Martin's Blog

1. HackingTeam, RCS, and Its Human Consequences

Before this book brings an old surveillance application back to life, it needs to say what that application was for.

HackingTeam was founded in Milan in 2003 and sold intrusion and surveillance software to government and law-enforcement customers. Its flagship platform, the Remote Control System, appeared under the names Da Vinci and later Galileo. The product joined covert collection on computers and phones to the ordinary machinery of an enterprise investigation: user accounts, work groups, targets, evidence databases, dashboards, alerts, audit records, backups, and a desktop analyst console.

That description can make the system sound administratively dull. It should not make its consequences sound abstract. Reporting and research before and after the 2015 leak connected HackingTeam’s products, customers, negotiations, or infrastructure to governments with documented records of political repression and surveillance of journalists, dissidents, and civil society. Citizen Lab and Kaspersky analyzed RCS samples and infrastructure before the company’s own archive became public. The leaked correspondence then exposed a much wider view of the company’s customer relationships and the gap between its public claims and the uses critics had warned about.

The archive is valuable precisely because it connects those consequences to the product that enabled them. It does not contain only an implant or a list of vulnerabilities. It contains the workflow around collection: how an operator defines a target, creates an agent configuration, receives typed evidence, correlates identities, requests files, searches communications, creates alerts, and shares an investigation through groups. The distance between a successful intrusion and sustained surveillance is the subject of this book.

What the historical evidence can prove

Commercial-spyware histories are unusually vulnerable to category errors. A server located in a country is called a customer. A customer is called an operator. A sample sent to one journalist becomes proof that an entire agency ran every available RCS feature. A proposal or demonstration becomes a sale. Once those claims are repeated, their qualifications tend to disappear.

I use a stricter ladder:

EvidenceSupported conclusionUnsupported leap
Code or manualRCS implemented or advertised a capabilityEvery customer received or used it
Malware analysisA sample is technically consistent with RCSThe identity of its operator
Named targeting recordA person or organization received an RCS-linked attemptSuccessful infection or collection, unless separately shown
Proxy and endpoint analysisInfrastructure is consistent with an operator locationWho authorized a particular target
Contract, invoice, or admissionA commercial relationship existedUse against a named person
Meeting, proposal, or trialA buyer evaluated or discussed RCSPurchase or deployment

The distinctions are not legal evasions. They keep attention on what happened to people without assigning conduct to institutions on inadequate evidence. Citizen Lab’s 2014 infrastructure study, for example, identified endpoints it believed represented 21 current or former government users. The researchers presented that as a technical inference from proxy chains, scanning, and samples—not as a leaked customer register and not as proof of targeting by every government named (Citizen Lab).

The 2015 archive later added commercial evidence, but it did not erase these categories. An invoice can clarify a vendor relationship while saying nothing about which investigations were lawful, which people were selected, or whether an agency ever achieved a working infection. Conversely, a forensically documented targeting can establish harm and intent even when the procurement record remains unavailable.

Before the leak: the people who made RCS visible

Public understanding of HackingTeam did not begin with its own breach. It began when journalists, activists, and researchers treated suspicious files as evidence rather than deleting them and moving on.

On 13 July 2012, the Moroccan citizen-media project Mamfakinch received what looked like a confidential news lead. The site had recently received international recognition and frequently published criticism of the Moroccan government. The lure exploited exactly what a newsroom is supposed to do: receive information from unfamiliar sources and investigate it. Citizen Lab’s analysis linked the resulting surveillance payload to HackingTeam’s RCS (Backdoors are Forever).

The event is often compressed into “Morocco used HackingTeam.” The public technical record supports a more precise statement: Mamfakinch was targeted from Moroccan address space with a malicious document whose final payload was identified as RCS. That is already serious. Naming a specific directing agency requires additional evidence.

Days later, Emirati human-rights defender Ahmed Mansoor received another malicious document. Citizen Lab reported that his laptop was infected with HackingTeam spyware delivered through an old Office vulnerability. Mansoor was not an abstract “target.” He was a prominent blogger and one of the UAE Five, activists imprisoned in 2011 after supporting political reform. Subsequent research records that he was targeted repeatedly by several commercial spyware families over multiple years (Citizen Lab).

Those two 2012 cases established a pattern that a product brochure could not show. A tool marketed for government investigations could be applied to the ordinary work of journalism and dissent. The decisive vulnerability was not only in Office or a browser. It was also social: a newsroom’s openness to a source, or an activist’s need to understand information about detention and abuse.

ESAT and surveillance across borders

The Ethiopian Satellite Television Service cases make the consequences even clearer. ESAT was an independent diaspora broadcaster whose reporting was frequently critical of Ethiopia’s government. Its journalists worked in the United States and Europe, partly because independent reporting inside Ethiopia was conducted under intense pressure.

On 20 December 2013, an attacker made three attempts in two hours against ESAT employees. The files were presented as journalistic material. Citizen Lab linked them to RCS through a combination of malware signatures, server behavior, and certificates associated with HackingTeam. The report described the attacker as governmental and estimated that the same actor had used RCS since at least May 2012, while retaining uncertainty about the precise agency (Citizen Lab).

The targeting continued after publication. In November and December 2014, ESAT journalists in the United States received updated RCS-linked attempts. Citizen Lab linked the attacker to Ethiopia and said it might have been the Information Network Security Agency. Its analysis also found that the relevant infrastructure and samples appeared to receive updates after the first report and after HackingTeam had been contacted about the case. The researchers therefore questioned the effectiveness of the company’s stated human-rights customer policy (Hacking Team Reloaded).

That conclusion needs the same care as the attribution. Citizen Lab did not claim to observe HackingTeam personnel selecting ESAT journalists. It observed what appeared to be newer product versions and updated infrastructure in the hands of the same governmental attacker. Because the vendor publicly said its technology required continuing support and could become useless after support was withdrawn, continued updates were relevant evidence about the practical strength of its safeguards.

The human context is not incidental. The Committee to Protect Journalists reported that Ethiopia imprisoned 17 journalists in 2014 and that more than 30 fled the country that year. ESAT employed journalists who had already left in the face of harassment, torture, or criminal charges. Spyware allowed political surveillance to follow them across a border (CPJ).

Transnational targeting changes the threat model for exile. Physical distance may prevent a local search of a newsroom, but it does not protect contact lists, sources, drafts, calls, passwords, or the identities of people still in the country. Compromising one journalist can map an entire reporting network. The risk radiates beyond the person who receives the lure.

Researchers map the product

Citizen Lab’s work was complemented by independent malware and infrastructure research. Its February 2014 mapping report described proxy chains designed to separate infected devices from apparent government endpoints. Instead of treating the visible server as the operator, the researchers correlated network behavior, latency, addressing patterns, and samples to reason about the chain. The result challenged the product’s marketing claim that its collection infrastructure was untraceable while also demonstrating why responsible attribution required more than an IP lookup.

Kaspersky’s Global Research and Analysis Team independently published mobile RCS findings in June 2014. It described modules for iOS, Android, BlackBerry, and Windows Mobile and a fingerprint for locating command servers. That work showed RCS extending beyond desktop documents and browsers into the devices that accompany a person throughout the day (Kaspersky).

These reports predate the source leak and matter for that reason. Their core claims were not reverse-engineered from HackingTeam’s email or customer spreadsheets. They emerged from samples, infrastructure, certificates, and interactions with intended targets. The 2015 archive could corroborate, complicate, or contradict them, but it did not create the original evidence.

A concise chronology

Timeline of major public RCS milestones from HackingTeam's founding through the Memento Labs acquisition
REPORTING · OFFICIAL RECORDSelected milestones used in this chapter. The sequence distinguishes documented targeting, the 2015 disclosure, and later corporate change; it is not a complete operational history.
DateEventEvidentiary status
2003HackingTeam founded in MilanPublic company history
July 2012Mamfakinch and Ahmed Mansoor targeted with RCS-linked materialNamed-target technical research
December 2013First documented ESAT attemptsNamed-target and infrastructure research
December 2013Wassenaar states agree new intrusion-software controlsMultilateral regulatory record
February-June 2014Citizen Lab maps RCS; Kaspersky publishes mobile findingsIndependent technical research
November-December 2014Updated RCS-linked attempts against US-based ESAT journalistsNamed-target technical research with qualified attribution
3 April 2015Italy grants HackingTeam a global individual export authorizationOfficial Italian parliamentary record
5-6 July 2015Roughly 400 GB of company data is disclosedBreach reporting and company acknowledgement
31 March 2016Italy revokes the global authorization; non-EU exports require specific licencesOfficial Italian parliamentary record
April 2019InTheCyber acquires a majority stake and creates Memento LabsContemporary acquisition reporting

The 2015 breach

In July 2015, an attacker published roughly 400 GB of HackingTeam material: email, contracts, invoices, source repositories, binaries, manuals, internal tools, and customer information. The publication destroyed the company’s ability to keep its capabilities and business relationships separate from public scrutiny. It also exposed exploit material, including a Flash flaw that became CVE-2015-5119 and was patched shortly after the leak.

The pseudonymous hacktivist usually styled Phineas Fisher—and also rendered Phineas Phisher—claimed responsibility. Contemporary reporting connected the claim to an account previously used around the 2014 breach of Gamma International, the company behind FinFisher (Vice, July 2015). In April 2016 the same persona published a detailed first-person account of entering HackingTeam’s network, moving through its internal systems, and extracting the material later released publicly (English translation of the Hack Back! account). That document is unusually detailed historical evidence, but it remains the claimant’s narrative rather than an independently authenticated forensic report. This book therefore records the claim without presenting the unknown person or group behind the pseudonym as conclusively identified.

HackingTeam’s early public statements acknowledged that meaningful source had escaped and warned that others could use it. That concern proved justified for at least the disclosed exploit material. Adobe patched CVE-2015-5119 on 8 July, and security researchers soon documented unrelated actors incorporating it into campaigns. Chapter 11 examines that episode in detail. The point here is broader: a spyware-vendor breach can harm people who were never its customers or original targets by turning restricted research into public attack capacity.

The dump also created a privacy problem of its own. It contained employee and customer communications, personal data, credentials, and operational details. Some of that material was plainly newsworthy and essential to accountability. Its presence in a public archive did not make every address, conversation, or identity ethically necessary to republish. This book relies on the minimum material needed to establish architecture, history, and defensive findings. It does not reproduce private correspondence for color.

Customers are not targets

The leaked business records widened the known set of relationships and showed contact with institutions in democratic and authoritarian states. They also made it easy to produce impressive country lists that mixed unlike things. Some entries represented active licences and support. Others represented resellers, prospects, trials, meetings, or negotiations. A government could buy the platform without every agency receiving it; an agency could possess it without every operation being unlawful.

The reverse is equally important. “Law-enforcement customer” is not a finding that use was legitimate. Legality depends on jurisdiction, authorization, necessity, proportionality, target, and safeguards. A contract clause cannot answer those questions, especially when the person selected for surveillance is a journalist or human-rights defender working outside the purchasing state’s territory.

The book consequently avoids a single undifferentiated customer list. It uses commercial records when a relationship is relevant, technical reports when they establish targeting, and official statements where a government has confirmed procurement or regulatory action. When the evidence shows only a demo or proposal, that is what the text calls it.

This discipline protects both directions of accountability. It avoids accusing a prospect of deployment without evidence, and it prevents a documented attack from being diluted into an abstract discussion of sales. The ESAT evidence matters because journalists were repeatedly selected, not merely because Ethiopia appeared in a spreadsheet.

Export control arrives late

The controversy around HackingTeam unfolded while states were deciding how to regulate intrusion technology. In December 2013, participants in the Wassenaar Arrangement agreed controls related to systems for generating, commanding, or delivering “intrusion software.” The European Union incorporated corresponding language through Delegated Regulation 1382/2014. Its definition covered software designed to avoid monitoring or defeat protective measures in order to extract or modify data or alter execution, while expressly excluding such things as debuggers and reverse-engineering tools (EUR-Lex).

That structure matters to this project. A control aimed at commercial command and delivery systems is not a declaration that all vulnerability research, debugging, or defensive analysis should be prohibited. Overbroad US implementation proposals later drew substantial criticism because they risked capturing legitimate security research and incident response. Effective oversight has to distinguish those activities while still controlling the sale of systems deliberately built for covert compromise.

Italy’s handling of HackingTeam demonstrates both the existence and the limits of licensing. Privacy International records that the Ministry of Economic Development first imposed a catch-all licensing obligation in 2014, then granted a global individual authorization in 2015. An official parliamentary response says the authorization was issued on 3 April 2015 for a series of countries including Egypt. Because it was global rather than transaction- specific, the authority did not conduct advance examination of each end user (Camera dei Deputati).

On 31 March 2016, the ministry revoked that global authorization in response to changed political conditions. HackingTeam could thereafter export dual-use products outside the EU only through specific authorizations reviewed for an individual order or contract. This was a significant tightening, but it was not the blanket worldwide ban sometimes described in summaries. A Lazio administrative court later rejected the company’s request to suspend the revocation, according to Privacy International’s submission to the UN Human Rights Committee (Privacy International).

Licensing is only one control. It acts at the moment of transfer and depends on truthful end-user information, governmental capacity, political will, and follow-up when misuse is reported. It does not replace domestic surveillance law, judicial authorization, vendor due diligence, technical audit, or remedy for a person already targeted. Nor can it claw back source after a breach.

The human cost is larger than a stolen file

RCS documentation organizes collection into evidence types: mail, chats, contacts, locations, screenshots, audio, files, passwords, and many others. The backend organizes those records beneath operations, targets, and agents. For an analyst this is a useful schema. For the person being watched it is an intimate reconstruction of work, relationships, movement, and private life.

The harm is therefore relational. A journalist’s address book exposes sources who never touched the malicious file. A defender’s messages expose clients and colleagues. Microphone access reaches people physically nearby. Credentials can open services and archives outside the infected device. Historical location can reveal meetings, medical visits, worship, or political activity. One successful compromise can put additional people at risk of surveillance.

Surveillance can also change behavior without producing a prosecution or a public leak. People who believe a government can read source communications may stop reporting, organizing, or seeking help. Sources may avoid journalists whose devices they do not trust. Exiled critics may discover that moving abroad changed the physical risk but not the state’s visibility into their network.

In 2019 the UN Special Rapporteur on freedom of opinion and expression placed targeted surveillance in this wider frame. The report connected surveillance of journalists, activists, opposition figures, and critics with detention, torture, and possible extrajudicial killing, and called for a moratorium on private surveillance-tool transfers until rigorous safeguards existed (A/HRC/41/35). That report concerns an industry, not only HackingTeam, but the earlier RCS cases show why the industry-level framework became necessary.

HackingTeam publicly described a customer policy that required lawful use and allowed support to be suspended. The ESAT chronology tests that assurance against observable outcomes: public notice of journalist targeting was followed by apparent use of updated RCS versions by the same attacker. The archive and source cannot reveal every internal due-diligence decision, but a policy whose operation is confidential offers affected people and researchers little way to verify whether it works.

The standard should not be that a vendor can name a legitimate product use. The question is whether it identifies foreseeable rights risks before sale, limits technical capability and support, investigates credible abuse, acts quickly, preserves evidence, and provides transparency and remedy. A system designed for secrecy makes each of those duties harder, not less necessary.

Corporate afterlife

The breach did not end the organization immediately. HackingTeam announced replacement technology and continued operating. In April 2019, InTheCyber acquired a majority stake and combined HackingTeam’s activities into a new company, Memento Labs. Its president described an 80 percent acquisition and a complete renewal of the brand and product effort (Formiche).

That is relevant corporate history, not proof that a later Memento product is the same system as the leaked RCS code. The source reconstructed in this book is frozen around 2014-era component snapshots. Rebranding, personnel changes, and rewritten products do not move those snapshots forward in time. The book uses “HackingTeam” for the historical company and “RCS” for the examined platform rather than treating every successor activity as one continuous technical object.

Corporate survival is not the moral center of the story. The enduring record belongs to the people who preserved suspicious messages, permitted forensic analysis, and made covert targeting visible. Without them, the product history would be told almost entirely through vendor claims and leaked sales data.

Why reconstruct it

The archive has already been examined extensively from the endpoint and affected-person side. That work produced malware analyses, infrastructure mappings, and mobile and desktop indicators. The operator side received less attention as a running system, partly because its dependencies aged badly: an obsolete Ruby stack, a MongoDB topology from another era, and an Adobe AIR console whose Linux runtime disappeared long ago.

Reconstructing that side answers different defensive questions. It shows what an operator saw, how the backend represented people selected for surveillance and the material collected about them, which services and database structures identify an installation, how collection fed alerting, and which security assumptions protected the accumulated data. It also makes failures visible: version mismatches, broken endpoints, dangerous defaults, brittle session behavior, and the possibility that a platform built to compromise others could itself expose its operators and victims.

The justification is not nostalgia and it is not the spectacle of reviving spyware. The justification is that defenders rarely receive this complete a record of a commercial surveillance product. A working backend turns static claims into testable ones, provided the test is narrow and the limits remain visible.

The boundary

This project draws that limit at the operator infrastructure.

No implant (core-*) or exploit (vector-*) code is built, run, repaired, or improved. Implant trees are reviewed statically: module registration is traced to concrete implementations and evidence writers, with conditional, disabled, referenced-only, and unresolved paths kept separate. That audit establishes source capabilities, not deployment, compatibility, collection success, or use against a person. No installer or delivery chain is exercised. No historical or current RCS system is contacted. The active environment contains the database backend, its evidence worker, a period-appropriate MongoDB deployment, and a newly written console that speaks the original operator API. Targets, identities, locations, credentials, messages, and evidence are synthetic.

Exploit packages are still part of the historical record. The book inventories their metadata and repository history because the catalogue reveals platform priorities, acquisition practices, release cycles, and antivirus pressure. It does not provide build or deployment instructions. Collector, anonymizer, and network-injector behavior is analyzed from source and manuals and is labelled accordingly rather than presented as lab traffic.

The fact that the archive is public does not mean every private detail belongs in this book. It uses only what is needed to establish the history and the technical record, leaves out personal data, and writes about victims as people rather than entries in HackingTeam’s database.

Working ethically with leaked surveillance source

Those limits apply to the research process as well as the finished book. Ignoring the archive would leave defenders dependent on vendor descriptions and scattered samples. Handling it carelessly could expose private data, adopt the operator’s point of view, or make abuse easier. The project therefore separates what may be useful to examine from what deserves to be reproduced.

Data minimization begins in the lab. Demonstration operations, people, messages, locations, and credentials are invented. Tests create disposable users and uniquely named fixtures. Screenshots must not show historical target records. The original manuals can document a UI workflow; they do not justify loading leaked operational databases into that interface.

The same rule applies to secrets. A hardcoded key may be relevant to assessing the platform’s security, but publishing every recoverable credential adds little after the design weakness is established. Source references should normally identify the location and function of a secret rather than repeat its value. Where an exact value is a useful indicator, the book should explain the defensive purpose and the risks of distribution.

Language also carries the product’s assumptions. RCS calls a person a “target,” a configured implant an “agent,” and collected private material “evidence.” Those terms are necessary when describing schemas and interfaces, but they are not endorsements. “Evidence” in the database means material the system stored under an evidence type; it does not establish authenticity, admissibility, lawful acquisition, or guilt. “Operation” means an RCS container, not a judicial finding that surveillance was authorized.

Publication safety is not satisfied merely by withholding exploit source. The book avoids procedural detail that would make delivery easier, does not repair offensive components, and tests only backend behavior with synthetic data. Conversely, it preserves enough specificity for defenders to verify findings: commit hashes, source paths, collection shapes, protocol traits, and the limits of each lab observation.

These choices shape the technical work that follows. Chapter 7 asks where a person’s records travel and what deletion really means. Chapter 10 tests who can reach those records. Chapter 13 begins incident response with authority, preservation, restricted handling, and safeguarding. The goal throughout is to help defenders recognize and investigate RCS without making surveillance easier.

What follows

The next chapter treats RCS as a system rather than a malware family. After that, the book freezes the inconsistent source snapshots, reconstructs the old runtime and console, follows evidence through the backend, and examines the operator workflow. The final parts assess the platform’s own security, preserve the complete exploit catalogue as history, and turn the reconstruction into detection and incident-response guidance.

Independent human-rights and survivor-sensitive editorial review remains a publication gate.

Sources and evidence

↑ HackingTeam's RCS: Bringing a Commercial Spyware Platform Back to Life