Revealed Cyber Spies Used Malware from GitHub to Hack EncroChat Cryptophone Network
Revealed: Cyber Spies Used Malware from GitHub to Hack EncroChat Cryptophone Network
Computer Weekly reveals for the first time how French cyber spies hacked EncroChat phones, used by organized crime groups, in 2020. A Czech spyware company rehacked the French hack and found that French malware - described as a national security secret - had been copied from the popular code-sharing platform GitHub. The Czech rehack uncovered digital fingerprints matching French evidence sent across Europe, proving how messages had been copied.
The exposure of the French method, British lawyers say, is likely to restart a critical case into the legality of police tactics in EncroChat in Britain’s Investigatory Powers Tribunal, which has been adjourned for more than two years, awaiting a finding on how the hack was carried out. 🚨
The secret French state hacking group that broke into tens of thousands of encrypted secure phones in Europe used an Android exploit first spotted in 2017. For two years, a fatal security vulnerability, known as the Bad Binder bug, was left unpatched inside 2.5 billion phones, leaving users at maximum risk. The exploit allowed cyber spies to take complete control of infected phones and copy or change users’ data, programs, and files at will. A “groundbreaking” report by Czech researchers has revealed how the French “implant” relied on Bad Binder - and that its code was poorly written, prone to repeated failure, and lacked elementary countermeasures to avoid detection.
British lawyers say that if the full facts had been disclosed when trials started in 2020, it would be “open to question whether courts were properly informed”. Matthew Ryder KC, a leading lawyer in the UK’s first EncroChat trial, stated this investigation is a “landmark breakthrough,” adding, “It suggests that after six years, we may finally know the details of the EncroChat interception by the French authorities.”
Computer forensics and malware expert Felix Freiling, a professor at Friedrich-Alexander-Universität (FAU) in Germany, described the report as “unique [and] an impressive breakthrough”. The bug code uncovered by Czech cyber security company Invasys “looks like a student project”, Freiling noted, including apparently having copied exploit code from the internet. The new information will be “vital for EncroChat trials and appeals” in Europe, according to leading Dutch criminal lawyer Justus Reisinger. He added, “We can’t simply say ‘we trust the data’ while not being able to do proper research into the manner of obtaining it. That is vital to providing suspects with fair trials.”
In Britain, thousands of cases have been judged and sentenced without explanation of how the data was obtained, because French authorities stipulated that the way the hack was carried out was a matter of national security.
Police investigators were increasingly finding secure EncroChat brand phones at the scenes of crimes. Since 2017, collaborating European police agencies designated EncroChat as a criminally dedicated secure communications (CDSC) system. Despite major investigations in several countries, security hardening of EncroChat phones and the end-to-end encryption of chat messages proved impervious to many types of attack. Law enforcement agencies were locked out. The Gendarmerie - French police - had a lucky break. Late in summer 2019, Google’s threat teams were tipped off about an exploit powering Android malware used to spy on targets of the notorious Israeli cyber intelligence agency NSO Group and its Pegasus spyware system. The Pegasus bug tip-off proved to be the beginning of the end for EncroChat.
Typically costing over $1,000 for a six-month contract, EncroChat phones were expensive and never clever. They had no smartphone features. They could send messages or images, store notes, and might occasionally host phone calls. EncroChat phones were used to exchange highly secure messages and images between closed groups of users, suspected mainly to be criminal groups. All EncroChat messages were automatically wiped within 14 days, using a “burn time” chosen by the sender.