the same problem. “They thought someone was listening in on their cell-phone calls,” he says. “They wanted to know what they could do to confirm it was happening.”

Mislan, who has examined thousands of phones at the Purdue Cyber Forensics Lab, politely disregarded some callers as a little paranoid. Others, he thought, had reason to be concerned. A decade ago the idea that anyone with little technical skill could turn a cell phone into a snooping device was basically unrealistic. But as the smart-phonemarket proliferates—it grew 86 percent in the United States alone last year—so do all the ethical kinks that come with it. Among them is a growing sector of perfectly legal smart-phone spyware apps that are peddled as tools for catching a cheating spouse or monitoring the kids when they’re away from home. But what they can effectively do, for as little as $15 or as much as several hundred, is track a person with a precision once relegated to federal authorities. “Not only can you look at a person’s e-mail or listen to their calls, in some cases you can also just turn on the microphone [on a smart phone] and listen to what the person is doing any time you want,” says Chris Wysopal, cofounder and CTO of Veracode, a software-security company.

Turning what is essentially cell-phone-bugging software into a business model is not a bad idea, technically speaking. The smart-phone market—largely dominated by the Symbian, Research in Motion, and iPhone operating systems—has 47 million users in the United States and is expected to exceed 1 billion worldwide by 2014, according to Parks Associates, a market-research firm. In most cases, people’s lives are tethered to these handsets. It’s how we e-mail, text, search, and, on occasion, even call someone. And the dependence just continues to grow. Last year consumers paid for and downloaded more than 670 million apps that can turn a phone into everything from a book reader to a compass. Smart-phone users effectively carry a real-time snapshot of what happens in their daily lives. This is what makes the smart phone the perfect way to track someone.

Among the top commercial spyware vendors who have ventured into this space are FlexiSPY, MobiStealth, and Mobile Spy. While the services vary, what they do is essentially the same. According to all three spyware Web sites, a person must have legal access to a smart phone to install a piece of spyware. For example, if you’re spying on a family member, that means the phone is family property. If you’re an employer monitoring your employee, the phone should be company-owned. To install the spyware, you have to have the phone in your possession for at least a few minutes to download the app. (There are apps that can be downloaded remotely, but that’s less common and not legal.) In Mobile Spy’s case, once the software is installed, you can log into your Mobile Spy web account to view e-mails, text messages, pictures taken, videos shot, calendar entries, incoming and outgoing calls, and GPS coordinates. MobiStealth and FlexiSPY take it a step further and allow a person to remotely record any conversations that take place near the cell phone. “The most threatening [part] is that it’s pretty impossible to tell if this is happening to you,” says Mislan. That’s because once the spyware app is on the phone it is virtually undetectable to the average user. There is no typical corresponding app icon, nor is it listed on any menu. At best, it may show up with a generic name like “iPhone app” or “BlackBerry app,” so that it appears to be a regular part of the system.

There is nothing illegal about making these apps, and almost all makers have disclaimers on their Web sites warning people not to use their products illegally. “Our software is for very specific uses,” says Craig Thompson, support coordinator of Retina-X Studios, the creator of Mobile Spy. “We do what we can to discourage innappropriate use.” Still, there is no way to know if someone is using the app to monitor his or her child (legal) or stalk an ex (not so much). Illegal use of spyware has already been reported in states such as Washington, Oklahoma, and Texas. According to Wysopal of Veracode, in addition to state and local laws, the federal Computer Fraud and Abuse Act and the Wiretap Act technically offer some protection for consumers. But even if someone discovers spyware on their phone, prosecuting the perpetrator can be difficult. “The problem with this law is the crime has to rise to the level of a felony for the FBI to investigate, [and] that typically involves $5,000 or more in damages,” Wysopal says. “I don’t really know what the damages are for someone installing [mobile spyware] and reading your e-mails.”

Jeff Troy, acting deputy assistant director for the FBI’s Cyber Division, says the issue is a growing concern for his organization because of how fast the smart-phone market is evolving. “I do think there is need for additional cyber laws to address this,” he says.

Until that happens, the best solution may well be preventive. According to BlackBerry maker Research in Motion, “BlackBerry smartphones include a firewall that can be set to prevent an app (like spyware) from making external connections; and passwords can also be required to authorize downloading an application to the device.” Google’s Android gives apps limited access to phone resources by default, but that can be changed manually, so the best bet is to lock the phone and/or SIM card whenever you’re not using it. Google has also recently activated a “kill switch” on its phone to remotely disable apps “that violate the Android Market Developer Distribution Agreement or other legal agreements, laws, regulations or policies.” Of the trio, Apple probably has the most user-friendly safety net, because all apps must be approved by its app store. To even get most spyware apps on an Apple iPhone, a person would have to jailbreak it, which voids the warranty.

If the software is already on a phone, Mislan says there is little that consumers can do on their own to confirm this. Even if you’re positive you are being spied on, doing something like replacing the SIM card is not always enough to wipe a phone clean of the problem. In some cases, Mislan advises consumers to reach out to companies like SMobile Systems that offer security solutions for cell phones—a growing market in themselves.

Wysopal says that as with so much that’s technology-related, something big has to break before things change in the smart phone–spyware space. “You’ll have to see someone important, like a politician, have their phone compromised,” he says. “If that happened, it would be a wake-up call.”


  1. Really Great article. I love to read your article whenever you post. This is really informative. There are lots of applications to monitor real time activities.

  2. Sorry, but you guys are missing the point here. Use of cell phone and other forms of tracking are a critical component for police these days. For example, the recent case of the Terrebonne Louisiana deputy and state trooper that got busted for planting a GPS tracker on a local sports coach. Turns out a local nitwit got pissed off when the coach cut his son from the baseball team. So, like any good American, said nitwit simply bribes a cop to slap a GPS tracker on the coaches car, then follow the coach around town spreading rumors that he was having an affair with a married woman. The rumor was completely false, but hey, this is America, cops are heros! No harm, no foul. Or the other case of SGT Randy Mucha of the Oak Brook Illinois police department. The problem started when two local residents showed up at a town meeting and called the mayor out for being an incompetent boob. Well, this is America, so like any good podunk mayor, he goes out and bribes a cop to slap a GPS tracker on the two uppity residents car. Then SGT Randy Mucha begins a spectacular slander campaign against the two residents that eventually forces them to leave town. Score one for the good guys, YAY! Only problem is, the two residents had a few bucks laying around, so they were able to have an investigation done that eventually led to Mucha being fired, and costing the township a couple million dollar settlement in favor of the two residents. And of special note to all you veterans, did you all hear about that VA police department in Waco, Texas? Well…two black cops say they were targeted by their fellow VA police pals. And guess what, their cell phones were tapped, and they were “spied on” by their cop pals! Its great to know that VA police will take time off from their busy schedule of GPS tracking and slandering “problem veterans”, such as myself, to give their own kind “the treatment”. VA police doing this stuff all day, every day, all across America. Land of the free, baby. Home of the brave.

  3. Apparently your conversatons can be listened to even if the cell phone is turned off.You have to remove the battery to nullify any eaves dropping.

    What sort of paranoid wanker would want to listen in on conversations of free people who believe in true democracy for all people on this planet? Are they so insecure that they have to know all that perchance passes our consciousness? They have to be really psychopathic control freaks,who have no concept of living a life of fun and creation.Sad pathetic beings.

  4. On my phone, it always seems that it’s the ‘speaker on’ feature, “that always seems ON, whether I shut it off, or not”. Yet, anyone else, who may be listening in on my conversations with my 90 year old mother & 80 year old father, may very well join the “Maytag Repairman”! Yet, THANK YOU, for having available, this Fine & Genuine service & site!

  5. If you are concerned about spying or tracking via cell, I would recommend either going without, or using a disposable (prepaid) phone and changing it frequently.

    However, our government is trying to end the days of the anon prepaid cell phone…

Comments are closed.