Page 1
ANDROIDMALWARE & STALKERWARE · A GUIDE FOR UK LAWYERS Android Malware, Stalkerware and Compromise The Open Platform's Larger Threat Surface, What Can Be Found, and the Duty of Care That Comes First COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES ANDROID STALKERWARE & MALWARE DETECTION SAFET Y-LED, VICTIM-CENTRED APPROACH CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: openness cuts both ways 03 How Android devices are compromised 04 Detecting compromise: what Android lets you see 05 Safety first: the duty of care 06 Interpretation and honest limits 07 Deployment: protecting the person, then the evidence 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary The headline point: Android's openness gives it a larger threat surface than iOS, sideloaded stalkerware and malware are easier to install and sweeping permissions let them see a great deal, but the most common surveillance is still consumer stalkerware installed with physical access or the misuse of legitimate features, openness also lets an examiner inspect apps and permissions more fully, and, as on iOS, the person's safety comes before the evidence.
§ 02 · FIRST PRINCIPLES The problem in plain English: openness cuts both ways
§ 03 · HOWDEVICESARECOMPROMISED How Android devices are compromised STALKERWARE PERMISSIONS MISUSED FEATURES CONTROLLED MALWARE (RARE) ACCOUNT
Page 2
§ 04 · DETECTINGCOMPROMISE Detecting compromise: what Android lets you see
§ 05 · SAFETYFIRST Safety first: the duty of care
§ 06 · INTERPRETATIONANDHONESTLIMITS Interpretation and honest limits
§ 07 · DEPLOYMENT Deployment: protecting the person, then the evidence
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE (APPS, FAMILY PROVIDER / OTHER THE PHONE SHARING / STALKERWARE PHYSICAL / PERMISSIONS) SETUP DASHBOARD DEVICES GOOGLE SAFET Y ACCOUNT CONSIDERATION
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THESTALKERWARETHEPERMISSIONSGAVEAWAY EXAMPLE2 · THE " SPYWARE " THATWASASHAREDGOOGLEACCOUNT EXAMPLE3 · THEBROADPERMISSIONSTHATWERELEGITIMATE
Page 3
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask the other side / in proceedings Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTIONFORANANDROIDSUSPECTED - COMPROMISE ANA LY SIS
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The Android suspected-compromise checklist Red flags When to involve a digital forensic expert 19. This guide continues the Android block. Through cflab.uk and e-discovery.uk, Android compromise work
§ 13 · COMMON QUESTIONS Frequently asked questions Is Android more vulnerable to stalkerware than iPhone? My client thinks their phone is being tracked. Where do we start? How can stalkerware be found on Android? Does an app with broad permissions prove it is spyware? What if the abuser controls the Google account? Should we just uninstall any stalkerware we find?
§ 14 · REFERENCE Glossary Sources and authoritative references 35 and CrimPR Part 19 reporting): cflab.uk/digital-forensics-services · guides library: cflab.uk/guides DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
Cite as: Joseph Naghdi, Android Malware Stalkerware And Compromise, Computer Forensics Lab, https://e-discovery.uk/library/android-malware-stalkerware-and-compromise/pdf.
