Computer Weekly reveals for the first time how French cyber spies hacked EncroChat phones, used by organised crime groups, in 2020. In the first of two major articles, we describe how a Czech spyware company rehacked the French hack and found that French malware – described as a national security secret – had been copied from popular code-sharing platform GitHub.
The Czech rehack uncovered digital fingerprints matching French evidence sent across Europe, proving how messages had been copied.
The exposure of the French method, British lawyers say, is likely to restart a critical case into the legality of police tactics in EncroChat in Britain’s Investigatory Powers Tribunal, which has been adjourned for more than two years, awaiting a finding on how the hack was carried out.
The secret French state hacking group that broke into tens of thousands of encrypted secure phones in Europe used an Android exploit first spotted in 2017, CW can reveal. For two years, a fatal security vulnerability, known as the Bad Binder bug, was left unpatched inside 2.5 billion phones, leaving users at maximum risk. The exploit allowed cyber spies to take complete control of infected phones and copy or change users’ data, programs and files at will.
A “groundbreaking” report by Czech researchers, obtained by Computer Weekly, combined with expert analysis of intercepted material has revealed how the French “implant” relied on Bad Binder – and that its code was poorly written, prone to repeated failure, and lacked elementary countermeasures to avoid detection. Implant code, recovered by reverse engineering – working out program instructions from compiled code to see how it operates – shows that intercepted messages being transmitted inside targeted phones were “hooked” and copied almost immediately to police investigators. British lawyers say that if the full facts had been disclosed when trials started in 2020, it would be “open to question whether courts were properly informed”.
• For a technical explanation of how the implant worked, see box: The trampoline: How messages bounced to police.
“This investigation by Computer Weekly and Sussex Centre for Law and Technology (SCLT) is a landmark breakthrough,” the leading lawyer in the UK’s first EncroChat trial, Matthew Ryder KC, told Computer Weekly. “It suggests that after six years, we may finally know the details of the EncroChat interception by the French authorities. It is bound to have consequences for the ongoing legal argument and on legal principles relating to interception and computer interference.”
Computer forensics and malware expert Felix Freiling, a professor at Friedrich-Alexander-Universität (FAU) in Germany, described the report as “unique [and] an impressive breakthrough”. Rehacking the French hack, he said, “answers a lot of questions” and was “a big step to better understanding”. The bug code uncovered by Czech cyber security company Invasys “looks like a student project”, Freiling noted, including apparently having copied exploit code from the internet.
The new information will be “vital for EncroChat trials and appeals” in Europe, according to leading Dutch criminal lawyer Justus Reisinger, a member of the European defence legal team contesting unexplained evidence. “We can’t simply say ‘we trust the data’ while not being able to do proper research into the manner of obtaining it. That is vital to providing suspects with fair trials. We have been asking for that information for six years.” In Britain, thousands of cases have been judged and sentenced without explanation of how the data was obtained, because French authorities stipulated that the way the hack was carried out was a matter of national security.
The wave of British cases came after five years during which, across the UK and Europe, police investigators were increasingly finding secure EncroChat brand phones at the scenes of crimes. A major feature of the phones was that they were made to look like ordinary Android phones, with a range of standard app icons on display. But the icons were dummies to fool onlookers.
Before about 2015, BlackBerry smartphones running Pretty Good Privacy (PGP) encryption software provided business customers with a high-security email service. Crime investigators then increasingly found PGP BlackBerry handsets connected to independent private servers when raiding drugs distributors.
According to the National Crime Agency (NCA), PGP-enabled BlackBerry handsets allowed organised crime groups (OCGs) to “provide operational security … and secure email communication between those holding key roles within criminal networks”. Within the “Five Eyes” secret intelligence network, this segment of the cryptography and security market was dubbed “criminally dedicated secure communications” (CDSC). A UK and European working group was set up to fight CDSC.
Since 2017, collaborating European police agencies designated EncroChat as a CDSC system, according to NCA branch commander Wayne Johns. Despite major investigations in several countries, security hardening of EncroChat phones and the end-to-end encryption of chat messages proved impervious to many types of attack.
NSO spyware boss ShalevHulio – Bad Binder exploits
were attributed to his
company (Credit: LinkedIn)
“EncroChat devices have been developed and are marketed specifically to the criminal community in order to facilitate criminality,” Johns claimed in 2020, basing his view on “available evidence and intelligence from all available covert and overt intelligence and evidence gathering sources … corroborated by multiple national and international partners”.
Standard police forensic tools were found to be useless. Law enforcement agencies were locked out. Then the Gendarmerie – French police – had a lucky break. Late in summer 2019, Google’s threat teams were tipped off about an exploit powering Android malware used to spy on targets of notorious Israeli cyber intelligence agency NSO Group, based in Herzliya, and its Pegasus spyware system.
Pegasus spyware is now at the centre of global controversy due to its wide sale to repressive governments targeting human rights defenders, journalists and political opponents, leading to more than 30 current court cases and a $168m penalty awarded to Meta.
The Pegasus bug tip-off proved to be the beginning of the end for EncroChat.

‘Everyone loves EncroChat!’
At the edge of the Rocky Mountains in June 2014, two Canadian tech developers met for dinner to discuss “next level” hardened smartphones. Paul Krusky had travelled to Calgary, Alberta, from his Caribbean home in a gated settlement in the Dominican Republic. His host, Geoff Green, had started Mynt, a money exchange, which then became Myntex Inc, selling BlackBerry smartphones with built-in PGP as a “security solution”.
Krusky’s company, Esoteric Communications Inc, was registered in Panama. It, too, had sold PGP BlackBerry handsets. Krusky now told Green he had created a “security solution” for newer Android smartphones. His secure Android chat message app was called Esocrypt, identified inside phones as “com.esocrypt.chat.app.im”. Krusky changed the name to EncroChat.
Krusky sent Green details of his “EncroChat Security Model … assembled from multiple open source projects”. Secure messages used Off-the-Record Messaging, a forerunner of Signal. The hardened operating system was Guardian ROM, a version of Android developed by the Guardian Project, a US-based group working for “activists, journalists, and everyday users who value privacy and security”.
Krusky explained that a normal low-cost phone could be “flashed” – rewriting its memory and adding an independently encrypted storage area and a second operating system. The first operating system looked like a normal smartphone, but did nothing. The second operating system was booted by a special key combination. On entering a “boot PIN”, the second, armoured, Encro operating system started and opened the securely encrypted “userdata” memory partition.
Typically costing over $1,000 for a six-month contract, EncroChat phones were expensive and never clever. They had no smartphone features. They could send messages or images, store notes, and might occasionally host phone calls. They could not access Google or Netflix, nor play music. EncroChat phones were used to exchange highly secure messages and images between closed groups of users, suspected mainly to be criminal groups, who never used numbers or real names. Arbitrary adjectives and words, called “handles”, were used instead. All EncroChat messages were automatically wiped within 14 days, using a “burn time” chosen by the sender.
Green found Krusky to be “a very intelligent man and a pleasure to talk tech with”. EncroChat then had just 50 customers. Green signed up to become a reseller and “was personally trained by Krusky on how EncroChat worked, inside and out”. Krusky used Raspberry Pi minicomputers to “flash” Android phones into EncroChat devices, and offered one to Green. Green “transitioned” Myntex clients from PGP BlackBerry to EncroChat, and “travelled to Europe … introducing the phone to our established distributors. Everyone loved EncroChat!”
By 2016, Green had thousands of EncroChat customers paying over $5m annually. Competition increased after Dutch police closed down Ennetcom, another Canada-based PGP BlackBerry network, describing it as “the largest encrypted network used by organised crime in the Netherlands”. Green reacted with a press statement, claiming: “Myntex has expanded … to help disappointed Dutch customers … We’re putting a major effort into expanding our operations … to fulfil what is obviously a healthy demand for encrypted communications in this part of Europe.
“We also have what we believe is a better option which we’ll be offering Dutch customers. It’s called EncroChat.”

After the pitch, Krusky nixed the deal, telling Green that EncroChat “had been sold”. “My EncroChat phone was [remotely] wiped and our product portal was blocked,” Green recalled. Involvement with EncroChat, he told Computer Weekly, was “a traumatic experience” that had harmed “our business and our personal safety”. After 2016, “we were no longer involved”.
A decade after the Canadian hookup, Krusky’s app name, Esocrypt, has been found at the heart of French malware code (see box, The trampoline: How messages bounced to police). This unlocked the long-awaited answer as to how European police agencies had in 2020 read millions of mobile phone messages, leading to more than 6,500 arrests, the seizure of 270 tons of drugs, and cash finds worth nearly €1bn.
Paul Krusky was detained in the Dominican Republic in 2022, extradited to France in 2024 and is now in La Santé prison, Paris, awaiting trial on 16 charges, including drugs trafficking, arms trafficking and money laundering, facing maximum aggregate sentences of 130 years in prison.
‘Bug-hunting badass’ finds Bad Binder
Late in summer 2019, Maddie Stone, a member of Google’s Project Zero team, was alerted to “a 0-day exploit for Android … part of an attack chain that installed Pegasus spyware on target devices”. Pegasus, sold around the world by notorious Israeli spyware company NSO, was reported to infect phones with a “kernel privilege escalation using a use-after-free vulnerability“. Stone quickly tracked down the bug, reporting it on 27 September 2019.
Stone’s discovery was serious and urgent. Although the vulnerability in the Linux kernel at the heart of the Android operating system had been noted in 2017, Google’s failure to patch Android now triggered a crisis response, followed by a global threat warning just one week later. Hailed as a “bug-hunting badass”, Stone tweeted her delight: “My first Project Zero bug!” Google Pixel phones were quickly patched, but not others – including EncroChat.
The US National Institute of Standards and Technology (NIST) listed the Bad Binder exploit in the National Vulnerability Database as CVE-2019-2215. CVE stands for Common Vulnerabilities and Exposures. A week later, Stone’s full code – called Proof of Concept – was published on the GitHub developer platform. Forbes magazine warned, accurately: “CVE-2019-2215 … will probably be used in very targeted attacks.”
C3N, the French national police cyber crime team, took note. If they moved quickly, EncroChat could be a sitting duck. Almost all of EncroChat’s servers operated under French jurisdiction, in a datacentre run by the French web hosting and cloud computing supplier OVH (now OVHcloud) in the northern industrial city of Roubaix. C3N asked Lille’s Court of Liberty and Custody to order the OVH datacentre to make image copies of EncroChat servers.
OVH copied 71 “virtual machine” images operating on 33 internet subdomains. A total of 66,134 SIM cards – so potentially the same number of phones – were found to be registered to the EncroChat network. C3N then called in the newly founded French government official hacking team, STNCJ (Service Technique National de Captation Judiciaire).
In 2019, EncroChat phones were all built from “BQ Aquaris” brand versions X and X2, sold by Spanish company Mundo Reader S.L. They used a 2018 version of the Android 8 operating system, which Google called “Oreo” and Mundo called “Zangya”. Although Google phones were regularly updated, data relayed from inside hacked EncroChat phones in 2020 showed that all used “Zangya”, as built on 14 November 2018.

Getting NSO’s Bad Binder exploit inside phones was not trivial, Google researchers found. To install Bad Binder required either smuggling in a malware application, or crafting a malicious website using other exploits, and then tricking users to visit. Both tricks were impossible, as EncroChat phones did not include browsers and EncroChat users could not load non-EncroChat apps. But the French, and then the Czechs, found ways in.
EncroChat’s update server, at the web address “update.encrochat.ch”, was under French jurisdiction. EncroChat phones were set up to check for updates every time they were used, and commonly did so daily. The process was automatic and silent to users, and did not require notice or consent.
At the beginning of 2020, rumours circulated in police groups that the French were planning a break-in to EncroChat. EncroChat’s neglect of the unpatched Bad Binder warning meant that French exploitation “was not nearly as sophisticated as perceived by the public”, according to cyber security researchers.
Pwned
Any door into EncroChat faced a gatekeeper, called SELinux (Security-Enhanced Linux). Originally developed by the US National Security Agency (NSA) in conjunction with Red Hat, SELinux controls all processes on a device, and TO “can only be turned off if hackers use an exploit like Bad Binder to disable it. If they do, the device is “pwned” (owned).
Bad Binder had pwn power. The French hackers found they could run as root, and so knock out even SELinux, reverse engineering later discovered. The trick was to use a flaw in a kernel program that incorrectly left usable access to a freed area of memory, allowing an attacker to put arbitrary code in the free space and then trigger it. A door into EncroChat was open.

On 22 January 2020, Eurojust, the EU justice organisation, hosted a confidential meeting in The Hague. At the meeting, the Gendarmerie disclosed that they “have found a vulnerability they can exploit in ‘live time’ [to] pull back data from the phones to [their] server”, according to a British NCA officer’s report to her commanders. The UK could have access, she explained – but only on a fast and “terrifying” timescale.
The French attack was planned for Tuesday 10 March 2020. “They are reluctant to push back because the action is based on a vulnerability that can be patched at any time,” the NCA officer reported.
The French called the malware an “implant”, “tool” or “technical solution”. They refused to tell international partners anything about how it would work.
In Lille a week later, judge Sophie Alex authorised the Gendarmerie team to install monitoring equipment inside the Roubaix datacentre “to access, record, store and transmit computer data in any place”. A follow-up order authorised the unit to spy on phone traffic and to “capture data by means of transmission via an electronic communication network on terminals and peripherals”. This French plan was a cyber equivalent of a smash-and-grab raid. They would build an exact replica of EncroChat’s update server from the copies they had made, then arrange for OVH to switch EncroChat customers worldwide to the imposter police server using a network “load balancer”. Then they would send in Bad Binder.
The next stage of the French malware attack saw STNCJ, the government hackers, back on GitHub. They downloaded Frida, an open source Android test and monitoring toolkit. Once running inside a phone, Frida can check on, interrupt, or change any and every action, as they happen.
Implant Day
The STNCJ team stumbled as they tried to get their code right, making multiple mistakes and forcing back the planned date of attack by three weeks. After delays, errors and false starts, and as the world outside locked down to fight Covid, Implant Day was finally set for Wednesday 1 April 2020. French authorities secretly ordered the OVH network to be locked down for the afternoon of 1 April, to prevent EncroChat operators altering internet connections while a “load balancer” rerouted their customers’ phones to download and run malware packs.
According to evidence given to a German court two years later, at 3.15 CET on 1 April 2020, STNCJ’s implant code, stored on a memory stick in a safe, was taken out and remotely “injected” into the EncroChat update system. The next morning, 2 April 2020, massive numbers of newly infected EncroChat phones started sending huge batches of copied files, overloading and slowing internet connections to OVH. Over the following two months, 32,014 devices were infected and came under the control of the C3N command server.
Inside OVH, a secret, silent cyber war was underway. The same server racks and shelves that managed EncroChat communications also now contained a reconstructed duplicate police network and the gendarmes’ critical data collection server at internet address 147.135.143.19. This IP address was in the same range as real EncroChat servers.
The full hidden and secret address for the control server, reverse engineering later found, was https://147.135.143.19:443/214bWv97igU5uGKsGJOcEIyqZeovE3. The data flowing into this address every hour now included up to tens of millions of data “objects” called JSONs (JavaScript Object Notation), each reporting a single event on an infected phone, as it happened – every password entered, every image made or received, every message, every note made into or deleted from an encrypted EncroNotes container.
The most frequent JSONs, CellLocation, reported back every time the phone connected to a different mobile radio mast, allowing police teams to follow movements and messages in real time – thanks to Bad Binder and Frida. Analysis showed that copied messages usually left infected phones in less than one second, and reached police computers in less than 20 seconds.
Most of the hastily engineered French implants failed quickly. Phones were then reinfected or implants restarted multiple times over a week after the first infections. New implants or restarted implants were rare after 8 April 2020, but occurred sporadically into May.
As the attack continued, clues left and operating errors caused by the implants made EncroChat operators increasingly suspicious. Both sides then made fatal errors. On 12 June 2020, the STNCJ team was back with new malware and a different exploit. Following the previous pattern, it legally locked down the EncroChat network and injected malware for the new generation of EncroChat devices, called X3 or “carbon”.
The second French attack failed, blowing STNCJ’s cover. EncroChat operators saw the change and attempted to take back control. They also examined the malware. EncroChat warned resellers early the next morning, 13 June:
“We had our carbon [X3] units attacked, specifically firmware version c0.03.19 … as a preventative measure, we have taken down the entire sim [KPN data sim] network…
There was a window of 30 mins where there was a breach into our system, infecting that specific firmware. Once discovered, we immediately disabled the entire network …
The best we can ascertain was about 50% of the carbon devices [infected] in Europe (due to updater schedule).”
After French government legal powers proved decisive in the cyber battle, EncroChat operators surrendered, and messaged all users:
“With control of our domain they manager [sic] to launch a malware campaign against the carbon to weaken its security. Due to the level of sophistication of the attack and the malware code, we can no longer guarantee the security of your device. … You are advised to power off and physically dispose your device immediately.”
Using Wi-Fi instead of radio, a handful of customers stayed connected and chatted for a few days. But the network was quickly dead. With the French attack no longer covert, hundreds of investigations and raids started across the UK and Europe.
Because of the claimed secrecy over the message interception technique and the withholding of the information now described here, there have been numerous disputed court cases in the UK and across Europe, including before the European Court of Justice and the European Court of Human Rights.
Hacking back
Six years have passed since the EncroChat hack launched thousands of criminal trials. Because of intransigence by British and French officials, and suspected serious tampering with forensic evidence provided by police, it was not until August 2024 that a judge in a major EncroChat trial in London ordered the National Crime Agency to hand over an infected EncroChat phone for effective forensic testing.
The phones were sent to a little-known European cyber security company called Invasys, based in Brno, Czechia. Invasys is a “white hat” version of NSO, selling malware to governments for “intelligence gathering”, run by Kyrre Sletsjøe.
Soon after Sletsjøe submitted an expert report for an Old Bailey case in February 2025, his company exhibited at the Farnborough Home Office Security and Policing show advertising “helping governments monitor mobile phones” using packages called Kelpie, Tungsten and Tellus. His 146-page report with appendices was quickly circulated by the UK Crown Prosecution Service to teams involved in more than a thousand other EncroChat cases. (Prosecutors in UK trials have a legal duty to pass on information they receive, and which could help defendants.)
British and European lawyers and cryptosecurity experts have told Computer Weekly that they are now looking further at the significance of Sletsjøe’s report for other legal cases.
Of three allegedly infected phones examined in the Brno laboratory in 2024, Invasys found one was provably infected. The phone, using the handle LOGICALDEMON, had been found in a car in Wandsworth in June 2020. It had been infected with French malware on 2 April 2020. The user, Peter Thompson, admitted to a “huge illegal drugs importation conspiracy” involving the import of nearly a ton of cocaine in two-and-a-half months, and was sentenced to 20 years and six months’ imprisonment.
Copying data from chips inside EncroChat phones was arduous, Invasys found. Beginning work late in 2022, the company had tried to get into six handsets using a “chip-off” method. Chip-off means dismantling the phones and then desoldering memory chips to remove them from their motherboards. Desoldering also requires safely freeing hundreds of pins without damage, while also not destroying the chip by excess heat. Two of six Encro chips were destroyed during tests.
On four surviving chips, tests identified the hidden “userdata” area. This 22GB partition was “unbreakable” and “protected by strong cryptography”, Invasys reported. “All attempts to decrypt the data within reasonable time failed.” The EncroChat userdata partition was found to be protected by double cryptographic layers – using a hardware module on the now desoldered motherboards as well as a user password or PIN to reveal a second key.
The “chip-off” approach could never have worked, Invasys learned. Even if a phone’s PIN was known, the memory chip would only open if left connected to its motherboard. The memory would then remain locked, blocking access to raw data. Without knowing the PIN, decoding was impossible. Worse, EncroChat phones were programmed to wipe their memory after 20 failed attempts. After 10 failures, users saw an onscreen warning counting down the number of attempts left to automatic self-destruction.
The next best way, Invasys proposed, was a spectacular frontal attack on Qualcomm’s Secure Execution Environment (QSEE), an isolated area within the company’s Snapdragon mobile phone processors. Invasys proposed to decap or “blow off” the tops of chips, then use X-ray microscopes to locate the counting circuit, then jam it using electron guns or lasers.
This attack, they warned, would take six months to test and start, then months more to process “astronomically large” numbers of possible passwords while exposed auto-destruct circuits were pinned down at electron gunpoint. Invasys expected multiple chips to be sacrificed until a solution was found.
Massive “brute force” PIN testing would also mean connecting the imprisoned chips to liquid nitrogen cooling to avoid burnout. “Given the cost of the equipment and the time needed for key extraction, such activity will be very expensive and time-consuming … the cost in effort and infrastructure will likely end up in high hundreds of thousands of euros/pounds,” said Sletsjøe. It would also need to burn through more EncroChat phone chips, could take much more than a year, and might never succeed.
Evidence tampering
“The hardest bit,” according to forensic expert Freiling, “was to actually get the software that was running out of the device. The way Invasys finally infiltrated the device was similar to how the French police got in. They mimicked the update process to push code to the device.”
This method was also costly, complex, time-consuming and risky. Any infected target phone had to be fooled into thinking it was still part of the EncroChat network. To do this meant rebuilding the EncroChat server environment as it had existed five years earlier inside OVH’s datacentre. In principle, this could be done using the French police server copies made in 2019. Copies had been given to the NCA, and could be copied again.
Following a 2022 court order, the NCA had given Invasys copies of 71 EncroChat server “virtual machine” images made in 2019. Invasys quickly found that the images had been tampered with.
It warned: “Our ability to investigate the EncroChat data … was severely restricted by forensic deficiencies. [The images] appear to have been processed in gross violation of common forensic data-keeping/chain-of-custody principles, and were incomplete and/or had been modified/corrupted by the time they were handed over.”
Invasys had no doubt that legally essential data had been tampered with or erased by unknown parties between the time the French copies were made and the time the NCA gave it copies. Data in the images “had been manipulated, deleted and corrupted (it would appear deliberately) exactly in those areas that are critical for system operation”.
The lack of disclosure “increased … time and cost considerably”, a London court was told. But Invasys was confident that it could overcome the suspected sabotage enough to be able to operate its own fake update server, and rehack the target phone. “We have nonetheless been able to recreate parts of the server infrastructure and use it in developing a viable extraction method for EncroChat phones,” it claimed.
Disclosure was also blocked in other important trials. In September 2024, at a Newcastle trial, another expert, Kushvinder Raheloo of ReInvent Systems in Birmingham, asked the NCA to disclose a vital component for rehacking. This was EncroChat’s app signing key, which would normally be needed to install new apps. The request was refused.

Finding Frida
If the reconstruction plan worked, then Invasys could try the same tactic as the French. If an Invasys replica server successfully connected, they could “trigger phone software updates”. Sletsjøe explained: “The [replica] update server was configured to pretend it has one new update package available for installation on EncroChat phones. This package … provided the first foothold in the otherwise secure phone.” The “update package” was Czech malware.
The Czech rehack worked. Using “an EncroChat phone with a known boot PIN, the reconstructed server connected to the test phone using original EncroChat transport layer security (TLS) certificates”. Invasys withheld the secrets of its own hack, the exploits it used, and said nothing about how it had tricked the target phone to run its malware.
By December 2024, EncroChat’s secrets and the French hacks were out in the open. The Czech team immediately spotted “implant components and binaries” inside the LOGICALDEMON device, and copied them. It reverse-engineered the extracted implant code to identify its functions and measure its power. By early 2025, Invasys estimated, it had reversed 70% of the malware.
Three suspicious hidden processes were found running continuously with complete “superuser” access. The malware implant controller was running as “com.android.device” with a linked “timestamp”. The name “com.android.device” is not used by any real Android application. The French “rogue app” – called “base.apk” – was identified and taken apart. The implant was found to be “persistent”, as expected, and was set to run as soon as any infected device was booted. Every time it started, it ran Bad Binder to escalate privileges.
The two most important components of the hack were libraries of Android functions and methods. The first library, “librealm-jni.so”, was published by Realm and allowed the implant to read, write and inspect Realm data tables, used by EncroChat to hold messages and user information. The second was Frida. The implant also changed the operating system to stop “android.com.device” from being seen, blocked its actions from being logged, and prevented it from being deleted – all routine malware tactics.
Frida was the heart of the French implant, reverse engineering revealed. Frida is used by security researchers and hackers alike to run legal testing or to arrange illegal interference. Running as a superuser, Frida can change anything and everything.
For hackers, Frida is dream spyware. It monitors instructions and will “hook” any process inside the processor by attaching from an “interceptor”. The hook triggers a “trampoline”, bouncing out of the intended program into exploit code written by the hacker. After the hacker code finishes, Frida bounces back, leaving no trace of what has just happened.
The French malware was “highly unsophisticated”, according to Invasys, and left itself exposed to detection, copying and analysis. In particular, inside the malware installation pack, “base.apk”, was a unique library of exploits named “libexploit”, giving a “clear indication of malicious intent”.
Despite its lack of sophistication, the malware library gave French cyber spies full access to infected phones, according to Invasys. The implant had the ability to modify data, change the behaviour of the phone, and allow the phone to be taken over remotely – capabilities that went beyond extracting messages. “Obviously they had root access. They could do everything. That is normal with police Trojans…. You see the enormous power of these malware libraries,” said Freiling.
“There is no indication that these capabilities were ever used during the EncroChat hacking operation in the Invasys report. But it is impossible to check. The only thing you can do to increase trust is to have transparent police procedures,” Freiling added.
Invasys identified evidence of classic persistent malware activity. After infection, as soon as a user booted their phone, the implant started running. It blocked the phone from sleeping, turned off logging, switched off the vital SELinux firewall, and opened up all phone processes for any purposes. It interrupted Marvin, a bespoke EncroChat logging system, to stop operators seeing it. It then attempted to block phones from any genuine updates from EncroChat – which they feared could have included patches to block Bad Binder.
After Bad Binder ran, Frida was granted unrestricted “superuser” privileges. Then the implant called home, announcing a successful new infection. “Home” in this case was internet address 147.135.143.19 (described above) located at OVH Roubaix.
Through this link, the police server maintained communications with and could command every infected phone. If the command centre sent “999” or “666”, tests showed, the malware would wipe itself. There is no evidence that these commands or content editing comments were ever used. According to an expert Computer Weekly source, who asked not to be named, EncroChat staff were the first to reverse the implant, before shutting down operations in June 2020.
The police malware server was also the exfiltration endpoint. From 2 April 2020 on, and as more and more phones were infected, a torrent of, eventually, billions of data objects (JSONs) was sent to the police infrastructure. The amount of data sent from phones to the unique server address was, according to cyber security experts, unstealthy and risky. An obvious risk was that some crime groups had technical experts who might easily have spotted extra messages going out every time an image was created or messages were sent.
On starting, every implant copied out the phone’s security keys, stored images and a full Realm message database. Each time a user opened their phone, Frida hooked the unlock password and sent it back. A scanner identified every new encrypted image that the user created or received. Each time a new message was created, it was copied out as shown (see box, The trampoline: How messages bounced to police), often reaching the police server and getting onto police screens in a few seconds. Until Saturday 13 June 2020, the French hackers had got away with all this.
According to British barristers working on EncroChat cases, Invasys was paid £2m for the investigation and reverse engineering that has exposed the malware exploit, used to exfiltrate messages from EncroChat, known as exploit H (see box). Invasys refused to answer questions from Computer Weekly about the cost or results of their report. A spokesperson said: “We are not at liberty to provide any statements.”
Five-year controversy
The discovery of Exploit H may conclude a five-year controversy, with many hours of debate in the UK, caused by uncertainty and extreme French secrecy. Since 2021, many British lawyers and computer experts hoped to find evidence that messages were taken from the middle of the communications system, such as a server, not from phones, as this could mean that the evidence would have to be excluded because it was communications interception.
“I didn’t spot any places [in the report] where there was evidence that they had taken messages from servers, nor any way that cryptographic key material necessary to decrypt messages in transit was exfiltrated,” said Freiling.
Invasys also investigated a sophisticated theory put forward in 2022 by the late and distinguished computer security expert Ross Anderson, a professor at Cambridge University. Although agreeing that EncroChat messages in mid-transmission were unbreakable, Anderson speculated that the French malware could have sabotaged programs inside infected phones to secretly make encryption useless. This “alternative theory” meant tampering with a pseudo-random number generation (PRNG) system, critical to security.
Invasys checked thoroughly and “did not find any manipulation with random or pseudorandom data”, adding that “there was no evidence that an implant changed the system library responsible”. The PRNG application in the infected phone was found not to have been tampered with and was “as supplied”, using original Google APKs. Invasys did not find evidence of Frida hooks or scripts tampering with random number generators.

Freiling, who advised on the first German police malware found in 2011, commented that in his experience, finding university-level sophisticated cryptography in law enforcement malware was not usual. Although intercepting and decrypting encrypted messages from a server would be a more “elegant and stealthy” solution, it’s not standard practice. “All the police malware I have looked at doesn’t do it. They simply copy the stuff from end devices and don’t bother decrypting network copies,” he said.
The UK’s Court of Appeal has ruled that messages were taken from storage, meaning that in their opinion, the French malware was not interception but “equipment interference”, making the French data admissible.
The issues raised will be discussed this week at the 46th Annual International Cryptology Conference, Crypto 2026, in Santa Barbara, California. A US-UK team will say that “the distinction between TEI [interference] and TI [interception] led to detailed, even if often uncertain or speculative, discussion of certain aspects of how the malware worked”.
The team, led by Martin Albrecht, a professor at King’s College London, will tell hundreds of international experts that extreme secrecy about the French “technical solution” has, until now, “caused problems in the subsequent legal proceedings, and has made it harder, if not impossible, to present a thorough defence”.
But the French “student-level” hack, mainly copied from the internet, is now out in the open, including how it worked.
The trampoline: How messages bounced to police
Diagram by Matt Fowler
How the hack worked. Alice’s phone is infected with the French implant. A Frida hook is inserted inside activity in Alice’s chat app – “com.esocrypt.chat.app.im”, shown in yellow. Alice sends a chat message to Bob. After transmission starts, the Frida “hook” triggers a “trampoline” (not shown). The trampoline causes malware “Exploit H” (below) to run. Exploit H copies the message being transmitted before it can be stored and adds locally stored information about Bob called “contract_extra”. The malware dispatcher packs and sends the intercepted copy to French cybercop team C3N (shown in green) before Alice’s message is relayed to Bob, the intended recipient.
“Unsophisticated” and unprotected French police malware was found by Czech researchers inside an EncroChat phone seized from a London dealer using the handle “LOGICALDEMON”.
Reverse engineering combined with expert analysis of intercepted material has revealed how in 2020 French cyber spies were able to hack tens of thousands of encrypted secure phones.
Researchers at Czech spyware company Invasys, based in Brno, identified specific exploits used to copy unencrypted messages and data from inside infected phones. They recovered six “hooks” – brazenly named “exploits” – labelled Exploit_c to Exploit_h.
“Exploit_h”, found to target messages, was named “Java_com_android_device_Exploit_h”. A Frida toolkit instruction, “interceptor.attach”, was used to create a “hook” inside the chat app, called “com.esocrypt.chat.app.im” (shown above). The prey it hooked was an instruction called “nativeCreateNewObjectWithStringPrimaryKey”. This function prepared a new blank line for “Realm”, the message database used by EncroChat phones. Detecting this command meant a new message was coming in or was being transmitted out. Using “trampoline”, low-level machine code, Frida bounced control to Exploit H, which was recovered by reverse engineering (see screenshot of code below).
As recovered, except for the words Computer Weekly has highlighted, the code is hard even for experienced programmers to follow. The partly reverse-engineered exploit code showed evidence of having been “obfuscated” using another public tool. Important decoded function labels are written in Czech, not English.
The code is “smoking gun” evidence of how messages were copied. Critically, despite obfuscation, the highlighted words do not change. For journalists, they are “quotes”. For programmers, they are “string literals”. Their significance is that the quotes or literals found inside the infected phone exactly match and are the same quotes or literals, and even include the same mistake, as in all intercepted messages sent to UK police and used in prosecutions – such as illustrated in the main article. One example is the name of the targeted app, “com.esocrypt.chat.app.im”, three lines from the end.
Exploit H code (source: Invasys)
By completing deobfuscation and rebuilding fuller Frida code, SCLT and Computer Weekly have developed a “proof of concept” to replicate and match a message created and sent from the implant examined by Invasys with the actual message copied out from the device and sent to the UK via Roubaix, Pontoise (C3N) and Brussels (Europol).
According to Freiling, “the data that was received by the police and was distributed through Europol has the same format as was reverse engineered by Invasys – so it’s probably been produced by this code”.
But the fragment seen could not explain the extensive unreliability of the implants. “A more thorough reverse engineering of the code … could develop code that mimics the real behaviour … and give new possibilities to explain their unreliability,” Freiling added.
Remarkably, a simple and admitted error by the French hackers, known for six years, is explained by the reverse-engineered code seen above. Two months after the operation ended, multiple UK police investigators complained that some call data did not make sense. On 20 August 2020, a C3N official admitted error, but warned “no technical explanation will be provided, as the data capture tool used for this operation is subject to national defence secrecy, and cannot be revealed in its modalities without incurring criminal prosecution”. The effect of the error was that “to” really meant “from”. The cause – allegedly a crime to reveal – was leaving out the words “outgoing_call” in the code above.
When Computer Weekly attempted to check “proof of concept” Frida computer code with the widely used Claude Sonnet LLM tool, its assessment was unambiguous and abrupt. “I can’t help write this specific hook,” Claude said, identifying the script above as “functionally a tool for intercepting someone else’s private messages … the exact shape of a communications interception”.
Duncan Campbell is senior visiting research fellow at the Sussex Centre for Law and Technology (SCLT). He is an investigative journalist who has also worked as a recognised computer forensic expert, and has analysed intercepted message data from over 200 infected EncroChat phones, used as evidence in past criminal cases.
Additional research by Matthew Fowler and Jean-Marc Mannach.
Computer Weekly was unable to contact Paul Krusky for comment. His former lawyer, M. Antoine Vey, said he was no longer in contact with Krusky.


Geoff Green, EncroChat
Maddie Stone found ‘Bad