FlexiSPY is a commercial mobile spyware and stalkerware product associated with Vervata and widely known for covert surveillance of Android devices. It has also been discussed in the broader overlap between consumer spouseware and government-oriented surveillance tooling. On Android, FlexiSPY has been documented using root access to establish reboot hooks that reinstall the application and launch multiple monitoring daemons at boot, providing durable persistence and continuous background surveillance.
Its capabilities include interception of SMS and MMS messages, keyword-based monitoring of messages and keystrokes, collection of contacts, retrieval of installed application lists, access to browser history and bookmarks, monitoring of device photos, recording of video, and capture of both microphone audio and incoming or outgoing phone calls. These behaviors place it firmly in the spyware category, with strong support for keylogging, local data collection, audio surveillance, and ongoing exfiltration-oriented monitoring of victim activity.
FlexiSPY has been referenced in reporting on abuse by intimate partners as well as in discussions of commercial surveillance vendors and mercenary spyware ecosystems. It has also been noted as a product acquired or evaluated by offensive service providers, including Appin and Hacking Team, reflecting its role as a commercially available surveillance platform rather than a conventional commodity banking trojan or ransomware family. The strongest directly supported platform evidence is Android.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In one 2012 leaked email from the Wikileaks archive of hacked data from Italy-based government malware maker Hacking Team, the company claimed the Android spy tool of FinFisher, one of its fiercest rivals, looked similar to FlexiSpy, a cheap product manufactured by Thai firm Vervata.
For example, in 2010 they purchased mobile spyware services through Vervata, the business behind the FlexiSPY mobile stalkerware.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial stalkerware/spyware suite described as using AccessibilityService for non-root IM/keystroke capture; historically also used root-based database monitoring (FileObserver on app SQLite DBs) per leaked source code.
Commercial mobile spyware/stalkerware service purchased and used by Appin operators for mobile device monitoring.
Android spyware capable of recording video.
Spyware capable of retrieving installed application lists from devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.