HomeSecurityPredator inside story: SMS the key to wiretapping research

Predator inside story: SMS the key to wiretapping research

Wiretapping: Revelations continue about the Predator spyware marketed by the company Intellexa and its use by the Greek government to attempt to monitor politicians and journalists.

Predator spyware aims to intercept users' information and communications and behaves like many malicious software out there - you need to allow it to infect you by clicking on a phishing link that will be sent via email, SMS, app, etc. Then, once it manages to invade, it has full control of the victim's device, meaning it has the ability to record the screen image and the camera, open the microphone and record sounds of the surrounding environment, record the keys we press on our device, get our geographical location, and much more.

See also: Predator scandal: How Tal Dillian tried to save his image

predator
Data Protection Authority on Predator: Over 20 targets in Greece

See also: How Sudan is connected to the Predator scandal that is shaking Greece

Although commercial spyware is intended to hack phones used by illegal networks and groups, it has been discovered that many authoritarian regimes but also democracies have abused this power to spy on political figures and journalists with whom they disagree.

Let's now see what has happened in the Greek Predator Scandal

The beginning of the allegations of Predator surveillance was made by Inside Story in April 2022 with journalist Thanasis Koukakis. The Citizen Lab at the University of Toronto conducted a forensic investigation and found evidence supporting his claim. This was the first confirmed illegal surveillance of a European citizen's communications with the Predator spyware, commercially owned by Intellexa. Nikos Androulakis, president of PASOK-KINAL, and politician Christos Spirtzis were then added to the list. All three of them assumed that the Greek state had ordered their surveillance and took legal action by filing lawsuits. Of course, the list of people who have fallen victim to Predator is constantly growing.

In August, Mr Mitsotakis’ nephew Grigoris Dimitriadis resigned from his position overseeing the national intelligence service amid a spyware scandal, although he denies any involvement. Around the same time, the prime minister fired the head of the national intelligence service. That same month, Intellexa laid off most of its Athens-based staff.

In September 2022, SecNews published its own technical analysis in which it tried to contribute to revealing the truth about the surveillance. The research analyzed domains-traps that were used to infect victims with malware. The findings reveal another dark side of organized crime and how Greek banking institutions and major companies are related. Read our technical analysis here.

In November, the European Parliament's Committee for the Investigation of Surveillance, PEGA, visited Greece and Cyprus with the aim of conducting an investigation into surveillance software as what was happening in the country alarmed them.

In December 2022, following the events and the growing list, the Greek government admitted to the NYT, which conducted its own investigation, that it had given the company Intellexa a license to sell the Predator product in other countries.

This week, the Hellenic Data Protection Authority (HDPA) imposed a €50,000 fine on Intellexa , finding that the company is unreasonably delaying delivering the data in possession to complete the audit of the wiretapping case.

See also: NoReboot bug: iPhone Backdoor that goes undetectedand resembles Predator

Data Protection Authority on Predator: Over 20 targets in Greece

Today Inside Story continues the revelations and reports that according to the Data Protection Authority, more than 20 were targeted in Greece. Let's take a closer look at what exactly the news report says.

The tangle of the Predator case seems to be slowly unraveling by the Hellenic Data Protection Authority (HDPA), which for the past six months has been silently conducting its own ex officio inspections into the use of spyware to monitor terminal devices of individuals within Greek territory.

What has the Data Protection Authority found?

Perhaps the most important of the findings of the Personal Data Protection Authority's audit so far, as revealed by its official responses to inside story questions, is the identification of approximately 40 text messages containing Predator-infected links, which have been sent to "just over 20" mobile phone numbers.

It should be noted that the Authority's investigation is still ongoing, so this number is likely to increase until it is completed. Simply put, the checks certify that Predator's targets in Greece exceed twenty. This is something that the inside story has been emphasizing since the first part of its revelations, when the government was attempting to present the Koukakis case as an isolated incident behind which an individual and not the government itself was hiding. In May 2022, before we learned about the Androulakis case, in our report titled: “There was not just one target of surveillance with spyware”, we wrote: “New evidence that we are bringing to light about a complex network of infected websites set up to trap targets within the borders leads to a logical conclusion: Journalist Thanasis Koukakis is not the only Greek whose mobile phone was illegally monitored. It is possible that even armed forces officers are on the list."

See also: Predator software: The second shareholder of Intellexa

We returned to the subject with a new article, the day after Androulakis' complaint. In it, citing communication we had with Google, we wrote that the company's risk analysis team estimated that according to the data it had collected up to that point in Greece, there was a single-digit number of targets who had Android phones. Koukakis and Androulakis have iPhones.

Data Protection Authority on Predator: Over 20 targets in Greece

Inside Story asked questions to the Anti-Money Laundering Authority on Tuesday, January 17, 2023, following the fine of 50,000 euros (which could reach 10 million euros) imposed on Intellexa, which markets Predator, for the company's non-cooperation with the Authority during its inspection process and following two publications – in the newspapers "To Vima" on 15/1 and "Ta Nea" on 16/1 – which referred to "20 decoy messages" that have been identified as part of the Authority's investigation into Predator and its ongoing inspections of "mass SMS (ed.: sms centers)".

In its responses, the APDPH states that "to date the Authority has addressed four such companies (ed.: sms centers) in Greece. As the process is ongoing, at this stage we cannot know whether these will be the last in Greece or not. In cases where companies are located outside Greece - as has already been established- but within the European Economic Area, the Authority has the possibility to request cooperation from the respective counterpart supervisory authorities". It also emphasizes that: "To date, around 40 SMS have emerged but the investigation is ongoing" and that these "have been sent to just over 20 numbers". Therefore, each target has received more than one SMS-bait.

See also: Predator Greece: What is Felix Bitzios' relationship with Intellexa?

What do SMS centers know?
A source with good knowledge of the methodology followed in such technical checks, reports in the inside story, that since the bait message has been sent from a Greek SMS center, then the person or persons who purchased the service with the intention of infecting have provided a mobile phone number and a credit/debit card number in order to complete the purchase. Greek mass messaging platforms have a 2FA system, which means that in order to activate the service, an SMS with a confirmation code must first be sent to the customer, while payment for the service is not made anonymously, e.g. with cryptocurrencies, but requires a bank card.

In addition to the SMS centers, the Authority points out that “checks are being carried out on companies that are in any way connected to Intellexa and the data resulting from the investigation.” Given that this data has been collected following an ex officio inspection by the Authority and a complaint from a person, it can be concluded that it is quite possible that among these “just over 20 numbers” that have received infected SMS messages, there are also people who have no idea that they have been the target of illegal surveillance with Predator or, even worse, that they have actually been trapped with this particular spyware.

The software that brutally attacks privacy
Predator, once it infects the target's device, turns it into the ultimate bug. Its operator can see and hear everything the person who has been trapped types or says on the phone (even if they use encrypted applications for their communications), have access to their contacts as well as to files stored on their device (e.g. photos). The most painful feature of spyware that brutally attacks privacy is that it can activate the camera and microphone of the mobile phone and have at any time the image and sound of the most personal moments of the victim and his environment (family, friends, professional). Even worse, the material from the use of legal surveillance (through declassification under the pretext of national security) or completely illegal (with Predator), as some of the protagonists of the wiretapping and has been proven by publications with dialogues from connections, also exists in hands outside the EYP and can be used as desired during the election campaign.

See also: Predator surveillance: This is how they targeted politicians, citizens and companies!

"In a democracy, the surveillance of people should be an exception and there should be rules. And it should not be possible to abuse it for political purposes. For party purposes, or to stay in power, manipulate elections or cover up corruption," Sophie in 't Veld, the rapporteur of the European Parliament's PEGA committee investigating the abuse of spyware in EU member states, including Greece, had said from Athens.

Why are the findings of the Data Protection Authority important? Read more in Inside Story.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS