Full Report
Citizen Lab director Ron Deibert gave a keynote speech about the Greek spyware scandal at an event hosted by Eteron think tank in Athens in May. The post Ron Deibert Speaks About “Greek Watergate” appeared first on The Citizen Lab.
Analysis Summary
# Incident Report: Greek Watergate (Predator Spyware Scandal)
## Executive Summary
The "Greek Watergate" involves the systemic use of Intellexa’s "Predator" mercenary spyware to target journalists, political figures, and civil society members in Greece. The incident represents a major breach of democratic oversight, where sophisticated mobile surveillance was used to monitor high-profile individuals, leading to national and European-level parliamentary investigations.
## Incident Details
- **Discovery Date:** Approximately 2021–2022 (Ongoing disclosures)
- **Incident Date:** 2021–Present
- **Affected Organization:** Members of the Greek Government (Opposition), Greek Journalists (e.g., Thanasis Koukakis), and Civil Society.
- **Sector:** Government / Media / Civil Society
- **Geography:** Greece
## Timeline of Events
### Initial Access
- **Date/Time:** 2021
- **Vector:** Phishing via SMS (Smishing)
- **Details:** Targets received personalized SMS messages containing malicious links masquerading as legitimate local news or social media notifications. Clicking the link initiated a "one-click" infection of the mobile device.
### Lateral Movement
- **Details:** As this is a mobile spyware infection, movement is generally restricted to the compromised device's environment, accessing integrated accounts (Cloud, Email, Social Media) rather than traditional lateral movement across a corporate network.
### Data Exfiltration/Impact
- **Details:** Predator spyware enables full access to the device, including the camera, microphone, encrypted messaging apps (Signal, WhatsApp), call logs, photos, and real-time location data.
### Detection & Response
- **Discovery:** Investigative journalists and forensic analysis by organizations like The Citizen Lab and Meta (Facebook).
- **Response Actions:** Technical forensic audits of devices; high-level investigations by the Hellenic Authority for Communication Security and Privacy (ADAE); formation of a European Parliament committee (PEGA) to investigate spyware use.
## Attack Methodology
- **Initial Access:** SMS-based social engineering (Smishing) utilizing malicious URLs.
- **Persistence:** The spyware is designed to maintain access through system processes, though it can be volatile depending on the OS version.
- **Privilege Escalation:** Uses undisclosed kernel-level exploits to bypass mobile operating system (iOS/Android) security sandboxes.
- **Defense Evasion:** Operates in the background with a minimal footprint; utilizes encrypted command-and-control (C2) communication.
- **Collection:** Interception of audio, video, keystrokes, and application data.
- **Exfiltration:** Data is periodically uploaded to C2 servers over HTTPS.
- **Impact:** Total loss of privacy for the target and exposure of their professional and personal contacts.
## Impact Assessment
- **Financial:** Significant costs related to judicial inquiries and the restructuring of national intelligence oversight.
- **Data Breach:** High-volume exfiltration of sensitive political and journalistic communications.
- **Operational:** Disruption of journalistic activities and political opposition functions.
- **Reputational:** Severe domestic and international scrutiny of the Greek government and the "Intellexa" corporate entity.
## Indicators of Compromise
- **Network Indicators:** Connections to known Predator/Cytrox infrastructure (e.g., specific domains used for link shortening - *defanged examples: hxxps[://]bit[.]ly/controlled-link*).
- **Behavioral Indicators:** Unexpected battery drain, overheating of mobile devices, or unusual background data usage.
## Response Actions
- **Containment:** Device isolation and factory resets (though often insufficient for persistent spyware).
- **Eradication:** Citizen Lab and other researchers identified and flagged the malicious infrastructure.
- **Recovery:** Public disclosure and policy advocacy for a moratorium on mercenary spyware.
## Lessons Learned
- **Commercialization of Surveillance:** The availability of "spyware-as-a-service" allows actors to bypass traditional security without needing in-house expertise.
- **Verification is Vital:** High-risk individuals must treat unsolicited links with extreme suspicion, even when they appear to come from trusted sources.
- **Lack of Regulation:** The incident highlights a global regulatory vacuum regarding the export and use of commercial surveillance tools.
## Recommendations
- **Mobile Defense:** Use of Lockdown Mode (Apple) and frequent device reboots to disrupt non-persistent infections.
- **Policy Change:** Implement stricter export controls on surveillance technology and increase transparency requirements for government intelligence agencies.
- **Forensic Support:** Ensure journalists and activists have access to tools like MVT (Mobile Verification Toolkit) to periodically scan for indicators of infection.