中国网络安全产业联盟2025美情报机构针对全球移动智能终端实施的监听窃密活动研究报告英文版82页_3mb
报告摘要
Summary of Mobile Cyberattacks Conducted by US Intelligence Agencies
Core Content
This report outlines a series of sophisticated cyberattacks conducted by US intelligence agencies, particularly the National Security Agency (NSA) and the Central Intelligence Agency (CIA), targeting mobile smart terminals and related infrastructure. These attacks span a wide range of techniques, from exploiting SIM card vulnerabilities to deploying commercial spyware and fake base stations. The report emphasizes the pervasive and covert nature of these activities, which aim to monitor, collect data, and control mobile devices globally.
Main Points and Key Information
1. SIM Card Vulnerabilities and Exploitation
-
Simjacker Vulnerability (2017-2019):
- This vulnerability allows attackers to exploit the S@T Browser in SIM cards to send specially formatted binary SMS messages.
- These messages trigger malicious execution on the device, enabling location tracking, data collection, and even telecom fraud.
- The attack was detected in Mexico, Colombia, and Peru, with over 1 billion users potentially affected.
- Similar to NSA's previously exposed attack tools like MONKEYCALENDAR and GOPHERSET, Simjacker is part of a broader strategy of using SMS for covert surveillance.
-
Attack Methods:
- SMS-PP (point-to-point) messages are used to trigger the S@T Browser.
- Attackers can collect device information, such as IMEI, location, and contact lists.
- The attack is stealthy, as victims are unaware of the SMS received or sent.
- The vulnerability is independent of the device type and depends on the SIM card's software.
-
NSA's ANT Attack Equipment:
- The NSA's Advanced Network Technology (ANT) division has developed multiple attack tools targeting mobile devices.
- These include both software and hardware-based tools, such as DROPOUTJEEP, GOPHERSET, and TOTECHASER.
- The tools can be deployed via close access or over-the-air (OTA), and some are capable of remote installation.
2. Data Collection via Pre-Installed Software
- Carrier IQ (2006-2011):
- Carrier IQ was widely pre-installed on Android devices by US operators to collect user data, including SMS and keyboard input.
- This data was used by the FBI and NSA for intelligence gathering, often exceeding legal authorization.
3. Commercial Spyware: Pegasus
- Pegasus Spyware (2018-2021):
- Pegasus, developed by the Israeli company NSO Group, was used by the US intelligence agencies to monitor mobile phone users.
- It can be deployed via zero-click attacks, allowing unauthorized access without user interaction.
- The spyware targets iOS and Android devices, enabling full access to device data and communications.
4. Fake Base Stations and Signal Interception
-
Stingray (2004-2013):
- The US intelligence agencies and law enforcement used fake base stations (Stingray) to intercept mobile communications.
- These devices mimic real base stations and can be used for surveillance and data collection.
-
Quantum System (2005-2013):
- The Quantum system, revealed by Snowden, is used to attack network equipment like switches and routers.
- It can be used to monitor and control various devices, including mobile phones and PCs.
5. Operator Infrastructure and Internal Systems
-
Regin (2018):
- Regin is a sophisticated malware used to attack operator intranets and network infrastructure.
- It enables long-term surveillance and data exfiltration.
-
Operation DAPINO GAMMA (2010-2011):
- The NSA and GCHQ targeted the Dutch SIM card manufacturer Gemalto to steal encryption keys.
- This allowed them to intercept communications and compromise device security.
6. PRISM Program and Super Data Access Interfaces
- PRISM (2007-2013):
- The PRISM program, exposed by The Guardian and The Washington Post, enables the NSA to collect data from internet platforms.
- It is a large-scale surveillance system that uses super data access interfaces to gather information on global users.
7. Combined Attacks on Operators and Smart Terminals
-
Operation Triangulation (2019-2023):
- This operation targets iPhones and iPads, using fake base stations to intercept data.
- It was exposed by Kaspersky and accused by the Russian FSB of being an NSA operation.
-
IRRITANT HORN Project (2011-2012):
- The IRRITANT HORN Project, launched by the Five Eyes intelligence alliance, involves replacing apps with malware and hijacking traffic.
- It was exposed by CBC and The Intercept in 2015.
Key Findings
- US intelligence agencies have been conducting cyberattacks on mobile devices for over two decades.
- These attacks often exploit vulnerabilities in SIM cards, software, and network infrastructure.
- The use of SMS as a vector for attacks has been a significant method, allowing covert data collection and device control.
- Commercial spyware like Pegasus is being used to target mobile users, often with zero-click capabilities.
- The attacks are highly sophisticated, involving both software and hardware, and are conducted with global reach and extensive resources.
- The US intelligence agencies have access to SS7 networks and other critical infrastructure, enabling large-scale surveillance.
Conclusion
The report highlights the extensive and covert cyberattack activities of US intelligence agencies against mobile smart terminals. These attacks exploit various vulnerabilities in the mobile ecosystem, including SIM card flaws, pre-installed software, and network infrastructure. The use of advanced tools and techniques, such as Pegasus and Quantum, underscores the sophisticated nature of these operations. The findings suggest that mobile devices are not just communication tools but also potential entry points for espionage and surveillance, raising serious concerns about privacy and security.
试读结束,高清完整版pdf/doc/ppt,请点下载