Security Affairs
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Thieving Magpie allows NSA spies to snoop on in-flight mobile calls

The Thieving Magpie programme allows the NSA and the GCHQ to intercept data from passengers traveling on board commercial aircrafts. This isn’t a sci-fi movie, the GCHQ and the NSA have spied on air passengers using in-flight GSM mobile services for years. The news was revealed by new documents obtained by Edward Snowden and recently […]

Thieving Magpie allows NSA spies to snoop on in-flight mobile calls

The Thieving Magpie programme allows the NSA and the GCHQ to intercept data from passengers traveling on board commercial aircrafts.

This isn’t a sci-fi movie, the GCHQ and the NSA have spied on air passengers using in-flight GSM mobile services for years.

The news was revealed by new documents obtained by Edward Snowden and recently published by The Intercept.

Today, approximately 100 companies permit the in-flight use of mobile devices.

Passengers of the principal airlines (British Airways, Virgin Atlantic, Lufthansa, and many Arab and Asian companies) can access in-flight GSM mobile services using the system designed by the UK company AeroMobile and SitaOnAir. The passengers connect to the on-board GSM servers that communicate with satellites operated by British firm Inmarsat.

The spy agencies could target in-flight passengers through the “Thieving Magpie” programme. The system allows spying on the victims even when targets are not using the mobile devices for calls or any data transfer. It is sufficient that the phone is switched on and registered with the in-flight GSM service.

Below an excerpt from the presentation

  • “If a target’s phone is switched on, it Will attempt to register to its home network that it using the OnAir service even if they don’t actually make/receive a call.
  • Registration requests can be combined with the right number/callsign of the aircraft
  • Available in near real time (approximately 10 minute delay)”

According to the presentation leaked by Snowden, the GCHQ and the NSA are able to intercept the transmission from the satellites to the ground stations.

Thieving Magpie

Thieving Magpie allowed the intelligence agencies to spy on flights in Europe, the Middle East, and Africa, but according to the presentation, it was designed for a global surveillance.

The surveillance program allows data collection in “near real time,” spies can track aircraft every two minutes while in flight.

Thieving Magpie program allows spying on any data sent via the GSM network, the cyber spies could access gather e-mail addresses, Facebook IDs, and Skype addresses. It also allows monitoring of Twitter, Google Maps, BitTorrent, and VoIP.

Thieving Magpie

According to Le Monde, the CIA was especially interested in Air France and Air Mexico flights, because they are potential targets for terrorists.

“We can read that, as from the end of 2003, ‘the CIA considered that Air France and Air Mexico flights were potential targets for terrorists’.” states the article published by Le Monde “The legal department of the NSA stated at this point ‘there is absolutely no legal problem in targeting aircraft from these two companies abroad’ and ‘they should be kept under strict surveillance from the point at which they enter American air space’.”

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Thieving Magpie, surveillance)