HOME

TheInfoList



OR:

The ANOM (also stylized as AN0M or ΛNØM)
sting operation In law enforcement, a sting operation is a deceptive operation designed to catch a person attempting to commit a crime. A typical sting will have an undercover law enforcement officer, detective, or co-operative member of the public play a role a ...
(known as Operation Trojan Shield (stylized TRØJAN SHIELD) or Operation Ironside) is a collaboration by
law enforcement agencies A law enforcement agency (LEA) is any government agency responsible for the enforcement of the laws. Jurisdiction LEAs which have their ability to apply their powers restricted in some way are said to operate within a jurisdiction. LEAs ...
from several countries, running between 2018 and 2021, that intercepted millions of messages sent through the supposedly secure
smartphone A smartphone is a portable computer device that combines mobile telephone and computing functions into one unit. They are distinguished from feature phones by their stronger hardware capabilities and extensive mobile operating systems, whic ...
-based
messaging app Instant messaging (IM) technology is a type of online chat allowing real-time text transmission over the Internet or another computer network. Messages are typically transmitted between two or more parties, when each user inputs text and trigge ...
ANOM. The ANOM service was widely used by criminals, but instead of providing
secure communication Secure communication is when two entities are communicating and do not want a third party to listen in. For this to be the case, the entities need to communicate in a way that is unsusceptible to eavesdropping or interception. Secure communication ...
, it was actually a
trojan horse The Trojan Horse was a wooden horse said to have been used by the Greeks during the Trojan War to enter the city of Troy and win the war. The Trojan Horse is not mentioned in Homer's ''Iliad'', with the poem ending before the war is concluded, ...
covertly distributed by the United States
Federal Bureau of Investigation The Federal Bureau of Investigation (FBI) is the domestic intelligence and security service of the United States and its principal federal law enforcement agency. Operating under the jurisdiction of the United States Department of Justice, ...
(FBI) and the
Australian Federal Police The Australian Federal Police (AFP) is the national and principal federal law enforcement agency of the Australian Government with the unique role of investigating crime and protecting the national security of the Commonwealth of Australia. Th ...
(AFP), enabling them to monitor all communications. Through collaboration with other law enforcement agencies worldwide, the operation resulted in the arrest of over 800 suspects allegedly involved in criminal activity, in 16 countries. Among the arrested people were alleged members of Australian-based
Italian mafia Organized crime in Italy and its criminal organizations have been prevalent in Italy, especially Southern Italy, for centuries and have affected the social and economic life of many Italian regions since at least the 19th century. There are six ...
, Albanian organised crime,
outlaw motorcycle club An outlaw motorcycle club is a motorcycle subculture generally centered on the use of Cruiser (motorcycle), cruiser motorcycles, particularly Harley-Davidsons and chopper (motorcycle), choppers, and a set of ideals that purport to celebrate fre ...
s, drug
syndicate A syndicate is a self-organizing group of individuals, companies, corporations or entities formed to transact some specific business, to pursue or promote a shared interest. Etymology The word ''syndicate'' comes from the French language, Frenc ...
s and other
organised crime Organized crime (or organised crime) is a category of transnational, national, or local groupings of highly centralized enterprises run by criminals to engage in illegal activity, most commonly for profit. While organized crime is generally th ...
groups.


Background

The shutdown of the Canadian secure messaging company
Phantom Secure Phantom Secure was a Canadian company that provided modified secure mobile phones, which were equipped with a remotely operated kill switch. After its shutdown, criminal users fled to alternatives including ANOM, which turned out to be a honeypot ...
in March 2018 left international criminals in need of an alternative system for secure communication.Multiple sources: * * Around the same time, the
San Diego San Diego ( , ; ) is a city on the Pacific Ocean coast of Southern California located immediately adjacent to the Mexico–United States border. With a 2020 population of 1,386,932, it is the List of United States cities by population, eigh ...
FBI branch had been working with a person who had been developing a "next-generation" encrypted device for use by criminal networks. The person was facing charges and cooperated with the FBI in exchange for a reduced sentence. The person offered to develop ANOM and then distribute it to criminals through their existing networks. The first communication devices with ANOM were offered by this informant to three former distributors of Phantom Secure in October 2018. The FBI also negotiated with an unnamed third country to set up a communication interception, but based on a court order that allowed passing the information back to the FBI. Since October 2019, ANOM communications have been passed on to the FBI from this third country. The FBI named the operation "Trojan Shield", and the AFP named it "Ironside". Europol set up the Operational Task Force Greenlight.


Distribution and usage

The ANOM devices consisted of a messaging app running on Android smartphones that had been specially modified to disable normal functions such as
voice telephony Telephony ( ) is the field of technology involving the development, application, and deployment of telecommunication services for the purpose of electronic transmission of voice, fax, or data, between distant parties. The history of telephony is i ...
,
email Electronic mail (email or e-mail) is a method of exchanging messages ("mail") between people using electronic devices. Email was thus conceived as the electronic ( digital) version of, or counterpart to, mail, at a time when "mail" meant ...
, or
location services A location-based service (LBS) is a general term denoting software services which use geographic data and information to provide services or information to users. LBS can be used in a variety of contexts, such as health, indoor object search, ent ...
, and with the addition of PIN entry screen scrambling to randomise the layout of the numbers, the deletion of all information on the phone if a specific PIN is entered, and the option for the automatic deletion of all information if unused for a specific period of time. The app was opened by entering a specific calculation within the calculator app, described by the developer of
GrapheneOS GrapheneOS (formerly Android Hardening or AndroidHardening) is an Android-based, open source, privacy and security-focused mobile operating system for selected Google Pixel smartphones. History The main developer, Daniel Micay, originally ...
as "quite amusing security theater", where the messaging app then communicated with other devices via supposedly secure
proxy server In computer networking, a proxy server is a server application that acts as an intermediary between a client requesting a resource and the server providing that resource. Instead of connecting directly to a server that can fulfill a request ...
s, which also – unknown to the app's users – copied all sent messages to servers controlled by the FBI. The FBI could then decrypt the messages with a
private key Public-key cryptography, or asymmetric cryptography, is the field of cryptographic systems that use pairs of related keys. Each key pair consists of a public key and a corresponding private key. Key pairs are generated with cryptographic alg ...
associated with the message, without ever needing remote access to the devices. The devices also had a fixed identification number assigned to each user, allowing messages from the same user to be connected to each other. About 50 devices were distributed in Australia for
beta testing Software testing is the act of examining the artifacts and the behavior of the software under test by validation and verification. Software testing can also provide an objective, independent view of the software to allow the business to apprecia ...
from October 2018. The intercepted communications showed that every device was used for criminal activities, primarily being used by organised criminal gangs. About 125 devices were shipped to different drop-off points to the United States in 2020. Use of the app spread through word of mouth, and was also encouraged by undercover agents; drug trafficker
Hakan Ayik Joseph Hakan Ayik, also known as Hakan Reis (born 31 January 1979) is a Turkish Australian drug trafficker who allegedly has an estimated net worth of $1.5 billion. He was described in June 2021 as "Australia's most wanted man". Early life A ...
was identified "as someone who was trusted and was going to be able to successfully distribute this platform", and without his knowledge was encouraged by undercover agents to use and sell the devices on the
black market A black market, underground economy, or shadow economy is a clandestine market or series of transactions that has some aspect of illegality or is characterized by noncompliance with an institutional set of rules. If the rule defines the se ...
, further expanding its use. After users of the devices requested smaller and newer phones, new devices were designed and sold; customer service and technical assistance was also provided by the company. The most commonly used languages on the app were Dutch, German and Swedish. After a slow start, the rate of distribution of ANOM increased from mid-2019. By October 2019, there were several hundred users. By May 2021, there had been 11,800 devices with ANOM installed, of which about 9,000 were in use. New Zealand had 57 users of the ANOM communication system. The Swedish Police had access to conversations from 1,600 users, of which they focused their surveillance on 600 users. Europol stated 27 million messages were collected from ANOM devices across over 100 countries. Some skepticism of the app did exist; one March 2021 WordPress blog post called the app a scam.


Arrests and reactions

The sting operation culminated in
search warrant A search warrant is a court order that a magistrate or judge issues to authorize law enforcement officers to conduct a search of a person, location, or vehicle for evidence of a crime and to confiscate any evidence they find. In most countries, ...
s that were executed simultaneously around the globe on 8 June 2021. It is not entirely clear why this date was chosen, but news organisations have speculated it might be related to a warrant for server access expiring on 7 June. The background to the sting operation and its transnational nature was revealed following the execution of the search warrants. Over 800 people were arrested in 16 countries. Among the arrested people were alleged members of Australian-based
Italian mafia Organized crime in Italy and its criminal organizations have been prevalent in Italy, especially Southern Italy, for centuries and have affected the social and economic life of many Italian regions since at least the 19th century. There are six ...
, Albanian organised crime,
outlaw motorcycle gang An outlaw motorcycle club is a motorcycle subculture generally centered on the use of cruiser motorcycles, particularly Harley-Davidsons and choppers, and a set of ideals that purport to celebrate freedom, nonconformity to mainstream culture, a ...
s, drug
syndicate A syndicate is a self-organizing group of individuals, companies, corporations or entities formed to transact some specific business, to pursue or promote a shared interest. Etymology The word ''syndicate'' comes from the French language, Frenc ...
s and other crime groups. In the
European Union The European Union (EU) is a supranational political and economic union of member states that are located primarily in Europe. The union has a total area of and an estimated total population of about 447million. The EU has often been des ...
, arrests were coordinated through Europol. Arrests were also made in the United Kingdom, although the
National Crime Agency The National Crime Agency (NCA) is a national law enforcement agency in the United Kingdom. It is the UK's lead agency against organised crime; human, weapon and drug trafficking; cybercrime; and economic crime that goes across regional and in ...
was unwilling to provide details about the number arrested. The seized evidence included almost 40 tons of drugs (over eight tons of cocaine, 22 tons of cannabis and cannabis resin, six tons of synthetic drug precursors, two tons of synthetic drugs), 250 guns, 55 luxury cars, and more than $48 million in various currencies and cryptocurrencies. In Australia, 224 people were arrested on 526 total charges. In New Zealand, 35 people were arrested and faced a total of 900 charges. Police seized $3.7 million in assets, including 14 vehicles, drugs, firearms and more than $1 million in cash. Over the course of the three years, more than 9,000 police officers across 18 countries were involved in the sting operation. Australian Prime Minister
Scott Morrison Scott John Morrison (; born 13 May 1968) is an Australian politician. He served as the 30th prime minister of Australia and as Leader of the Liberal Party of Australia from 2018 to 2022, and is currently the member of parliament (MP) for t ...
said that the sting operation had "struck a heavy blow against organised crime". Europol described it as the "biggest ever law enforcement operation against encrypted communication". In 2022, ''Motherboard'' journalist Joseph Cox published documents stating that the FBI obtained message data through the cooperation of an unnamed country within the
European Union The European Union (EU) is a supranational political and economic union of member states that are located primarily in Europe. The union has a total area of and an estimated total population of about 447million. The EU has often been des ...
.


Australia

About 50 of the devices had been sold in Australia. Police arrested 224 suspects and seized 104 firearms and confiscated cash and possessions valued at more than 45 million AUD.


Germany

In Germany, the majority of the police activity was in the state of
Hesse Hesse (, , ) or Hessia (, ; german: Hessen ), officially the State of Hessen (german: links=no, Land Hessen), is a States of Germany, state in Germany. Its capital city is Wiesbaden, and the largest urban area is Frankfurt. Two other major histor ...
where 60 of the 70 nationwide suspects were arrested. Police searched 150 locations and in many cases under suspicion of drug trafficking.


Netherlands

In the Netherlands, 49 people were arrested by Dutch police while they investigated 25 drug production facilities and narcotics caches. Police also seized eight firearms, large supplies of narcotics and more than 2.3 million euros.


Sweden

In Sweden, 155 people were arrested as part of the operation. According to police in Sweden which received intelligence from the FBI, during an early phase of the operation it was discovered that many of the suspects were in Sweden. Linda Staaf, head of the Swedish police's intelligence activities, said that the suspects in Sweden had a higher rate of violent crime than the other countries.


United States

No arrests were made in the United States because of privacy laws that prevented law enforcement from collecting messages from domestic subjects. However, the
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a federal executive department of the United States government tasked with the enforcement of federal law and administration of justice in the United State ...
indicted seventeen persons (all foreign nationals) under the
Racketeer Influenced and Corrupt Organizations Act The Racketeer Influenced and Corrupt Organizations (RICO) Act is a United States federal law that provides for extended criminal penalties and a civil cause of action for acts performed as part of an ongoing criminal organization. RICO was en ...
for their participation in "the ANOM enterprise" which spread the devices.


Legal challenges

, multiple court cases have been brought in Australia to challenge the legitimacy of the ANOM sting operation. A judgment in one of the cases before the
Supreme Court of South Australia The Supreme Court of South Australia is the superior court of the Australian state of South Australia. The Supreme Court is the highest South Australian court in the Australian court hierarchy. It has unlimited jurisdiction within the state in ...
has ruled in favor of the police.


See also

*
EncroChat EncroChat was a Europe-based communications network and service provider that offered modified smartphones allowing encrypted communication among subscribers. It was used primarily by organized crime members to plan criminal activities. Police ...
– a network infiltrated by law enforcement to investigate
organized crime Organized crime (or organised crime) is a category of transnational, national, or local groupings of highly centralized enterprises run by criminals to engage in illegal activity, most commonly for profit. While organized crime is generally th ...
in Europe *
Ennetcom Ennetcom was a Netherlands based communications network and service provider. The company was based in the Netherlands as were most of its customers, but most of the company servers were based in Canada. Danny Manupassa, the company owner, was ar ...
– a network seized by Dutch authorities, who used it to make arrests *
Sky Global Sky Global was a communications network and service provider founded in 2008 in Vancouver, Canada. A significant share of users of its systems were international crime organizations involved in drug trafficking, and the company management was su ...
– a communications network and service provider based in Vancouver, Canada


References


External links

{{Commons category , Operation Trojan Shield
ANOM.io - Domain Seized
- as of 8 June 2021, this displays FBI and AFP graphics, a "Trojan Shield" graphic and a "This domain has been seized" notice, with a form inviting visitors "To determine if your account is associated with an ongoing investigation, please enter any device details below" 2021 in international relations 2021 in law Anonymity networks Deception operations Encryption debate Secure communication Operations against organized crime Law enforcement operations Trojan horses June 2021 events History of cryptography Federal Bureau of Investigation operations