Skip to content

Threat actor

pcTattletale

Last fetched

pcTattletale is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

pcTattletale was a remote surveillance app, commonly referred to as "stalkerware", designed to secretly track people without their knowledge. The app allowed the person who planted it to remotely view screenshots and private data from the victim's Android or Windows device from anywhere in the world. Although pcTattletale marketed itself as a tool for monitoring employees, it also openly promoted its use for spying on spouses and domestic partners without their consent. The spyware required physical access to the target's device for installation and could be quickly deployed with just one click. The company also offered a "We Do It For You" service to assist in installing the spyware on a target's computer. According to TechCrunch, pcTattletale was used to compromise the front desk check-in systems at several Wyndham hotels across the United States, exposing screenshots containing guest details and customer information. The company has since ceased operations after a data breach.

Techniques by tactic

No ATT&CK techniques are recorded for pcTattletale in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to pcTattletale today — this states the absence of a published link, not that pcTattletale has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from pcTattletale into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.