How Vietnam-based 1Byte, which sells TheTruthSpy stalkerware, created networks of fake sellers with forged US passports to evade detection and funnel payments
Context & Ripple Effects
1Byte's TheTruthSpy operation has been unraveling in public for over a year: TechCrunch first traced nine Android spyware apps on roughly 400K phones back to 1Byte-controlled servers, then a leak of TheTruthSpy's own data showed the network tracking calls and locations of hundreds of thousands of people.
What today's reporting adds is the money trail: the Vietnam-based operator didn't just hide its apps, it manufactured entire seller identities — complete with forged US passports — so payment processors would see a spread of unrelated merchants rather than one stalkerware business. That puts it in the same lane as the scammers later shown defeating banks' KYC facial scans with stolen biometrics and virtual cameras: identity verification as the attack surface.
First-order effects
- Payment processors that onboarded these fake sellers were unknowingly clearing revenue for a stalkerware network already tied to hundreds of thousands of tracked victims — every one of those merchant accounts is now a compliance liability they must unwind.
Second-order effects
- Other commercial spyware vendors relying on reseller fronts face heightened scrutiny, since investigators now have a documented template — forged passports plus layered fake sellers — for piercing the same structure elsewhere.
Third-order effects
- If forged identity documents can pass merchant KYC at scale, the burden shifts from catching individual bad merchants to verifying the authenticity of identity documents themselves — an arms race that document-forging operations like the Vietnamese identity-theft service sentenced in 2015 foreshadowed long ago.
The trend: Commercial spyware operators are industrializing identity fraud to keep payment rails open, making KYC integrity the choke point regulators and processors will fight over next.