SpyX
SpyX is identified in the provided content as a spyware maker and consumer-grade spyware operation. In June 2024, SpyX suffered a data breach that exposed nearly 2 million users or unique email addresses. Exposed data reportedly included IP addresses, countries of residence, device information, and 6-digit PINs stored in the password field. The breach also contained roughly 17,000 plaintext Apple Account/iCloud credentials, including target email addresses and plaintext Apple passwords, which were likely used to monitor targets directly through the cloud. Troy Hunt of Have I Been Pwned verified the legitimacy of the leaked SpyX records. The breach data was flagged as sensitive and is not publicly searchable. The content also states that Google removed a Chrome extension associated with SpyX. No specific threat actor attribution, malware family relationships, or additional infection vectors are provided beyond its operation as spyware and its apparent use of cloud account credentials for monitoring targets.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SpyX is described as spyware. The breached data included email addresses, IP addresses, countries of residence, device information, 6-digit PINs, and iCloud credentials including plaintext Apple passwords, indicating it was used to monitor targets, including via cloud account access.
A consumer-grade spyware product/operation; discussed here in the context of its own data breach exposing user data and plaintext Apple Account credentials.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.