Domestic stalkerware, the jealous partner's malware

Stalkerware Spyzie, Cocospy, Spyic, over 3 million victims combined. Your iPhone drained via your Apple ID. How to check and take back control.

On May 26th, Joseph Cox of 404 Media interviewed Zack Whittaker, the journalist who’s been leaking pretty much all the major consumer stalkerware cases for the past five years. Verdict? It’s not a niche market, it’s a mass market. Hundreds of thousands of victims on just one network. Targets iPhones and Androids. Installation by your partner, ex, roommate, in two minutes while you’re in the shower.

The Deal

Stalkerware is spyware sold to Joe and Jane Public. Not Pegasus, not Predator, not the mercenary spyware grade that Citizen Lab tracks from Toronto. The stuff you install on your girlfriend’s phone to read her messages, listen to her calls, track her location, and turn on her mic remotely. Brands like Spyzie, Cocospy, Spyic, mSpy, TheTruthSpy.

Whittaker’s been leaking these since 2021. The latest wave, February 2025, exposed 518,000 Spyzie clients including at least 4,900 compromised iPhones, and 2.65 million email addresses on the twin network Cocospy + Spyic. That’s over three million victims just from this one family of operators.

Monthly subscription? Thirty to seventy dollars for the standard plan, more if you add premium modules like mic and cam access. Companies live in offshore holdings, Cyprus, British Virgin Islands, or straight out of China. Cocospy, Spyic, and Spyzie are all the same team, traced back to one Chinese operator by Whittaker.

mSpy runs the same business model under a separate brand, legacy Cyprus-Ukraine. When leaks expose them, they shut down and reopen under a new name. Market size? Around $145 million a year, according to Future Market Insights.

On the iPhone side, the dominant method doesn’t even need physical access. Your partner knows your Apple ID password because you shared it, they’ve seen your iPhone unlock a hundred times, or you’ve used the same one for fifteen years. They log in to iCloud via browser, download your backups, and the stalkerware app does its thing server-side. No app on your phone, nothing to detect locally. Exactly how Whittaker documented Cocospy, Spyic, and Spyzie in 2025.

Rarer but more comprehensive variant: a configuration profile MDM, the mechanism designed for managing business fleets. The close one installs the stalkerware app via Apple Configurator on their Mac, supervising your phone with a Lightning or USB-C cable. The profile’s marked removalDisallowed, named something innocuous like “iOS Update” or “Battery Optimizer”. A Screen Time password your partner set hides the “Device Management” entry in Settings. You’re clueless. On Android, it’s the app disguised as a system tool, hidden behind a generic name, with accessibility turned on to read everything for you.

Why This Matters to You

Here’s where the usual cybersec press coverage drops off. We hear a lot about the mercenaries, NSO, Intellexa, Paragon, the billion-euro budgets and diplomatic targets. But the statistical danger for you? It’s not some state watching you, it’s your ex stalking you. States have their part too, pushing for mass control legislatively, as I’ve broken down in Six Months and Nineteen Global Texts, the Terrible Convergence. But the sheer frequency of domestic victims trumps all.

Whittaker’s been saying since 2021 that domestic stalkerware outdoes all mercenary spyware combined. The press ignores it because it’s dirty, intimate, lacks Pegasus’ geopolitical cachet.

Information asymmetry is total. Buyers find these products in three clicks: fake “Top 10 spy apps” sites owned by sellers, SEO on jealous searches, Reddit with affiliate accounts, TikTok in “POV I hooked my guy” format, Google Ads hijacked on “Find My iPhone” or “family locator”.

Marketing facade: “parental control for kids” quickly pivots to “monitor your spouse”. Potential victims never search for “stalkerware”. They don’t even know it exists. That’s the definition of a threat you don’t see coming.

You’re the target. Couple with iPhone and Mac, integrated Apple ecosystem, shared iCloud family, common passwords “because we trust each other”. When trust cracks, siphoning takes a few clicks from a browser, or two minutes MDM installation while you’re out. You’ll only know reading this.

What You Do Now

1. Check your iPhone, configuration profiles, and Screen Time.
Settings, General, VPN & Device Management. If you see a profile you didn’t install, especially with a vague name like “iOS Update”, “Battery Saver”, “Profile Service”, delete it. Then Settings, Screen Time. If a password’s active and it’s not yours, disable via your Apple ID. That password often hides the VPN & Device Management entry. If the delete button’s greyed out or the profile returns after “Reset All Settings”, it’s removalDisallowed with active DEP supervision: need Apple Store server-side break. Apple reference: remove a configuration profile.

2. Take back control of your critical accounts.
Change your Apple ID password immediately and enable two-factor authentication with a number your close circle doesn’t control. Check the list of devices connected to your Apple ID in Settings, top. Any unknown device, delete it. Enable Advanced Data Protection for end-to-end encrypted backups, server-side exfiltration becomes useless.

3. Switch to E2EE tools for sensitive stuff.
Critical messages on Signal, not iMessage. Passwords in your own manager, Bitwarden self-hosted or KeePassXC local file, not a shared Apple Keychain. Local encrypted backups on external drive, not just iCloud.

4. If you suspect active installation, leave the physical perimeter before acting.
Stalkerware with mic and GPS rats you out in real-time. Contact specialized help services from an unsurveilled device and network. The Coalition Against Stalkerware lists resources by country and a response kit for victims.

Sources

Tech terms? Check the glossary.