EncroChat hack: "Bad Binder" flaw at heart of French operation

A 146-page report by Czech cybersecurity firm Invasys reveals that French authorities exploited the Android "Bad Binder" flaw to infiltrate EncroChat.

EncroChat hack: "Bad Binder" flaw at heart of French operation

The "Bad Binder" vulnerability at the heart of EncroChat hack by DGSI

A 146-page report from Czech cybersecurity firm Invasys partially lifts the veil on the technical methods employed by French authorities to hack the secure messaging platform EncroChat. According to ZDNet France, which draws on an article from Computer Weekly, gendarmes and specialists from the Directorate General of Interior Security (DGSI) are said to have combined the Android "Bad Binder" flaw with the cybersecurity tool "Frida" to infiltrate the platform's infrastructure.

Until then, the technical details of the operation remained largely confidential. When this spectacular crackdown was revealed in July 2020, the two key technical devices were covered by national defence secrecy. The gendarmes had simply acknowledged using automatic telephone updates to deploy their device.

A fake update as infection vector

Before British courts, experts had clarified the overall mechanism: malicious software transmitted to users in the form of a software update, made possible by the prior takeover of EncroChat's update server. It was a British court ruling that subsequently opened the way for Invasys to study seized EncroChat telephones.

The firm was thus able to identify traces of "Bad Binder" launching at startup on devices infected by this fake update. Reported by Google researchers in October 2019, this vulnerability allows total access to an Android device. At the time, these researchers considered it likely that NSO Group, the manufacturer of Pegasus spyware, had already seized this flaw.

"Frida", a real-time surveillance tool

In addition to "Bad Binder", French authorities are also said to have relied on "Frida", a cybersecurity toolbox which, once installed on a telephone, allows processes to be tracked and interrupted in real time. Computer Weekly sums up the whole thing as a "dream spyware" for surveillance operators.

This technical combination constitutes, six years after the events, the most precise description ever released publicly of the means deployed during this international interception operation.

A considerable judicial outcome

In a report published in June 2023, the Europol agency reported approximately one hundred murder plots identified thanks to the intercepted data, hundreds of tonnes of drugs seized, and 6,558 suspects arrested across Europe.

Two Canadian nationals, accused of being respectively the boss and technical director of EncroChat, were extradited to France. The date of their trial is not yet known.

A persistent legal debate

The operation continues to provoke contestation. Its detractors argue that it allowed law enforcement to carry out a massive data collection, deemed too broad and outside the legal framework for interceptions. The prosecution, meanwhile, contends that the messaging platform was designed "to order" for criminals, which would justify the means employed.

The revelation of the role of "Bad Binder" reopens questions about the boundary between judicial police operation and offensive exploitation of computer security flaws — a debate that remains unresolved before several European courts.

Source: ZDNet France

Read this article in the original language