Operation Trojan Shield Explained

Operation Trojan Shield
Partof:Operation Ironside
Planned By:U.S. Federal Bureau of Investigation, Europol, Australian Federal Police, and others
Executed By:United States, Australia, Europol+
Country Names:Sweden, United States, Australia, United Kingdom, New Zealand, Germany, Netherlands,
Countries Number:16
Method:Honeypot communication device with security backdoor
Target:organized criminal networks that use encrypted communication devices
Objective:Surveillance of criminal activity
Date Begin:2018
Date End:2021
Suspects Number:Germany:150
Arrested Number:1,119+

The ANOM (also stylized as AN0M or ΛNØM) sting operation (known as Operation Trojan Shield (stylized TRØJAN SHIELD) or Operation Ironside) is a collaboration by law enforcement agencies from several countries, running between 2018 and 2021, that intercepted millions of messages sent through the supposedly secure smartphone-based proprietary messaging app ANOM. The ANOM service was widely used by criminals, but instead of providing secure communication, it was actually a trojan horse covertly distributed by the United States Federal Bureau of Investigation (FBI) and the Australian Federal Police (AFP), enabling them to monitor all communications. Through collaboration with other law enforcement agencies worldwide, the operation resulted in the arrest of over 800 suspects allegedly involved in criminal activity, in 16 countries. Among the arrested people were alleged members of Australian-based Italian mafia, Albanian organised crime, outlaw motorcycle clubs, drug syndicates and other organised crime groups.

Background

An investigation into a Canadian secure messaging company called Phantom Secure was initiated in 2017. The FBI alleges that the investigation revealed that Phantom Secure sold its encrypted devices exclusively to members of transnational criminal organizations (TCO). Hardened encrypted devices provide an "impenetrable shield against law enforcement surveillance” and are in high demand by TCOs, thus the shutdown of Phantom Secure in March 2018 left a vacuum for TCOs in need of an alternative system for secure communication.

Around the same time, the San Diego FBI branch had been working with a person who had been developing a "next-generation" encrypted device for use by criminal networks. The person was facing charges and cooperated with the FBI in exchange for a reduced sentence. The person offered to develop ANOM and then use his contacts to distribute it to TCOs through existing networks.[1] Before the devices were put to use, however, the FBI, and the AFP had a backdoor built into the communication platform which allowed law enforcement agencies to decrypt and store the messages as the messages were transmitted. The first communication devices with ANOM were offered by this informant to three former distributors of Phantom Secure in October 2018.[2]

The FBI named the operation "Trojan Shield",[3] and the AFP named it "Ironside".[4] Europol set up the Operational Task Force Greenlight.[5]

Distribution and usage

The ANOM devices consisted of a messaging app running on Android smartphones with a custom ROM called ArcaneOS that had been specially modified to disable normal functions such as voice telephony, email, or location services, and with the addition of PIN entry screen scrambling to randomise the layout of the numbers, the deletion of all information on the phone if a specific PIN is entered, and the option for the automatic deletion of all information if unused for a specific period of time.[6]

The app was opened by entering a specific calculation within the calculator app, described by the developer of GrapheneOS as "quite amusing security theater", where the messaging app then communicated with other devices via supposedly secure proxy servers, which also – unbeknownst to the app's users – copied all sent messages to servers controlled by the FBI. The FBI could then decrypt the messages with a private key associated with the message, without ever needing remote access to the devices.[7] The devices also had a fixed identification number assigned to each user, allowing messages from the same user to be connected to each other.

About 50 devices were distributed in Australia for beta testing from October 2018. The intercepted communications showed that every device was used for criminal activities, primarily being used by organised criminal gangs. About 125 devices were shipped to different drop-off points to the United States in 2020.[8]

Use of the app spread through word of mouth, and was also encouraged by undercover agents;[9] drug trafficker Hakan Ayik was identified "as someone who was trusted and was going to be able to successfully distribute this platform", and without his knowledge was encouraged by undercover agents to use and sell the devices on the black market, further expanding its use.[10] After users of the devices requested smaller and newer phones, new devices were designed and sold; customer service and technical assistance was also provided by the company. The most commonly used languages on the app were Dutch, German and Swedish.[11]

After a slow start, the rate of distribution of ANOM increased from mid-2019. By October 2019, there were several hundred users. By May 2021, there had been 11,800 devices with ANOM installed, of which about 9,000 were in use. New Zealand had 57 users of the ANOM communication system. The Swedish Police had access to conversations from 1,600 users, of which they focused their surveillance on 600 users.[12] Europol stated 27 million messages were collected from ANOM devices across over 100 countries.[13]

Some skepticism of the app did exist; one WordPress blog post in March 2021 called the app a scam.[14] [15] [16]

Law enforcement operational methodology

The following is alleged by the FBI:

2018

The "backdoor" built by the FBI into the system by design would send an additional encrypted copy of each message sent by the ANOM users to a third party server referred to by the FBI as an "iBot" server. Fourth amendment interpretations endangered the project if the iBot servers were located in the U.S. and so the servers necessarily were located outside U.S. borders. The first server would decrypt the copied message, process the information in the message (GPS location, text, username/Jabber-ID, password etc.) and then re-encrypt it to send it to a second "FBI-owned" iBot server (iBot2).

2019

Because the FBI could not own the first iBot node, nor were they permitted to receive any of the seized information about U.S. citizens, they contracted with the AFP to run the first node of the server and process the data. (Australian law does not provide the same protections as U.S. law for its citizens.) Controversially the AFP did share "general" information about conversations from the ANOM messages with the FBI during this time period despite Australia’s judicial order to intercept ANOM communications did not allow for the sharing of the content with foreign partners.

Summer 2019

Allegedly, the FBI officially had not reviewed any of the ANOM decrypted content yet by the summer of 2019. As a method of getting around the Australian court order, the FBI needed to secure a mutual legal assistance treaty (MLAT) request with a third country where the transfer of information would be legal pursuant to their national laws. While much work was done to keep the identity of the third country secret, its identity was discovered by the press as Lithuania in 2023.[17]

The FBI worked with Lithuania through the Autumn of 2019. However, the FBI alleges that the iBots had geo-fenced all messages that originated from the U.S., to prevent the FBI-owned iBot2 server from inadvertently seizing messages in violation of the Fourth Amendment.

7 October 2019 - 7 January 2020

Lithuania created an iBOT copy (iBot3) of the FBI-owned iBOT2 server and began receiving content from the iBOT2 server every 2–3 days.

Post 7 January 2020

A newer MLAT and court order from Lithuania allowed the FBI to receive ANOM user data every Monday, Wednesday and Friday until 7 June 2021. This encompasses all data ever generated by any ANOM user with the alleged exception of 15 (or 17) users that originated from phones in the U.S.

Arrests and reactions

The sting operation culminated in search warrants that were executed simultaneously around the globe on 8 June 2021.[18] It is not entirely clear why this date was chosen, but news organisations have speculated it might be related to a warrant for server access expiring on 7 June. The background to the sting operation and its transnational nature was revealed following the execution of the search warrants. Over 800 people were arrested in 16 countries.[19] [20] [21] Among the arrested people were alleged members of Australian-based Italian mafia, Albanian organised crime, outlaw motorcycle gangs, drug syndicates and other crime groups.[19] [4] [22] In the European Union, arrests were coordinated through Europol.[23] Arrests were also made in the United Kingdom, although the National Crime Agency was unwilling to provide details about the number arrested.[24]

The seized evidence included almost 40 tons of drugs (over eight tons of cocaine, 22 tons of cannabis and cannabis resin, six tons of synthetic drug precursors, two tons of synthetic drugs), 250 guns, 55 luxury cars, and more than $48 million in various currencies and cryptocurrencies. In Australia, 224 people were arrested on 526 total charges. In New Zealand, 35 people were arrested and faced a total of 900 charges. Police seized $3.7 million in assets, including 14 vehicles, drugs, firearms and more than $1 million in cash.[25]

Over the course of the three years, more than 9,000 police officers across 18 countries were involved in the sting operation. Australian Prime Minister Scott Morrison said that the sting operation had "struck a heavy blow against organised crime". Europol described it as the "biggest ever law enforcement operation against encrypted communication".[19]

In 2022, Motherboard journalist Joseph Cox published documents stating that the FBI obtained message data through the cooperation of an unnamed country within the European Union.[26]

Australia

About 50 of the devices had been sold in Australia. Australian Federal Police arrested 224 suspects and seized 104 firearms and confiscated cash and possessions valued at more than 45 million AUD.[27]

Germany

In Germany, the majority of the police activity was in the state of Hesse where 60 of the 70 nationwide suspects were arrested.[28] Police searched 150 locations and in many cases under suspicion of drug trafficking.[29]

Netherlands

In the Netherlands, 49 people were arrested by Dutch National Police while they investigated 25 drug production facilities and narcotics caches. Police also seized eight firearms, large supplies of narcotics and more than 2.3 million euros.

Sweden

See also: Gun violence in Sweden. In Sweden, 155 people were arrested as part of the operation. According to police in Sweden which received intelligence from the FBI, during an early phase of the operation it was discovered that many of the suspects were in Sweden. Linda Staaf, head of the Swedish police's intelligence activities, said that the suspects in Sweden had a higher rate of violent crime than the other countries.[30]

United States

The first search warrants were granted by judges in May 2021. Initially, no arrests were made in the United States because of 4th amendment interpretations that prevented law enforcement from collecting messages from domestic subjects.[31] However, the United States Department of Justice indicted seventeen persons (all foreign nationals, see court dockets here) under the Racketeer Influenced and Corrupt Organizations Act for their participation in "the ANOM enterprise" which spread the devices.[32]

Legal challenges

, multiple court cases have been brought in Australia to challenge the legitimacy of the ANOM sting operation. A judgment in one of the cases before the Supreme Court of South Australia has ruled in favor of the police,[33] although that judgment has, since November 2023, been appealed.[34]

See also

External links

Notes and References

  1. Web site: Corder . Mike . Perry . Nick . Spagat . Elliot . 2021-06-08 . Global sting began by creating message service for crooks . live . https://web.archive.org/web/20210608103515/https://apnews.com/article/europe-technology-a6ac691e26be2efc6e2f4a6974117536 . 8 June 2021 . 2023-04-06 . AP NEWS . en.
  2. News: Zhuang. Yan. Peltier. Elian. Feuer. Alan. 8 June 2021. The Criminals Thought the Devices Were Secure. But the Seller Was the F.B.I.. en-US. The New York Times. 8 June 2021. 0362-4331. 9 June 2021. https://web.archive.org/web/20210609014628/https://www.nytimes.com/2021/06/08/world/australia/operation-trojan-horse-anom.html. live.
  3. News: 8 June 2021 . Hundreds arrested in global crime sting after underworld app is hacked. Harding. Luke . 8 June 2021 . . 9 June 2021 . https://web.archive.org/web/20210609034518/https://www.theguardian.com/australia-news/2021/jun/08/anom-encrypted-app-fbi-afp-australia-federal-police-sting-operation-ironside-an0m . live .
  4. News: Westcott . Ben . FBI and Australian Federal Police encrypted app trap ensnares hundreds of criminal suspects . 8 June 2021 . . 9 June 2021 . https://web.archive.org/web/20210609005546/https://www.cnn.com/2021/06/08/australia/afp-fbi-anom-app-operation-ironside/index.html . live.
  5. https://twitter.com/Europol/status/1402115313559388164 Europol
  6. Web site: Cox . Joseph . 8 July 2021 . We Got the Phone the FBI Secretly Sold to Criminals . 2021-07-08 . Vice . en.
  7. Web site: Robertson. Adi. 8 June 2021. The FBI secretly launched an encrypted messaging system for criminals. 8 June 2021. The Verge. en. 9 June 2021. https://web.archive.org/web/20210609013810/https://www.theverge.com/2021/6/8/22524307/anom-encrypted-messaging-fbi-europol-afp-sting-operation-trojan-shield-greenlight. live.
  8. Web site: Cox . Joseph . 12 January 2022 . FBI Honeypot Phone Company Anom Shipped Over 100 Phones to the United States . 2022-01-12 . Vice . en.
  9. Web site: 8 June 2021. Underworld figure Hakan Ayik unwittingly helped Operation Ironside, the AFP's biggest criminal sting. 8 June 2021. Australian Broadcasting Corporation. en-AU. 9 June 2021. Taouk. Maryanne. https://web.archive.org/web/20210609034449/https://www.abc.net.au/news/2021-06-09/fugitive-hakan-ayik-unwittingly-helped-operation-ironside/100198164. live.
  10. News: 8 June 2021. Hakan Ayik: The man who accidentally helped FBI get in criminals' pockets. en-GB. BBC News. 8 June 2021. 8 June 2021. https://web.archive.org/web/20210608184123/https://www.bbc.com/news/world-57397779. live.
  11. News: 8 June 2021. 49 NL arrests in international 'encrypted phones' operation. NL Times. 10 June 2021.
  12. News: Smed . Akvelina . 8 June 2021 . 155 tungt kriminella gripna i Sverige i stor insats . sv . 155 serious criminals arrested in Sweden in large operation . . live . 8 June 2021 . https://web.archive.org/web/20210609034449/https://www.svt.se/nyheter/inrikes/europol-berattar-om-det-omfattande-tillslaget . 9 June 2021.
  13. Web site: Drug Rings' Favorite New Encrypted Platform Had One Flaw: The FBI Controlled It. 8 June 2021. NPR. en. 9 June 2021. Chappell. Bill. NPR. 8 June 2021. https://web.archive.org/web/20210609034455/https://www.npr.org/2021/06/08/1004332551/drug-rings-platform-operation-trojan-shield-anom-operation-greenlight. live.
  14. Web site: ANOM Encrypted Scam Exposed . dead . https://web.archive.org/web/20210610004653/http://webcache.googleusercontent.com/search?q=cache%3Ahttps%3A%2F%2Fanomexposed.wordpress.com%2F2021%2F03%2F29%2Fanom-encrpted-scam-exposed%2F . 10 June 2021 . 13 June 2021 . ANOM Exposed .
  15. Web site: 9 June 2021. Anom Encrypted App Analysis. 9 June 2021. https://web.archive.org/web/20210609010314/https://the-latest.news/anom-encrypted-app-analysis/. 9 June 2021. live.
  16. News: 8 June 2021. ANOM global phone sting: What we know. Raidió Teilifís Éireann. Agence France-Presse. 8 June 2021. 9 June 2021. https://web.archive.org/web/20210609034448/https://www.rte.ie/news/2021/0608/1226913-global-crime/. live.
  17. Web site: Revealed: The Country that Secretly Wiretapped the World for the FBI. Joseph. Cox ·. 11 September 2023. 404 Media.
  18. News: Anom: The app at the heart of the FBI's major transnational sting . 8 June 2021 . . 8 June 2021 . 9 June 2021 . https://web.archive.org/web/20210609034449/https://www.nzherald.co.nz/nz/anom-the-app-at-the-heart-of-the-fbis-major-transnational-sting/HUPSM4FPQT2KZCBSVAUINWA2GE/ . live .
  19. News: 8 June 2021. ANOM: Hundreds arrested in massive global crime sting. en-GB. BBC News. 8 June 2021. 8 June 2021. https://web.archive.org/web/20210608054245/https://www.bbc.com/news/world-57394831. live.
  20. Web site: Cox. Joseph. 8 June 2021. Trojan Shield: How the FBI Secretly Ran a Phone Network for Criminals. live. 8 June 2021. Vice. en. 8 June 2021. https://web.archive.org/web/20210608031704/https://www.vice.com/en/article/akgkwj/operation-trojan-shield-anom-fbi-secret-phone-network.
  21. Web site: Svetlova . Anna . 8 June 2021 . ru:Европол задержал более 800 преступников в рамках международной операции . Europol detained over 800 criminals as part of an international operation . https://www.gazeta.ru/social/news/2021/06/08/n_16076948.shtml . live . https://web.archive.org/web/20210609034451/https://www.gazeta.ru/social/news/2021/06/08/n_16076948.shtml . 9 June 2021 . . ru . 8 June 2021.
  22. AFP-led Operation Ironside smashes organised crime . 8 June 2021 . Australian Federal Police . live . https://web.archive.org/web/20210608025117/https://www.afp.gov.au/news-media/media-releases/afp-led-operation-ironside-smashes-organised-crime . 8 June 2021 . 8 June 2021.
  23. Web site: Trojan Shield: Europol details massive organized crime sting. 8 June 2021. 8 June 2021. Deutsche Welle. en-GB. 9 June 2021. https://web.archive.org/web/20210609034451/https://www.dw.com/en/trojan-shield-europol-details-massive-organized-crime-sting/a-57808917. live.
  24. News: Davis . Margaret . UK criminals among those duped into using secret message service run by the FBI . en-GB . Belfast Telegraph . live . 8 June 2021 . https://web.archive.org/web/20210609034450/https://www.belfasttelegraph.co.uk/news/uk/uk-criminals-among-those-duped-into-using-secret-message-service-run-by-the-fbi-40514540.html . 9 June 2021 . 0307-1235.
  25. Web site: Corder . Mike . Perry . Nick . 8 June 2021 . FBI-encrypted app hailed as a 'shining example' of collaboration between world cops for tricking gangs . live . https://web.archive.org/web/20210609034451/https://www.stuff.co.nz/national/crime/300327974/fbiencrypted-app-hailed-as-a-shining-example-of-collaboration-between-world-cops-for-tricking-gangs . 9 June 2021 . 8 June 2021 . Stuff . en.
  26. Web site: Cox . Joseph . 2022-06-03 . A European Country Helped the FBI Intercept Anom Messages, But It Wants to Remain Hidden . 2022-06-03 . Vice . en.
  27. Web site: 9 June 2021 . Checks and balances needed for new police surveillance powers . 2021-06-11 . The Sydney Morning Herald . en.
  28. News: 9 June 2021 . Nach Europol-Razzia: Verdächtige in Untersuchungshaft . de . After Europol raid: Suspects in custody . Die Welt . 10 June 2021.
  29. News: 9 June 2021 . Nach Europol-Razzia: Dutzende Beschuldigte in Deutschland . de . After Europol raid: dozens of suspects in Germany . saarbruecker-zeitung.de . 10 June 2021.
  30. News: Smed . Akvelina . Jönsson . Oskar . Boati . David . 2021-06-08 . Underrättelsechefen: 'Sveriges användare stack ut' . sv . The head of intelligence: 'Sweden's users stood out' . SVT Nyheter . 2021-06-09 . 10 June 2021 . https://web.archive.org/web/20210610023020/https://www.svt.se/nyheter/inrikes/underrattelsechefen-sveriges-anvandare-stack-ut . live .
  31. Web site: Malone . Ursula . 2021-06-14 . The FBI played a huge role in Operation Ironside but haven't made a single arrest – here's why . 2021-06-15 . ABC News . en-AU.
  32. Web site: Cox . Joseph . 9 June 2021 . DOJ Charges Criminal 'Influencers' Who Worked for FBI's Honeypot Phone Company . 2022-05-23 . Vice . en.
  33. News: 2023-04-17 . Why accused criminals are challenging evidence from one of the world's biggest police stings . en-AU . ABC News . 2023-04-18.
  34. News: Mott . Mitch . The argument that could bring Operation Ironside tumbling down . . 17 November 2023.