Full Report
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account. Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them. Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance...
Analysis Summary
# Tool/Technique: Unauthorized Desktop Client Linking (Session Hijacking)
## Overview
This technique involves an adversary (in this case, law enforcement) linking a secondary, controlled device (e.g., WhatsApp Web or Signal Desktop) to a target's primary mobile messaging account. By exploiting the legitimate "Multi-device" or "Linked Devices" feature of end-to-end encrypted (E2EE) apps, the attacker gains real-time access to incoming and outgoing messages without needing to break the underlying encryption.
## Technical Details
- **Type:** Technique / Post-Exploitation / Session Hijacking
- **Platform:** Cross-platform (Android/iOS mobile accounts linked to Windows/macOS/Linux/Web desktops)
- **Capabilities:** Real-time message synchronization, contact list access, bypass of E2EE via authorized endpoint addition.
- **First Seen:** Publicly detailed in reports regarding Germany’s Customs Office (Zollkriminalamt) practices circa 2020.
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- **T1091 - Replication Through Removable Media** (Physical access to mobile device)
- **T1566 - Phishing** (Stealing verification codes)
- **[TA0006 - Credential Access]**
- **T1539 - Steal Web Session Cookie**
- **[TA0009 - Collection]**
- **T1602 - Data from Information Repositories** (Messaging account synchronization)
- **[TA0005 - Defense Evasion]**
- **T1550.004 - Use Alternate Authentication Material: Web Session Cookie**
## Functionality
### Core Capabilities
- **Session Synchronization:** Automatically mirrors the target's chat history and live communications to a secondary device.
- **Encryption Bypass:** Accesses plaintext data at the endpoint, rendering the "in-transit" encryption moot.
- **Persistent Access:** Once the QR code is scanned or the verification code is entered, the session remains active until manually revoked by the user.
### Advanced Features
- **SMS Interception:** Utilizing Lawful Interception (LI) interfaces to capture SMS verification codes to authorize new desktop instances remotely.
- **Phishing Kits:** State-sanctioned phishing pages designed to trick users into providing two-factor authentication (2FA) codes or scanning QR codes.
## Indicators of Compromise
- **File Hashes:** N/A (Uses legitimate binaries like Signal-Desktop.exe or WhatsApp.exe)
- **Network Indicators:** Connections to legitimate messaging API endpoints (e.g., `web.whatsapp[.]com`, `chat.signal[.]org`).
- **Behavioral Indicators:**
- Login notifications from new, unrecognized locations or devices.
- Unexpected "Active Session" entries in the mobile app's "Linked Devices" settings.
- Receipt of unsolicited SMS verification codes.
## Associated Threat Actors
- **Zollkriminalamt (ZKA):** Germany’s Customs Investigation Bureau.
- **State-level Law Enforcement:** Various agencies utilizing "Lawful Access" methodologies.
## Detection Methods
- **Manual Audit:** Regularly checking the "Linked Devices" or "WhatsApp Web" section in the mobile application settings for unauthorized active sessions.
- **Push Notifications:** Monitoring for service-generated notifications that state "A new device has logged into your account."
- **SMS Monitoring:** Identifying unauthorized requests for account verification codes.
## Mitigation Strategies
- **Physical Security:** Use strong biometric or passcode locks on mobile devices to prevent unauthorized QR code scanning.
- **Two-Step Verification:** Enabling a secondary PIN/Password within the messaging app to prevent new devices from being added even if the SMS is intercepted.
- **Session Review:** Periodically logging out of all active web/desktop sessions.
- **Security Notifications:** Ensuring that "Security Notifications" are enabled to alert the user when a contact's safety number changes or a new device is added.
## Related Tools/Techniques
- **SIM Swapping:** Intercepting the mobile identity to register a new instance.
- **Session Cookie Theft:** Extracting local storage/browser cookies to clone a session.
- **Pegasus/Predator:** While this technique is "low-tech," it achieves similar surveillance goals as high-end spyware without the need for zero-day exploits.