HomeIntelligenceBrief
BREACH BRIEF🟡 Medium ThreatIntel

ESET Highlights Surge in Android Stalkerware and Persistent Windows XP Exploits at RSA 2021

ESET’s RSA 2021 research shows a 48 % jump in Android stalkerware detections and demonstrates how vulnerable Windows XP binaries still enable attacks on modern systems; both trends underscore the need for continuous control‑assurance and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 eset.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
eset.com

Android Stalkerware Surge & Legacy XP Exploits Spotlighted at RSA 2021

What Happened – ESET researchers presented new findings at RSA 2021 on two fronts: (1) a 48 % year‑over‑year rise in detections of Android stalkerware, with more than 80 families examined and critical privacy‑related code flaws uncovered; (2) continued abuse of vulnerable Windows XP binaries that can be leveraged on modern systems via “living‑off‑the‑land” techniques, extending the attack surface of legacy code.

Why It Matters for Trust & Control Assurance

  • Unvetted mobile apps bypass traditional endpoint controls, creating a blind spot for data‑exfiltration monitoring – a scenario continuous control‑assurance programs must detect and evidence.
  • Legacy binaries that remain executable on current OSes undermine baseline hardening controls; without systematic evidence of remediation, audit readiness is weakened.
  • Mapping these emerging threats to a unified control set (e.g., access, configuration, monitoring) demonstrates due‑diligence across multiple frameworks.

Who Is Affected – Enterprises with BYOD or mobile‑first workforces, organizations still running legacy Windows components, and any entity responsible for protecting personal data on mobile devices.

Recommended Actions

  • Conduct a mobile‑app inventory and enforce strict vetting/MDM policies to block unauthorized stalkerware.
  • Identify and isolate legacy XP DLLs or binaries; apply compensating controls (application whitelisting, sandboxing) where removal isn’t feasible.
  • Capture continuous evidence of these controls (policy enforcement logs, endpoint telemetry) to support audit and compliance reviews. Source: ESET RSA 2021 announcement

Technical Notes

  • Stalkerware apps exploit Android permissions and insecure data‑transmission APIs, enabling covert collection of contacts, location, and microphone/audio.
  • XP exploits rely on vulnerable DLLs that can be invoked by signed system tools, allowing privilege escalation even on non‑XP hosts. Source: same as above
📰 Original Source
https://www.eset.com/int/about/newsroom/press-releases/events/eset-comes-to-rsa-conference-2021-with-research-on-android-stalkerware-and-xp-exploits-2/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →