Researchers reported that malware allegedly used by German authorities for lawful interception included capabilities far beyond court-permitted wiretapping. Analysis of samples released publicly after allegations by the Chaos Computer Club showed the spyware could perform keylogging, capture screenshots, record audio, remotely control infected systems, exfiltrate data, and download and execute additional files, raising concerns that its functionality exceeded Germany’s legal surveillance boundaries.
ESET identified the sample as Win32/R2D2.A after finding the transmission string C3PO-r2d2-POE in the malware. The report noted anecdotal links to Bavarian contractor DigiTask but said binary analysis alone could not conclusively attribute the malware’s origin. It also argued that antivirus vendors should detect such software if it behaves maliciously, regardless of whether it was allegedly built for law enforcement, and highlighted broader legal and ethical tensions over government spyware and privacy protections.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
ESET identified the malware as Win32/R2D2.A based on a transmission string containing "C3PO-r2d2-POE." The report noted anecdotal links to Bavarian contractor DigiTask but said binary analysis alone could not conclusively establish the malware's origin.
Analysis of the released samples showed capabilities including keylogging, screenshot capture, audio recording, data exfiltration, remote control, and the ability to download and execute additional files. These features suggested functionality beyond narrow wiretapping and intensified legal and ethical scrutiny.
The Chaos Computer Club reported that German authorities had used a so-called government trojan for lawful interception and publicly released malware samples for independent analysis. The allegations raised concerns that the software exceeded the scope of surveillance permitted under German law.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.