FBI paid renegade developer $180k for backdoored AN0M chat app that brought down drug underworld
- Reference: 1623193122
- News link: https://www.theregister.co.uk/2021/06/08/fbi_trojan_shield/
- Source link:
About 12,000 smartphones with [1]AN0M installed were sold into organized crime rings: the devices were touted as pure encrypted messaging tools — no GPS, email or web browsing, and certainly no voice calls, cameras, and microphones. They were "designed by criminals, for criminals exclusively," one defendant told investigators, Randy Grossman, Acting US Attorney for the Southern District of California, told a press conference on Tuesday.
However, AN0M was forged in a joint operation by Australian and US federal law enforcement, and was deliberately and surreptitiously engineered so that agents could peer into the encrypted conversations and read crooks' messages. After Australia's police [2]broke the news that the messaging app had recorded everything from drug deals to murder plots — leading to hundreds of arrests — now the FBI has spilled its side of the story, revealing a complex sting dubbed [3]Operation Trojan Shield .
[4]
The Dept of Justice's Randy Grossman walks through journalists through Operation Trojan Shield at a press conference on Tuesday
"For the first time the FBI developed and operated its own hardened encrypted device company, called AN0M," Grossman said.
"Criminal organizations and the individual defendants we have charged purchased and distributed AN0M devices in an effort to secretly plan and execute their crimes. But the devices were actually operated by the FBI."
Playing the long game
According to court documents
[5]PDF
this all came about after the shutdown of Phantom Secure, a Canadian biz selling Blackberry phones customized for encrypted chat to the criminal community. CEO Vincent Ramos [6]pleaded guilty in 2018 to conspiring with drug traffickers and [7]was sentenced to nine years behind bars and had $80M in assets seized.The closure of Phantom Secure put the staff working there on the FBI's radar. The bureau's San Diego office recruited a developer at the company as a confidential human source (CHS), court documents state. This source had previously been sentenced to six years in the clink for importing illegal drugs, and agreed to cooperate with the Feds to reduce any future punishment potentially coming their way.
[8]
Crucially, not only had this programmer worked on the Phantom Secure's encrypted messaging software, but they were also doing work on rival encrypted comms service [9]Sky Global — which also sold modified handsets with secure messaging features — as well as developing their own secure customized phone called AN0M.
[10]Australian cops, FBI created backdoored chat app, told crims it was secure – then snooped on 9,000 users' plots
[11]Belgian police seize 28 tons of cocaine after 'cracking' Sky ECC's chat app encryption
[12]US govt indicted me because I make privacy tools, says crypto-chat app CEO accused of helping drug smugglers
[13]Blessed are the cryptographers, labelling them criminal enablers is just foolish
"The CHS … had invested a substantial amount of money into the development of a new hardened encrypted device," the indictment by FBI Special Agent Nicholas Cheviron reads.
"The CHS offered this next generation device, named 'AN0M,' to the FBI to use in ongoing and new investigations. The CHS also agreed to offer to distribute AN0M devices to some of the CHS’s existing network of distributors of encrypted communications devices."
[14]
[15]
And so, in October 2018, the three-year sting operation began.
The CHS — who was paid $120,000 plus $59,000 in living and travel expenses by the authorities — worked with the FBI and the Australian Federal Police to hide a master decryption key into the AN0M app. Messages sent by the software's users were quietly copied and sent off to servers controlled by law enforcement, who were able to use the key to decrypt the texts. Technically speaking, each message is effectively BCC'd to a so-called iBot server located outside the United States that strips away the AN0M-level encryption, and re-encrypts the text for law enforcement. This text is then sent to another server, where the contents can be decrypted and viewed by investigators.
[16]
The first three distributors for AN0M were based Down Under. As the Australian authorities were ahead of the FBI in getting a legal framework in place to snoop on these conversations, the Oz cops were first in examining the chatter — albeit just conversations involving users either in Australia or with a nexus to it. Presumably, the AN0M app was set up to send the messages to a server in Australia's jurisdiction.
In this beta test, 50 handsets were passed out Down Under, and this phase of the operation was successful; two of the country's biggest criminal gangs were successfully penetrated and the message copying system worked perfectly. Aussie police reviewing the texts said they found 100 per cent were related to crime. Everyone who used the app was assigned a unique ID, and these handles were known to the police.
Let's go global
In the next phase, the CHS expanded the distribution network beyond Australia, and the FBI found itself in a position to collect the data. After negotiations with an unnamed third country, a message-relaying iBot server was set up in that nation to collect the BCC'd conversations, and on October 21, 2019, it began beaming copies of crooks' chats from AN0M handhelds to an FBI-owned system every Monday, Wednesday, and Friday. The third country's officials had secured a court order for the surveillance, and the FBI used a Mutual Legal Assistance Treaty, also known as an [17]MLAT , to obtain the decrypted material.
Sales of AN0M grew steadily, and got a boost when French and Dutch police [18]took down the EncroChat encrypted service in 2020. When a similar swoop [19]shuttered Sky Global in 2021, demand skyrocketed. After the latter take-down, AN0M sales tripled to more than 9000 handsets, each costing $1700 with a six-month subscription to the AN0M encrypted messaging network, Grossman said.
The data haul from the application was immense: more than 27 million messages from 100 countries, and between 300 criminal gangs. This included more than 400,000 photos, typically of drugs or guns and, crucially, shipment plans.
[20]
A photo shared via the app. It's tuna surprise. The surprise being there's no tuna. It's coke. Source: DoJ. Click to enlarge
Belgian police, tipped off by the AN0M data, in 2020 captured 613 kilos of cocaine hidden in tuna cans. These were traced to an Ecuadorian supplier, who was caught with another 1523 kilos of coke in a container that would have shipped to Antwerp.
[21]
Would make for one hell of a Hawaiian pizza — cocaine-stuffed pineapples. Source: DoJ. Click to enlarge
After intercepting chat about cocaine shipments, on May 12 this year Spanish police seized 1595 kilos of cocaine hidden in hollowed out pineapples. The delivery, from a supplier in Costa Rica, had an estimated street value of $70M.
Police around the world have made 800 arrests from AN0M-gathered intelligence, including cuffing six US law enforcement officers. Of all of those detained, they primarily face charges of drug trafficking, money laundering, gun violations, and violent crime.
[22]
Grossman also announced Uncle Sam had indicted 17 suspects on RICO charges relating to the use and marketing of the AN0M handsets. Most of these people are said to be distributors, though the prosecutor said three were administrators who helped run the service. Eight of those RICO suspects have already been collared and detained.
"Operation Trojan Shield has shattered any confidence the criminals may have in the use of hardened encrypted devices," Grossman concluded. ®
Get our [23]Tech Resources
[1] https://www.theregister.com/2021/06/08/operation_ironside_anom/
[2] https://www.theregister.com/2021/06/08/operation_ironside_anom/
[3] https://www.fbi.gov/news/stories/fbi-global-partners-announce-results-of-operation-trojan-shield-060821
[4] https://regmedia.co.uk/2021/06/08/grossman.jpg
[5] https://regmedia.co.uk/2021/06/08/trojan.pdf
[6] https://www.theregister.com/2018/10/03/phone_ceo_pleads_guilty/
[7] https://www.justice.gov/usao-sdca/pr/chief-executive-communications-company-sentenced-prison-providing-encryption-services
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMA83Tyj05QDw4S6p@RD4gAAAAs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[9] https://www.theregister.com/2021/03/19/sky_global_ecc_shuts_down_indictment_raids/
[10] https://www.theregister.com/2021/06/08/operation_ironside_anom/
[11] https://www.theregister.com/2021/04/08/sky_ecc_drugs/
[12] https://www.theregister.com/2021/03/15/sky_global_indicted/
[13] https://www.theregister.com/2021/05/12/blessed_are_the_cryptographers/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMA83Tyj05QDw4S6p@RD4gAAAAs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMA83Tyj05QDw4S6p@RD4gAAAAs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMA83Tyj05QDw4S6p@RD4gAAAAs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[17] https://2009-2017.state.gov/j/inl/rls/nrcrpt/2012/vol2/184110.htm
[18] https://www.theregister.com/2020/07/02/encrochat_op_venetic_encrypted_phone_arrests/
[19] https://www.theregister.com/2021/03/19/sky_global_ecc_shuts_down_indictment_raids/
[20] https://regmedia.co.uk/2021/06/08/tuna.jpg
[21] https://regmedia.co.uk/2021/06/08/pineapple.jpg
[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMA83Tyj05QDw4S6p@RD4gAAAAs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[23] https://whitepapers.theregister.com/
Well gosh, I don't honestly think $180k would be enough to pay for the sheer terror and dread and paranoia it must now be like to live every moment of that snitches life. Hope they were better at hiding their identity than DPR eh? No friends, fellow devs, nobody who could be bought for like, a *lot* of money, to give some very angry people a point in the right direction? Must be sleeping easy on that not actually very substantial pile of blood money.
I he stays away from that world, those people, and stays clean, he stands a much better chance. He presumably will be offered a new ID. It's not like these people are bound together by honesty - their lives are full of double crosses, betrayal, and physical attacks. They'll move on to other grudges.
Law enforcement has methods of hiding people who help them. Also, this guy wasn't known by the criminals--they just wrote code for a company which interacted with them. I'm pretty sure most of those caught recently have never heard of them. Those caught a while ago might have, but weren't told who it was. They'll likely be safe.
I imagine that if you were also one of the devs at Phantom Secure or especially Sky Global you'd have an idea as to who it was given we know they had also been sentenced for drug importation before. I'd also guess that there are photos of them in the public domain or at least ones that could appear in the public domain.
The criminals involved don't need to actively look for that person - a chance encounter would suffice. Either way I can't see how you'd sleep easy knowing the magnitude of who you'd p*ssed off.
Evil people are always amazed that good people can be clever.
A job well done
This is a great job by law enforcement in many countries and demonstrates the usefulness of thought-out targeted attacks as a method of identifying and tracking criminals. I applaud those who did this and I hope they're able to continue solving crimes like this. If we needed extra points to prove why encryption and security aren't the enemy, this is an excellent one. By hard work and actual policing, the FBI and its friends have done a much better job than they could ever hope to do by mass surveillance.
Stupid cops
Advertising your means of capture ruins it. The crims, and there is an infinite supply of them, will switch to another method, and the cops will *follow* as usual. Well, it keeps the boys busy.
Better idea, legalize all "drugs" (as in Portugal), as we already do with alcohol and tobacco, and make the serious ones prescription only.
The drug trade collapses, prices crash, lives are saved, and the cops can get more exercise beating up protesters. Win-win.
Re: Stupid cops
The crims, and there is an infinite supply of them, will switch to another method, and the cops will *follow* as usual.
It appears from the story that they did indeed switch - from one taken down secure phone/app to another.
I doubt they'll learn as they effectively paid to be imprisoned this time ($1700 per handset).
This is where the techno ignorance of the masses pays dividends.
Trusting trust
[1]Reflections on Trusting Trust should be mandatory reading for all "criminals"?
Not only software is a problem, but the hardware too. If you want some strong guarantees about the system you are using, then you must make both hardware and software yourself. At the same time, you then cross your fingers that you have not introduced any bugs.
Maybe, using an old typewriter, paper and the post-office is becoming more secure than your computing platforms. I guess you should use some kind of code. But then, OTP has a very long history and is very secure. Oh, yes, the RTT is lower, but that is compensated with the better security.
But in the end, it will be the users who make simple or stupid mistakes that cause them to be caught. That cannot be fixed with any type of technology. Or, can you already get an integrated brain replacement?
[1] https://dl.acm.org/doi/pdf/10.1145/358198.358210