French law enforcement compromised EncroChat phones by exploiting CVE-2019-2215—the Android Binder use-after-free flaw known as Bad Binder—and pushing a malware implant through EncroChat’s update infrastructure, according to a forensic re-analysis cited by Computer Weekly. Investigators reportedly recovered the implant from an infected device and found it used Frida hooks and Realm libraries to capture plaintext messages and other data directly on the handset, then exfiltrate the material to a French police-controlled server hosted by OVH in Roubaix. The findings indicate the operation collected evidence from infected endpoints rather than decrypting communications in transit, a distinction with potential consequences for EncroChat prosecutions across the UK and Europe.
Bad Binder was previously documented by Google Project Zero as an in-the-wild Android local privilege-escalation vulnerability that could lead to full device compromise through arbitrary kernel read/write and root access. Public reporting and exploit material show the flaw was widely actionable on unpatched Android devices, and a GitHub proof-of-concept demonstrated how it could be adapted to disable protections such as SELinux and gain broad system control. The new reporting says the EncroChat implant itself was technically unsophisticated and partly assembled from public code, raising fresh questions about disclosure, forensic integrity, and whether evidence derived from the infected devices could have been altered before being presented in court.

Trace attribution and downstream blast radius.
14 events from the most recent confirmed update back to the earliest known activity.
On 2 April 2020, infected EncroChat phones began exfiltrating copied data to a French police-controlled server. French authorities had redirected devices to a replica update server under their control.
Computer Weekly reported that French authorities inserted their implant into EncroChat's update infrastructure on 1 April 2020. The operation abused CVE-2019-2215 and control of the update mechanism to deliver malware to devices.
Over the following two months after the initial deployment, 32,014 EncroChat devices were infected and controlled by the French command server. The implant copied plaintext messages, passwords, images, notes, keys, and location-related data from phones.
A GitHub repository for CVE-2019-2215 shows a commit on October 17, 2019 adding a full exploit from Qu1ckR00t. The code demonstrates arbitrary kernel read/write, privilege escalation to root, and disabling protections such as SELinux and seccomp on vulnerable Android devices.
Android stated that updates for affected Pixel devices were available as early as October 7, 2019. Project Zero noted Pixel 3 and Pixel 3a were already protected.
Android added updates for CVE-2019-2215 to the October 2019 Android Security Bulletin on October 6, 2019. Project Zero said devices with a security patch level on or after that date should be patched.
On October 3, 2019, Project Zero disclosed issue 1942 as CVE-2019-2215 because it had credible evidence of in-the-wild exploitation. The disclosure identified the flaw as a Binder driver use-after-free enabling local privilege escalation to full device compromise.
A Project Zero bug tracker entry for 'Android: Use-After-Free in Binder driver' was published as issue 1942. This issue is the vulnerability record later associated with CVE-2019-2215.
Project Zero reported the security implications of the Binder bug to Android on September 26, 2019. Android later assigned it CVE-2019-2215 after that report.
In late summer 2019, Google's Threat Analysis Group, Android Security, and Project Zero received information suggesting NSO had an Android 0-day exploit used in a Pegasus attack chain. The details pointed to a kernel use-after-free reachable from inside the Chrome sandbox.
The Binder use-after-free flaw was patched in Linux 4.14 and Android 3.18, 4.4, and 4.9 kernels in February 2018. Project Zero later noted the fix was not included in Android monthly security bulletins, leaving many shipped devices unpatched.
Project Zero said the underlying Binder driver bug was originally found and reported by syzbot in November 2017. At that time it was not yet recognized or tracked as a security vulnerability with a CVE.
Computer Weekly reported that French law enforcement hacked EncroChat phones in 2020 by abusing CVE-2019-2215 and deploying malware through EncroChat's update infrastructure. The report also identified French police cyber units C3N and STNCJ and described concerns about the integrity of server images provided in later prosecutions.
A later forensic re-analysis by Czech company Invasys recovered the implant from an infected EncroChat device and reverse-engineered it. Invasys concluded the malware used Frida hooks and Realm libraries to copy plaintext messages directly from phones rather than decrypting traffic in transit.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcecyberveille.ch
Open sourcecomputerweekly.com
Open sourceprojectzero.google
Open sourcegithub.com
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.