Contact
Report

The apps that watch you: how stalkerware enables tech-facilitated abuse

September 16, 2026 14 min read
MethodOSINT
The apps that watch you: how stalkerware enables tech-facilitated abuse

If you think someone may be monitoring your phone or computer, consider reading this on a device they cannot access. Safety advice and support contacts are at the end of this report.

Introduction

In the first nine months of 2025, Refuge, the largest domestic abuse organisation in the UK, received a 62% rise in technology-facilitated abuse (TFA) against women and girls, collecting more referrals by the end of September than all of 2024. The organisation shared even more concerning numbers in their July 2026 report, which showed a 78% increase in TFA and economic abuse, which can also be done digitally.

According to PubMed Central and Sage Journals, TFA is a growing global trend in intimate partner violence (IPV) and involves the use of online spaces and everyday technology to carry out various forms of abuse, such as stalking, coercive control and harassment. Regardless of one’s relation to the perpetrator, TFA may be executed via social media platforms, compromised digital accounts, wearable technology and more.

In their 2025 press release, Refuge noted an increase in survivors reporting surveillance methods used to conduct TFA, such as the implementation of spy cameras and microphones in homes and the use of other technologies like stalkerware – tools commonly marketed for parental control purposes that abusers may install on their target’s digital device(s).

The latter grants perpetrators the ability to spy on their victims in secret, monitoring their digital activity and harvesting their personal data, as the software will either not appear on a target’s device or may resemble predownloaded applications, making it arguably one of the most invasive and difficult-to-detect forms of surveillance used in TFA thus far.

This report further explores the impact of stalkerware in IPV, its legal issues and loopholes, additional TFA methods and resources for those experiencing abuse.

The use of stalkerware in IPV

The capabilities of stalkerware apps vary, but they typically grant abusers access to their target’s location, photos and videos, SMS messaging, call logs and search history. This baseline of features allows perpetrators to retrieve a large quantity of personal information to weaponise against their targets, and can enable or contribute to multiple forms of abuse, such as psychological, economic, sexual or physical harm.

In the case of a woman named Melody, who spoke to Sky News about her experience with stalkerware in late 2024, her ex-partner used the app mSpy to stalk her for months and would show up in locations she had not shared with anyone, leaving her in a constant state of fear for what they would do next.

A five-star review dated 06.06.2022, headlined I highly recommend giving mSpy a try, describing using mSpy to track a boyfriend’s calls and messages.
Review featured on mSpy’s website, retrieved on September 15, 2026. Reviewer name redacted by Intel Focus.

“I’ve never felt so frightened in all my life,” she told the outlet. “The way this goes according to my domestic abuse support workers is: the next step they will kill you.”

Melody, speaking to Sky News

Similar warnings have been echoed by groups like the National Organization for Women (NOW), an American feminist movement, who claim that the chances of homicide in cases of IPV increase significantly when digital access is gained by the abuser.

Luckily, Melody detected the stalkerware before the situation worsened after noticing her mobile’s battery was draining faster and took it to be evaluated. The repair shop she visited found and removed the invisible application, but mSpy had already allowed Melody’s ex access to everything on her phone, including her diary, information she gave to authorities, her contacts and her location.

Another woman who spoke to Sky News had Life360, a live location tracking app often used by families, weaponised against her by her ex-boyfriend while pregnant. The woman, referred to as Caitlin, said her ex convinced her the app was for her safety, but began making her provide evidence of her whereabouts when she was not where he thought she would be and would use the silent treatment or grow violent in retaliation.

Caitlin’s situation serves as an example of how apps like Life360, while not marketed towards abusers or considered stalkerware, can still be used maliciously. In these scenarios, the app creators and companies are not legally at fault. Unfortunately, this often remains the case even when apps identified by professionals as stalkerware, like mSpy, are used in TFA.

The legal loopholes of stalkerware

Kaspersky, a cybersecurity and anti-virus provider, explains that apps classified as stalkerware often describe themselves as parental control apps, which are generally legal, to avoid clandestine surveillance laws. By marketing themselves this way, despite their features allowing for secret, non-consensual surveillance, companies and developers may distance themselves from harmful uses of their apps, exploiting gaps in the legal framework to avoid liability.

While many stalkerware apps market themselves as child monitoring tools, their mixed-use marketing and the descriptions of their capabilities on social media and company websites often exhibit characteristics that arguably appeal to abusers more than concerned parents, particularly in cases where monitoring romantic relationships is mentioned.

XNspy, a popular stalkerware app, has exhibited this mixed-use marketing while showcasing its features on social media.

Xnspy post on X promoting Tinder Monitoring to see a teen’s chats, matches and usage, with a graphic reading Monitor Tinder activity.
Xnspy on X, December 5, 2025.
Xnspy post on X headed Suspect lies or secrets? advertising silent recording of incoming and outgoing calls.
Xnspy on X, July 21, 2025.
Xnspy post on X reading They won’t know. But you’ll know everything, advertising fully remote, hidden tracking of calls, messages, location and screen time on any iPhone.
Xnspy on X, July 21, 2025.

View the posts on X: December 5, 2025 · July 21, 2025 · July 21, 2025 (second post)

The above descriptions of XNspy share some qualities with child monitoring software and do not directly suggest customers engage in TFA, but they clearly signal attributes of stalkerware by highlighting their stealth and ability to surveil their target’s interactions with potential intimate partners.

In the first post, XNspy encouraged parents to use their software to look at their teenager’s Tinder. The dating app bans teens under 18, the legal age of an adult in many countries, from creating profiles. Although a child may find a way to set up an account before they are 18, one might argue this feature is more likely to appeal to and be used by an abuser on a current or former partner, rather than a parent who, if eager to monitor their underage child’s online safety, should and likely would have them remove the app if discovered.

The same could be said about the messaging used in XNspy’s posts from July 21, 2025. As previously stated, being undetectable is, for the most part, a more sought-after and common feature of stalkerware than it is in parental control apps. The ability to listen to audio and phone calls and to monitor text messages, location and screen time are capabilities occasionally shared by both, but it is the emphasis on secrecy, together with their previous post about Tinder, that appears to reveal a pattern of mixed-use messaging.

uMobix post on X saying Close friends isn’t about secrets. It’s about privacy, and promoting viewing hidden and deleted activity, above a carousel about Instagram close friends.
uMobix post to X from January 27, 2026.

View the post on X

The above post by uMobix, another stalkerware app, also uses language that may signal to abusers in addition to parents. They directly call on users to view their target’s “close friends” activity on Instagram, a feature that allows you to share posts with a select number of followers, which they describe as a place that is not secret, but private. This could appeal to an abuser who has been removed from their intimate partner’s close friends, or across all socials, and wants to learn who they are in communication with or what they are sharing.

Unlike XNspy, uMobix’s website initially presents the software as a child and employee monitoring app. However, further exploration of the site reveals mixed-use messaging that also directly promotes the surveillance of intimate partners.

Section of the uMobix website headed Whom uMobix Monitors, with three columns: Kids, Spouses and Employees.
The uMobix website’s “Whom uMobix Monitors” section, listing kids, spouses and employees.
About Us section of the uMobix website headed Little Idea, Big Solution, listing features including absolute secrecy.
The “About Us” section of the uMobix website.

When looking for stalkerware apps like XNspy and uMobix on official app stores, such as Google Play or the App Store, many do not appear. This is due to the restrictions these platforms have against apps with secretive surveillance features, so users are typically asked to “sideload” their software, meaning they must download it via the app’s website or from other third-party sources.

Sideloading is known to be associated with security and privacy risks for users, as they are not vetted by Apple or Google; genuine parental control apps rarely require one to jump over such hurdles to use their software.

Some stalkerware-adjacent or associated apps remain on official stores despite their clandestine features, like mLite, which is also marketed as a parental control app and shares mSpy’s icon among other links that show a connection between the two apps. As we dove into reviews of mLite, we found some concerning reviews from users that claim to have used it to spy on intimate partners despite its requirements to notify the target.

While we cannot independently verify that these individuals used the app in the way they described, and not all reviews claimed to have stalked their partner, nor were they all positive, its more “complex” variation, mSpy, is known to have been weaponised for TFA and is categorised as deliberate stalkerware. Below are screenshots of reviews on April 22, 2026 and August 17, 2026, via Google Play.

Google Play review of mLite dated July 29, 2026, describing using the app to spy on a cheating partner without them suspecting. The developer, IPL Group Pty Ltd, replied: Dear Customer, we are thrilled with your review!
1/6Google Play review, July 29, 2026. The developer, IPL Group Pty Ltd, replied: “Dear Customer, we are thrilled with your review!” Reviewer name and contact details redacted by Intel Focus.
Google Play review of mLite dated August 10, 2026, describing tracking a partner’s WhatsApp chats, text messages and call logs. The developer replied: Dear Customer, we hope you will like our app!
2/6Google Play review, August 10, 2026. Developer reply: “Dear Customer, we hope you will like our app!” Reviewer name and contact details redacted by Intel Focus.
Google Play review of mLite dated April 10, 2026, describing gaining full remote access to a spouse’s phone.
3/6Google Play review, April 10, 2026. Reviewer name and contact details redacted by Intel Focus.
Google Play review of mLite dated March 25, 2026, describing using the app to access everything on a partner’s phone.
4/6Google Play review, March 25, 2026. Reviewer name and contact details redacted by Intel Focus.
Google Play review of mLite dated March 21, 2026, calling it perfect to spy on cheating lovers and to listen to conversations remotely.
5/6Google Play review, March 21, 2026. Reviewer name redacted by Intel Focus.
Google Play review of mLite dated November 24, 2025, describing monitoring a spouse’s phone, with a developer reply dated January 30, 2026 pointing to official support channels.
6/6Google Play review, November 24, 2025. The developer replied on January 30, 2026. Reviewer name and contact details redacted by Intel Focus.

Six reviews. Scroll sideways to see them all, and select one to enlarge it.

In the oldest review we documented, published in November 2025, the developer replied to a user, disregarding their abuse of the app to monitor their spouse, while providing information on how to receive support.

Who is held accountable for stalkerware TFA?

When stalkerware is used in TFA, legal responsibility most often falls on the abuser, while developers are rarely, if ever, held accountable. This is compounded by the often opaque ownership and online presence of developers, despite their role in creating the features that allow abusers to target their victims.

While some apps have been around since the early-to-mid 2000s, Axios reported that it was only in 2019 that the United States’ FTC took one of its first actions against a stalkerware company, known as Retina X. Some stalkerware apps, like mSpy, have been recognised as tools to stalk victims of abuse for years, as shared in a report by NPR in 2014, but continue to survive.

As shared by Gblock and the State of Surveillance, this past April marks the first time in a decade that a stalkerware company was prosecuted in the US for enabling abusers to stalk their current and former partners. While there is some justice against stalkerware companies and abusers using the apps in certain countries like the US, there is an absence of laws prohibiting stalkerware and holding its creators accountable globally. Sometimes, hacktivists take it upon themselves to infiltrate stalkerware software and try to stop it when authorities do not.

In February 2026, TechCrunch published a report on stalkerware, claiming that 27 stalkerware companies have been hacked or had their users’ or victims’ data leaked since 2017, with the most recent instance having taken place against uMobix, which saw hackers scrape 500,000 user payment records, in this case targeting the information of those who purchased the app for surveillance purposes. In other cases, however, the victims of stalkerware may also be further victimised when the information initially collected by their abuser is later hacked and leaked online.

Despite the harm the careless design of many stalkerware apps causes to the victims of abusers beyond being surveilled, developers at fault for this have not seen consequences in court. This is again, where their claims of legitimate use or intent, such as being for child monitoring, protect them.

  1. NPR reports that apps including mSpy are being used to stalk and control victims of domestic abuse.

  2. The FTC takes one of its first actions against a stalkerware company, Retina X.

  3. TechCrunch counts 27 stalkerware companies hacked or leaked since 2017. The latest, uMobix, loses 500,000 customer payment records to a hacktivist.

  4. A stalkerware company is prosecuted in the US for enabling abusers to stalk partners, the first such case in a decade.

Accountability milestones cited in this section.

TFA methods on the rise

In March 2026, Women Against Violence Europe (WAVE) spoke with Kiera Brodie, the Tech Abuse Training Lead at Refuge’s Technology Facilitated Abuse and Economic Empowerment (TFAEE) team. In their discussion, Brodie said that TFA methods are expected to grow more complex as we incorporate additional technologies in our lives.

Wearable technology, for example, is a rapidly growing area, and the team is already starting to see aspects of this. The variety of tech and the ways devices connect will continue to expand,” Brodie said. “It’s not just that individual technical systems will become more complicated; the networks linking these devices will create an extensive web of surveillance around survivors.”

Kiera Brodie, Refuge, speaking to WAVE

In 2025, UN Women expressed great concern regarding the rise in AI tools to conduct TFA against women and girls, claiming they worsen common forms of online abuse. In their report, they listed the tools’ ability to spread automated hate speech, deepfake pornography, doxing, digital attacks and impersonation online.

Although such advanced and new techniques may be deployed to commit TFA, Brodie added that “simpler” forms of abuse, such as iCloud or email hacking to stalk targets, are often overlooked and can be overshadowed by things like AI or stalkerware, but that all forms remain important and persistent.

In the report by Kaspersky mentioned in the above paragraphs, they also noted that it is rare to see a form of TFA alone, and that an abuser deploying something like stalkerware is likely using other technologies or tactics, such as account hacking, to harm their victim.

Safety tips and help

If you believe your device(s), or that of someone you know, may be infected with stalkerware, or are the victim of other forms of TFA or IPV, please refer to the list of websites and organisations provided below that include tips on what to do and where to go for support. A majority of the organisations included specifically target women and girls, as well as members of the queer community, given that they are disproportionately impacted by such forms of abuse. However, both perpetrators and victims of TFA or IPV may naturally be of any gender or sexuality, and those tools may be useful for anyone at risk.

Important: before you click on the links below

  1. Access them on a device that is inaccessible to the individual you believe may have deployed stalkerware on your device(s).
  2. If stalkerware is discovered, do not immediately remove the software.

Both of these suggestions are to avoid notifying the user that you are aware of their actions, as this could spark an unwanted or dangerous reaction before you have a safety plan in place.

Tips on detecting stalkerware safely and what to do if you discover any

Support and resources if you are a victim of stalkerware or other forms of TFA or IPV

How to prevent stalkerware from being installed on your device

The following checklist is derived from a Kaspersky blog, which also includes some additional information about the legal issues surrounding stalkerware. It is also important to note that these steps should be taken prior to suspecting that your device may be compromised. If you find that it is, refer to the above steps.

  • Use reliable, strong passwords on your devices that only you know.
  • Block the ability for third-party apps to be installed on your devices.
  • Go through your device’s apps and see if any are out of the ordinary and whether they are pre-installed apps or new.
  • Protect your devices with anti-malware and anti-virus software products.