Close Menu
    What's Hot

    Dubai Cuts Deal For New Port to Bypass Strait of Hormuz

    Alejandro Garnacho transfer news: Aston Villa agree deal with Chelsea for winger | Football News

    China’s Open AI Models Are Challenging Silicon Valley’s Playbook

    Facebook X (Twitter) Instagram
    Trending
    • Dubai Cuts Deal For New Port to Bypass Strait of Hormuz
    • Alejandro Garnacho transfer news: Aston Villa agree deal with Chelsea for winger | Football News
    • China’s Open AI Models Are Challenging Silicon Valley’s Playbook
    • Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
    • Opinion | The Rise of Loneliness Influencers
    • Trump’s Iran Quagmire Is Here
    • Dyson V10 Konical Review (2026): Affordable and Solid
    • Teledyne Technologies Incorporated (TDY) Q2 2026 Earnings Call Transcript
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Android Adds Intrusion Logging for Sophisticated Spyware Forensics

    adminBy adminMay 13, 2026No Comments6 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Android Adds Intrusion Logging for Sophisticated Spyware Forensics
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Android Adds Intrusion Logging for Sophisticated Spyware Forensics

    Google on Tuesday unveiled a new opt-in Android feature called Intrusion Logging for storing forensic logs to better analyze sophisticated spyware attacks.

    Intrusion Logging, available as part of Advanced Protection Mode, enables “persistent and privacy-preserving forensics logging to allow for investigation of devices in the event of a suspected compromise,” the company said.

    The feature, it added, was developed in partnership with Amnesty International and Reporters Without Borders. According to a help document shared by Google, it logs device and network activities on a daily basis, including information about device behavior and the various applications that run on it.

    The kinds of activities recorded are listed below –

    • App activity (e.g., when an app process starts)
    • App installations, updates, and uninstalls
    • Network connections like starting and stopping Wi-Fi, Bluetooth, DNS lookups, and IP addresses
    • File transfers to or from the device over USB
    • Changes to system certificates
    • When the device is locked or unlocked

    Google also noted that the log data is end-to-end encrypted by the device and stored on Google servers. The encryption keys are secured by Google Account password and screen lock credentials, meaning the logs cannot be accessed by any third-party, including Google itself, apart from the device owner.

    Cybersecurity

    “By storing the data on a secure server, even malware installed on the smartphone cannot access, delete, or manipulate it,” Reporters Without Borders said. “End-to-end encryption also ensures that neither Google nor state actors can access the data. The Intrusion Logging function in particular enables detection and forensic analysis of even highly sophisticated and previously difficult-to-detect attacks.”

    The encrypted logs are stored for a period of 12 months, after which they are automatically wiped. Once Intrusion Logging is enabled, a user cannot delete the logs before the 12-month expiration window, even if the account is closed or the feature is turned off. Users have the option to download the logs offline, should they prefer to keep them for longer periods.

    That said, Google has emphasized that once the logs are downloaded and decrypted, users are responsible for their security. “In certain legal or regulatory environments, you may be required by law to provide access to your decrypted data or your security credentials,” it pointed out.

    Another thing to keep in mind when enabling the feature is that it also records network events generated during Chrome Incognito browsing, such as DNS lookups and IP connections, as it operates at the system level and does not distinguish between the browsing modes. In other words, anybody with access to the decrypted logs can glean what websites were visited, but cannot infer specific pages on those sites.

    The motivation behind Intrusion Logging is that a high-risk individual, who suspects they may have been targeted by advanced surveillance tools because of who they are and what they do, can share the activity log with trusted security experts for detailed examination.

    The logs can be downloaded by navigating to the Settings app, and then tapping Security & privacy -> Advanced Protection -> Intrusion Logging -> Access logs. The feature is currently rolling out to all devices running the Android 16 December update and newer.

    “With Intrusion Logging, Google is the first major vendor to proactively address the challenge of detecting advanced attacks on devices,” Donncha Ó Cearbhaill, head of Security Lab at Amnesty International, said in a statement. “By making more consensual forensic data available for researchers, we can make life more difficult for attackers and help civil society seek accountability when their devices are unlawfully targeted by spyware and mobile data extraction tools.”

    Other Privacy and Security Features Coming to Android

    Besides Intrusion Logging, Google has announced a raft of privacy and security improvements, including verified financial calls, a new phone call spoofing protection feature to combat attacks where scammers impersonate banks to trick users into revealing sensitive data or transferring funds. 

    When users receive a call that appears to be from a participating bank, Android asks the installed online banking app to confirm if they are actually attempting to reach the customer. If the app confirms no such is being made, the call is automatically ended by the system.

    “Your bank or financial institution may also designate numbers as inbound-only, meaning they never use them to call customers,” Google said. “Incoming calls from these numbers will be ended directly.” The feature is expected to go live on Android 11+ devices with Revolut, Itaú, and Nubank in the coming weeks, before expanding to more banks later this year.

    Cybersecurity

    Other notable changes are listed below –

    • Expanding Live Threat Detection to issue warnings about suspicious app behavior, including SMS forwarding and accessibility overlays that are typically used by Android banking trojans to steal credentials.
    • Evaluating downloaded APK files via Chrome on Android for known malware when Safe Browsing is enabled before it’s installed.
    • Removing access to the accessibility services API from all apps that are not labeled as accessibility tools.
    • Disabling device-to-device unlocking and Chrome WebGPU support.
    • Adding scam detection for chat notifications.
    • Enhancing Find Hub’s Mark as lost feature with the ability to lock a phone with biometric authentication, blocking thieves from turning off device tracking if a device is marked as lost. Triggering Mark as lost also turns on additional protections like hiding Quick Settings and disabling new Wi-Fi and Bluetooth connections.
    • Reducing the number of times a third-party with physical access to a device can guess the PIN or password, in addition to implementing longer wait times between failed attempts.
    • Improving device recovery by making a device’s IMEI number accessible via the lock screen on devices running Android 12 or higher.
    • Better privacy controls that allow users to share their precise location temporarily for specific tasks while a specific app is open, and provide access to specific contacts to a third-party app, as opposed to sharing the entire address book.
    • Introducing AISeal with pKVM for hardware-backed, on-device isolation of artificial intelligence (AI)-related data processing.
    • Expanding Binary Transparency in Android to ensure integrity through verification of official builds and a public ledger for authentic Google apps and foundational GMS APIs.
    • Hiding SMS one-time passwords (OTPs) from most apps for three hours to block OTP theft by malicious apps that have been granted the SMS permission.
    • Giving carriers the ability to disable 2G by default to shield customers from legacy technology vulnerabilities.
    • Hardening data protection by introducing post-quantum cryptography to safeguard against future threats.
    • Incorporating explicit user controls to opt-in and out of entire features, security guardrails, and transparency when using Gemini on Android.

    “By improving protections against banking scams, and extending powerful protections like Live Threat Detection and Android Advanced Protection, we are ensuring that Android remains the most secure platform,” Eugene Liderman, director of Android security and privacy, said.

    adds Android Forensics Intrusion logging Sophisticated spyware
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article3 ways to appear smarter than you are
    Next Article Meta Is Facing Another Lawsuit Over Scam Ads On Facebook And Instagram
    admin
    • Website

    Related Posts

    Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

    July 22, 2026

    Google is making it easier to switch from iPhone to Android

    July 22, 2026

    The Fastest Path to AI Adoption Runs Through Security

    July 22, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Dubai Cuts Deal For New Port to Bypass Strait of Hormuz

    Alejandro Garnacho transfer news: Aston Villa agree deal with Chelsea for winger | Football News

    China’s Open AI Models Are Challenging Silicon Valley’s Playbook

    Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by