Apps & Consumer
Google launches Android feature to help track spyware attacks
Google is rolling out Intrusion Logging for Android, an opt-in feature designed to help security researchers investigate government spyware attacks and police forensic device activity.
Google is rolling out a new opt-in feature in Android called Intrusion Logging to help security researchers investigate spyware attacks. The feature is part of Android’s Advanced Protection Mode—an Android opt-in security mode designed to counter government spyware attacks and police forensic devices. These two types of threats can be combined; in at least one documented case in Serbia, authorities used a forensic tool made by Cellebrite to unlock a device and then installed spyware to continue monitoring the target.
The feature was developed in collaboration with Amnesty International. Donncha Ó Cearbhaill, the head of Amnesty’s Security Lab, who has investigated spyware abuse cases around the world, noted that Android’s technical limits have historically made it difficult to deeply analyze system logs and files for signs of compromise. According to Amnesty International, the new feature represents “a fundamental shift in the amount and quality of forensic data available on Android devices.” Previously, forensic analysis relied on logs that were never designed for intrusion detection, which made it difficult to reliably detect known attacks.
Intrusion Logging, which Google stated is currently rolling out to all devices running the Android 16 December update and newer, creates daily logs and stores them encrypted in a user’s Google account. Uploading logs to the cloud potentially prevents spyware from deleting evidence of a device compromise. The feature tracks events such as when the phone was unlocked, app installations, connections to a malicious website, and connections to the Android Debug Bridge—a tool allowing a computer connection to an Android device. These logs can help investigators determine if a phone was targeted with spyware or stalkerware.
Google’s Advanced Protection Mode is similar to Lockdown Mode on Apple devices, which is also aimed at protecting at-risk users from spyware. In March, Apple stated it had never detected a successful attack against users with Lockdown Mode enabled. Additionally, in 2023, research by Citizen Lab showed that Lockdown Mode blocked an attempt to infect a target with spyware developed by NSO.
While the feature improves mobile forensics, Intrusion Logging has several limits. For now, the feature’s requirements include:
- Enabling Advanced Protection Mode
- Running the latest Android software version (Android 16 or newer)
- Using Google-made Pixel devices
- Linking the device to a Google account
Why it matters
This marks the first time a smartphone manufacturer has built a native feature specifically to assist security researchers in investigating spyware, potentially closing a critical gap in mobile forensics.