§ Guide, full text

Android Malware Stalkerware And Compromise

Android's openness creates a larger threat surface, making sideloaded stalkerware and malware easier to install. This guide details how to detect compromise, the importance of safety, and where evidence lives, helping UK lawyers understand and address Android security issues.

20 pages · 27 min read

Loading the PDF reader

Page 1

ANDROIDMALWARE & STALKERWARE · A GUIDE FOR UK LAWYERS Android Malware, Stalkerware and Compromise The Open Platform's Larger Threat Surface, What Can Be Found, and the Duty of Care That Comes First COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES ANDROID STALKERWARE & MALWARE DETECTION SAFET Y-LED, VICTIM-CENTRED APPROACH CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: openness cuts both ways 03 How Android devices are compromised 04 Detecting compromise: what Android lets you see 05 Safety first: the duty of care 06 Interpretation and honest limits 07 Deployment: protecting the person, then the evidence 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary The headline point: Android's openness gives it a larger threat surface than iOS, sideloaded stalkerware and malware are easier to install and sweeping permissions let them see a great deal, but the most common surveillance is still consumer stalkerware installed with physical access or the misuse of legitimate features, openness also lets an examiner inspect apps and permissions more fully, and, as on iOS, the person's safety comes before the evidence.

§ 02 · FIRST PRINCIPLES The problem in plain English: openness cuts both ways

§ 03 · HOWDEVICESARECOMPROMISED How Android devices are compromised STALKERWARE PERMISSIONS MISUSED FEATURES CONTROLLED MALWARE (RARE) ACCOUNT

Page 2

§ 04 · DETECTINGCOMPROMISE Detecting compromise: what Android lets you see

§ 05 · SAFETYFIRST Safety first: the duty of care

§ 06 · INTERPRETATIONANDHONESTLIMITS Interpretation and honest limits

§ 07 · DEPLOYMENT Deployment: protecting the person, then the evidence

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE (APPS, FAMILY PROVIDER / OTHER THE PHONE SHARING / STALKERWARE PHYSICAL / PERMISSIONS) SETUP DASHBOARD DEVICES GOOGLE SAFET Y ACCOUNT CONSIDERATION

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THESTALKERWARETHEPERMISSIONSGAVEAWAY EXAMPLE2 · THE " SPYWARE " THATWASASHAREDGOOGLEACCOUNT EXAMPLE3 · THEBROADPERMISSIONSTHATWERELEGITIMATE

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask the other side / in proceedings Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTIONFORANANDROIDSUSPECTED - COMPROMISE ANA LY SIS

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The Android suspected-compromise checklist Red flags When to involve a digital forensic expert 19. This guide continues the Android block. Through cflab.uk and e-discovery.uk, Android compromise work

§ 13 · COMMON QUESTIONS Frequently asked questions Is Android more vulnerable to stalkerware than iPhone? My client thinks their phone is being tracked. Where do we start? How can stalkerware be found on Android? Does an app with broad permissions prove it is spyware? What if the abuser controls the Google account? Should we just uninstall any stalkerware we find?

§ 14 · REFERENCE Glossary Sources and authoritative references 35 and CrimPR Part 19 reporting): cflab.uk/digital-forensics-services · guides library: cflab.uk/guides DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

Cite as: Joseph Naghdi, Android Malware Stalkerware And Compromise, Computer Forensics Lab, https://e-discovery.uk/library/android-malware-stalkerware-and-compromise/pdf.

Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp