DTEK not detecting a hidden GPS tracker called Traccar
Hello,
I thought it would be an interesting experiment to see how DTEK does against a purpose built GPS tracking application called Traccar. The tests were carried out first on a Priv, then a Key1 running the latest version of DTEK
www.traccar.org
They offer two versions of the app for Android - one of which is designed to be hidden from the target.
The hidden version is labeled as "Device Settings" with an appropriate icon. Once opened and closed for the first time by the attacker, the app is removed from the app launcher, but it appears under device settings and can be uninstalled.
The normal version is called Traccar and appears as such.
Both generate notifications when running, but these can be turned off by the attacker.
Both appear in DTEK's list of applications
The only visible indication to the user would be the GPS icon in the notification tray next to the WIFI signal meter, but this doesn't always stay on even if GPS is being used.
If the user dives into the security/location settings, they will see both as "recent location requests".
----
I first tested the hidden version. Once the service is started, the GPS icon appears at the notification bar, indicating that it is accessing GPS. Under Settings -> Security/Location, it appears as a "recent location request" as "Device Settings".
It also appears under Developer Tools -> Running Services as "Device Settings". Clicking this reveals "TrackingService" is running.
However, DTEK does NOT record any GPS access attempts from this hidden version of Traccar. Foreground or Background
----
I then tried their normal version. Just like the hidden version, the GPS icon appears in the notification bar indicating it is being used, and it too appears as a "recent location request" with a running service.
But in this case, DTEK DOES record its GPS access attempts in the Foreground only when first the service is first activated. It doesn't appear to be detecting background events while the app is running.
Thoughts? Maybe someone else would be willing to test this to see if they get the same results?
@bbwng
@BB_RobertL