The Effects of Weaponized Malware on End-to-End Encryption & Exfiltrating data from Signal Messenger
Download resourcesAbout this session
Geoff Green, co-founder and CEO of Myntex, surveys the commercial spyware industry that sells 'weaponized malware' able to break into a phone with nothing more than its number. He defines zero-click, one-click, tactical, strategic-ISP and man-in-the-middle infection methods, then profiles the leading vendors: the Intellexa Alliance's Predator, NSO Group's Pegasus, RCS Lab's Hermit, Paragon's Graphite and Black Cube's Bluetooth exploit ARCLIS, citing cases from an exiled politician's iPhone to Harvey Weinstein's private investigators. He explains how spyware evades researchers with anti-analysis checks, persists across reboots, exfiltrates data slowly over unmetered Wi-Fi, and can self-destruct after weeks of silence. The technical core is a live Android demonstration: using a known privilege-escalation exploit in Android's trusted key store, he duplicates Signal's key pair to decrypt its local database and read messages in plaintext, showing that end-to-end encryption cannot protect data once the device itself is compromised. He closes with the spyware trade's economics, the Surveillance Watch mapping project, and practical defenses such as disabling iMessage and FaceTime, non-mainstream browsers, VPNs, and quarterly factory resets. A short Q&A follows on iOS versus Android exploitability.
Weaponized malware has emerged as a significant threat. Explore the tactics used by weaponized malware to infiltrate your phone, the advancements and capabilities of forensic surveillance tools, and extracting encrypted data from Signal Messenger. • The current mobile threat landscape • How forensic tools can bypass E2EE • Prominent spyware capabilities exposed • Malware attack lifecycle, from infection to data exfiltration • The evolution of encryption protocols • Exfiltrating Signal messages • A roadmap for holistic cybersecurity measures
Key takeaways
- Assume a phone number alone can be enough to trigger a zero-click infection; high-risk individuals should not treat 'never click links' as sufficient protection on its own.
- End-to-end encryption inside an app cannot survive full device compromise: once an attacker gains root or privilege escalation, they can duplicate key material and decrypt the local database directly.
- For high-risk users, disable iMessage and FaceTime, switch to non-mainstream browsers such as Firefox Focus, always run a VPN or Tor, and never click links received in messages.
- Factory-reset high-risk devices quarterly and after travel; few weaponized-malware implants survive a true factory reset, unlike a simple reboot.
- Check the Surveillance Watch project for documented ties between a vendor, government or organization and commercial spyware before trusting a 'secure' or 'private' product.
Speakers

Geoff is digital privacy and security advocate, with a dedicated focus on safeguarding the communications of leaders, executives, and high-risk clients. In 2010 he co-founded Myntex, a company specializing in mobile security and protecting against… Read moreRead less
Geoff is digital privacy and security advocate, with a dedicated focus on safeguarding the communications of leaders, executives, and high-risk clients. In 2010 he co-founded Myntex, a company specializing in mobile security and protecting against the latest in digital espionage. His work has been pivotal in pushing the boundaries of secure communication systems, and his company has consistently set new industry standards, driven by his deep commitment to innovation and integrity. He is passionate about educating others, particularly on the often-misunderstood realm of malware and spyware that targets mobile phones. While encryption plays a critical role in securing communications, Geoff emphasizes that it’s not a catch-all solution, an infected device can still compromise a users privacy by bypassing encryption altogether.
