U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Thieving Magpie allows NSA spies to snoop on in-flight mobile calls

The Thieving Magpie programme allows the NSA and the GCHQ to intercept data from passengers traveling on board commercial aircrafts. This isn’t a sci-fi movie, the GCHQ and the NSA have spied on air passengers using in-flight GSM mobile services for years. The news was revealed by new documents obtained by Edward Snowden and recently […]

Thieving Magpie allows NSA spies to snoop on in-flight mobile calls

The Thieving Magpie programme allows the NSA and the GCHQ to intercept data from passengers traveling on board commercial aircrafts.

This isn’t a sci-fi movie, the GCHQ and the NSA have spied on air passengers using in-flight GSM mobile services for years.

The news was revealed by new documents obtained by Edward Snowden and recently published by The Intercept.

Today, approximately 100 companies permit the in-flight use of mobile devices.

Passengers of the principal airlines (British Airways, Virgin Atlantic, Lufthansa, and many Arab and Asian companies) can access in-flight GSM mobile services using the system designed by the UK company AeroMobile and SitaOnAir. The passengers connect to the on-board GSM servers that communicate with satellites operated by British firm Inmarsat.

The spy agencies could target in-flight passengers through the “Thieving Magpie” programme. The system allows spying on the victims even when targets are not using the mobile devices for calls or any data transfer. It is sufficient that the phone is switched on and registered with the in-flight GSM service.

Below an excerpt from the presentation

  • “If a target’s phone is switched on, it Will attempt to register to its home network that it using the OnAir service even if they don’t actually make/receive a call.
  • Registration requests can be combined with the right number/callsign of the aircraft
  • Available in near real time (approximately 10 minute delay)”

According to the presentation leaked by Snowden, the GCHQ and the NSA are able to intercept the transmission from the satellites to the ground stations.

Thieving Magpie

Thieving Magpie allowed the intelligence agencies to spy on flights in Europe, the Middle East, and Africa, but according to the presentation, it was designed for a global surveillance.

The surveillance program allows data collection in “near real time,” spies can track aircraft every two minutes while in flight.

Thieving Magpie program allows spying on any data sent via the GSM network, the cyber spies could access gather e-mail addresses, Facebook IDs, and Skype addresses. It also allows monitoring of Twitter, Google Maps, BitTorrent, and VoIP.

Thieving Magpie

According to Le Monde, the CIA was especially interested in Air France and Air Mexico flights, because they are potential targets for terrorists.

“We can read that, as from the end of 2003, ‘the CIA considered that Air France and Air Mexico flights were potential targets for terrorists’.” states the article published by Le Monde “The legal department of the NSA stated at this point ‘there is absolutely no legal problem in targeting aircraft from these two companies abroad’ and ‘they should be kept under strict surveillance from the point at which they enter American air space’.”

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Thieving Magpie, surveillance)