Phone Stalkerware & Hidden Spy App Forensic Triage (MVT) (2026)

Triage Android and iOS devices for hidden stalkerware (mSpy, FlexiSPY, Cocospy, KidsGuard), disguised system package names, Accessibility keyloggers, and anomalous logcat/dumpsys IOCs using Mobile Verification Toolkit (MVT) methodology.

Phone Stalkerware & Hidden Spy App Forensic Triage (MVT) — Interactive Console
Runs locally in your browser • Instant output
Operational Safety (OPSEC) Warning: Commercial stalkerware notifies the remote operator if uninstalled or if Airplane Mode is toggled. Preserve evidence with adb bugreport or MVT before wiping.
2 IOC match(es)
com.mspy.litemSpy Commercial Stalkerware
com.android.system.update.serviceFlexiSPY / Masqueraded Agent
Amnesty MVT & ADB Non-Destructive Commands
# 1. Install Amnesty International Mobile Verification Toolkit (MVT)
pipx install mvt
mvt-android download-iocs

# 2. Non-Destructive ADB Package & Accessibility Triage
adb shell pm list packages -f -3 > installed_3p_apks.txt
adb shell settings get secure enabled_accessibility_services
adb shell dumpsys device_policy

# 3. Run MVT Against Android Backup / Bugreport or iOS Backup
mvt-android check-adb --output ./mvt_forensic_out
mvt-ios check-backup --iocs ~/.local/share/mvt/indicators ./ios_backup_dir
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Phone Stalkerware & Hidden Spy App Forensic Triage (MVT)](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/phone-stalkerware-mvt-forensic-triage/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/phone-stalkerware-mvt-forensic-triage/">Phone Stalkerware & Hidden Spy App Forensic Triage (MVT) — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Phone Stalkerware & Hidden Spy App Forensic Triage (MVT)

Quick Answer & 2026 Technical Summary (phone spyware forensic check mvt)Updated 2026 Standard

Stalkerware apps omit the `android.intent.category.LAUNCHER` intent filter in their `AndroidManifest.xml` or programmatically disable their main launcher Activity via `PackageManager.setComponentEnabledSetting()` immediately after initial setup, often disguising their Settings entry as 'System Sync' or 'Wi-Fi Service'. Use this interactive phone spyware forensic check mvt above to test hidden stalkerware package name scanner, mobile verification toolkit mvt command builder, and detect hidden spy apps android dumpsys locally in your browser with zero server uploads.

Target Keyword Spec: phone spyware forensic check mvt | Modules: Stalkerware Disguised Package & IOC Signature Matcher • Accessibility, NotificationListener & DeviceAdmin Auditor • Amnesty Tech Mobile Verification Toolkit (MVT) Command Builder
Primary Focus: phone spyware forensic check mvt
Core Capability: hidden stalkerware package name scanner
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Stalkerware Disguised Package & IOC Signature Matcherhidden stalkerware package name scannerMatch installed package lists (`pm list packages -f`) against deceptive sta...Domestic Coercive Control & Stalkerware Triage
Accessibility, NotificationListener & DeviceAdmin Auditormobile verification toolkit mvt command builderParse `adb shell dumpsys accessibility`, `notification`, and `device_policy...Journalist, Activist & Executive Mobile Forensics
Amnesty Tech Mobile Verification Toolkit (MVT) Command Builderdetect hidden spy apps android dumpsysGenerate ready-to-run `mvt-android` and `mvt-ios` CLI workflows with STIX2 ...Hidden Launcher-Less App & Battery Drain Investigation
Android OS Compatibility TargetAndroid 13 / 14 / 15 / 16 (API 33–36)AOSP + OneUI / HyperOS / Pixel UISupports modern Scoped Storage & ADB Wireless
Privilege & Safety BoundaryNon-Destructive User-Space DiagnosticsReversible via ADB / GSM MMI CodesPreserves OEM warranty & Knox fuse integrity
Telemetry Latency & Sampling60Hz – 240Hz Frame & Sensor Polling< 16.6ms Frame Budget (60 FPS Lock)Calibrated for mobile gaming & hardware triage
In-Depth ZerosUniverse Tutorial

How to Tell if Someone Has Hidden Spy Apps on Your Phone

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Phone Stalkerware & Hidden Spy App Forensic Triage (MVT)

01

Paste ADB Package List or Dumpsys Output (or Load a Preset)

Paste output from `adb shell pm list packages -f` / `dumpsys accessibility` or load a realistic Stalkerware-Infected vs Clean Android forensic sample.

02

Inspect Flagged Stalkerware Package Signatures & Masquerades

Review suspicious packages impersonating Google Play Services, System Update, or Wi-Fi Settings alongside their persistence hooks.

03

Audit Silent Surveillance Hooks (Accessibility & Device Admin)

Verify whether any non-system app has active `BIND_ACCESSIBILITY_SERVICE`, `BIND_NOTIFICATION_LISTENER_SERVICE`, or `BIND_DEVICE_ADMIN` privileges.

04

Export MVT Forensic CLI Commands & Safe Removal Plan

Copy the generated `mvt-android check-adb` commands and follow the OPSEC safety protocol before revoking device admin or factory resetting.

Key Capabilities & Technical Architecture

Stalkerware Disguised Package & IOC Signature Matcher

Match installed package lists (`pm list packages -f`) against deceptive stalkerware bundle IDs (`com.android.system.service`, `com.ws.sys`, `com.ring. internal`) that impersonate core OS services.

Accessibility, NotificationListener & DeviceAdmin Auditor

Parse `adb shell dumpsys accessibility`, `notification`, and `device_policy` outputs to expose silent screen-scrapers, WhatsApp message interceptors, and uninstall-blocked apps.

Amnesty Tech Mobile Verification Toolkit (MVT) Command Builder

Generate ready-to-run `mvt-android` and `mvt-ios` CLI workflows with STIX2 IOC feed integration for non-destructive forensic acquisition over ADB or encrypted iTunes backups.

Survivor-Safe Operational Security (OPSEC) Triage Checklist

Step-by-step domestic abuse and executive threat model guidance explaining how to inspect a device without triggering remote wipe alerts or tipping off the operator.

Practical Use Cases

Domestic Coercive Control & Stalkerware Triage

Identify commercial spouseware/stalkerware sideloaded onto a phone when physical lock-screen access was compromised, while preserving forensic evidence safely.

Journalist, Activist & Executive Mobile Forensics

Build MVT inspection pipelines to analyze SMS link history, WhatsApp databases, and Android APK hashes against Amnesty International's public STIX2 indicators.

Hidden Launcher-Less App & Battery Drain Investigation

Spot apps that hide their launcher icon (`setComponentEnabledSetting`) while holding persistent `FOREGROUND_SERVICE_MICROPHONE` or `ACCESS_BACKGROUND_LOCATION` wakes.

Frequently Asked Questions (FAQs)

How do commercial stalkerware apps hide from the Android app drawer?+

Stalkerware apps omit the `android.intent.category.LAUNCHER` intent filter in their `AndroidManifest.xml` or programmatically disable their main launcher Activity via `PackageManager.setComponentEnabledSetting()` immediately after initial setup, often disguising their Settings entry as 'System Sync' or 'Wi-Fi Service'.

Why shouldn't you immediately uninstall stalkerware if you suspect physical danger?+

Commercial stalkerware dashboards alert the buyer immediately when telemetry stops, when SIM cards change, or when Device Administrator privileges are revoked. Removing the app abruptly can escalate physical danger for domestic abuse survivors; safety planning from a separate, untrusted-free device should always come first.

What is the Mobile Verification Toolkit (MVT) created by Amnesty International?+

MVT is an open-source forensic tool (`mvt-ios` and `mvt-android`) designed by Amnesty International's Security Lab to analyze mobile backups, filesystem dumps, and ADB diagnostics against STIX2 indicators of compromise (IOCs) for both mercenary spyware (Pegasus, Predator) and commercial stalkerware.

How does stalkerware read encrypted WhatsApp or Signal messages without root?+

Even though WhatsApp and Signal use end-to-end encryption in transit, stalkerware abuses Android's `AccessibilityService` to scrape the plaintext UI hierarchy directly off the screen while you read or type messages, and uses `NotificationListenerService` to capture incoming message previews silently.

Does Play Protect detect sideloaded commercial stalkerware?+

Google Play Protect catches many known stalkerware families, but stalkerware installation guides routinely instruct the attacker to disable Play Protect and enable 'Restricted Settings' manually during physical installation. Checking Play Protect's toggle state is one of the fastest first-line indicators.