The hacker who humiliated spyware makers and was never caught
The hacker who humiliated spyware makers and was never caught
羞辱了间谍软件制造商却从未被捕的黑客
Over the last few decades, several mysterious hackers have captured the public’s imagination, but none quite like Phineas Fisher. A decade after their most famous hack, Phineas remains, by most accounts, the most prolific and public hacker never to have been caught. As part of our series on the biggest cybersecurity mysteries of all time, we’re delving into the enigma of Phineas, the hacktivist who hacked controversial spyware makers FinFisher and Hacking Team. 在过去的几十年里,几位神秘的黑客抓住了公众的想象力,但没有谁能像 Phineas Fisher 那样。在他们最著名的黑客攻击事件发生十年后,根据大多数人的说法,Phineas 仍然是史上最高产且最公开、却从未被抓获的黑客。作为我们“史上最大网络安全谜团”系列报道的一部分,我们将深入探讨 Phineas 这个谜团——这位黑客活动家曾入侵了备受争议的间谍软件制造商 FinFisher 和 Hacking Team。
The latter, an Italian startup, was among the first to turn government spyware into a viable global business, paving the way for spyware makers such as the Israeli NSO Group. Phineas’ hack against Hacking Team eventually led to the startup’s demise years later. Apart from Anonymous, an amorphous amalgam of hacktivists with a mixed track record of mostly stunt hacks designed to gather publicity rather than have real impact, Phineas is perhaps the most well-known hacktivist in history. Their story is made of impressive hacks and endless unanswered questions. 后者是一家意大利初创公司,它是首批将政府间谍软件转化为可行全球业务的公司之一,为以色列 NSO Group 等间谍软件制造商铺平了道路。Phineas 对 Hacking Team 的攻击最终导致了该初创公司多年后的倒闭。除了“匿名者”(Anonymous)——一个由黑客活动家组成的松散集合体,其过往记录褒贬不一,且大多是为了博取关注而非产生实际影响的噱头式攻击——Phineas 可能是历史上最著名的黑客活动家。他们的故事由令人印象深刻的黑客攻击和无数未解之谜组成。
Who is Phineas Fisher? Variously called an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has said they “use a lot of different names” for different hacking escapades. The hacks we know about were big enough to turn Phineas into a legend among hackers. “I would like to meet Phineas Fisher so that I could buy them a seven-course, three-Michelin-star dinner somewhere and listen to them explain how they turned Hacking Team inside out like a gym sock,” a well-known security researcher once wrote on Twitter. There’s even a song about them. Phineas Fisher 是谁?这位黑客被称为无政府主义者、网络罪犯、黑客活动家和治安维持者,他们曾表示在不同的黑客行动中“使用过许多不同的名字”。我们所知的那些黑客攻击规模之大,足以让 Phineas 在黑客圈中成为传奇。“我真想见见 Phineas Fisher,请他们吃顿七道菜的米其林三星晚餐,听他们解释是如何像翻袜子一样把 Hacking Team 彻底翻了个底朝天,”一位知名安全研究员曾在 Twitter 上这样写道。甚至还有一首歌是关于他们的。
Phineas first emerged in August 2014, when they announced they had hacked Gamma Group, the makers of the FinFisher spyware — which is where the nickname comes from. They publicized the hack via a Twitter account cheekily called @GammaGroupPR, leaking stolen data including mobile spyware, product manuals, and a price list. The damage was limited, and FinFisher carried on. Phineas published a post-mortem that doubled as a leftist manifesto, then vanished. Phineas 最初出现在 2014 年 8 月,当时他们宣布入侵了 FinFisher 间谍软件的制造商 Gamma Group——这也是其绰号的由来。他们通过一个名为 @GammaGroupPR 的调侃式 Twitter 账号公布了这次攻击,泄露了包括移动间谍软件、产品手册和价格表在内的被盗数据。造成的损害有限,FinFisher 也得以继续运营。Phineas 发布了一份事后分析报告,这份报告同时也是一份左翼宣言,随后便销声匿迹了。
A year later, they came back with a bang, hacking Hacking Team, another spyware maker. They took practically everything: more than 400 gigabytes including source code, tens of thousands of internal emails, confidential contracts, and customer lists. The leak allowed journalists to reveal scandals in Ecuador, Mexico, and Panama. Years later, Hacking Team’s CEO David Vincenzetti was forced to sell his company for one euro. For some former employees, Phineas’ hack was the beginning of the end. 一年后,他们强势回归,入侵了另一家间谍软件制造商 Hacking Team。他们几乎拿走了所有东西:超过 400 GB 的数据,包括源代码、数以万计的内部邮件、机密合同和客户名单。这次泄密让记者们得以揭露厄瓜多尔、墨西哥和巴拿马的丑闻。多年后,Hacking Team 的首席执行官 David Vincenzetti 被迫以一欧元的价格出售了他的公司。对于一些前员工来说,Phineas 的攻击是这一切终结的开始。
Phineas went on to hack the union of the Mossos d’Esquadra, which is the police force of Catalonia, publishing a post-mortem and a 39-minute tutorial video — consistent with their stated anti-police ideals. Their next victim was the ruling party of Turkey’s authoritarian president Recep Tayyip Erdoğan, a hack motivated by solidarity with Rojava, a leftist autonomous region in northern and eastern Syria that Turkey was fighting against. 此后,Phineas 入侵了加泰罗尼亚警察部队 Mossos d’Esquadra 的工会,发布了一份事后分析报告和一段 39 分钟的教程视频——这与他们所宣称的反警察理念相一致。他们的下一个目标是土耳其威权总统雷杰普·塔伊普·埃尔多安的执政党,这次攻击的动机是声援罗贾瓦(Rojava),这是叙利亚北部和东部的一个左翼自治区,当时正遭到土耳其的打击。
Phineas’ last known victim was Cayman National Bank’s branch in the Isle of Man, a self-governing island between England and Ireland. The hack hinted at a different side of Phineas. “I look for illegal ways to make money in order to free my time so I can do something useful with it. Once I had that figured out, I started scaling it up and making more money than I need and giving the extra away,” Phineas said in an interview with activist Freddy Martinez. (Phineas donated at least $10,000 in Bitcoin to Rojava.) Phineas 最后已知的受害者是开曼国民银行(Cayman National Bank)位于马恩岛(英格兰和爱尔兰之间的一个自治岛屿)的分行。这次攻击暗示了 Phineas 的另一面。“我寻找非法赚钱的途径是为了腾出时间,好去做些有意义的事。一旦我找到了方法,我就开始扩大规模,赚取超过我所需的钱,并将多余的部分捐出去,”Phineas 在接受活动家 Freddy Martinez 采访时说。(Phineas 向罗贾瓦捐赠了至少 1 万美元的比特币。)
Phineas kept the hack — which happened in 2016 — quiet for three years later before announcing the “Hacktivist Bug Bounty Program,” an initiative to reward hacktivists who expose companies’ illegal and unethical activities. When Cayman National Bank confirmed the hack, it claimed it “was amongst a number of banks targeted.” Phineas confirmed they had been hacking several banks for years. That was their last public appearance. Their Twitter and Reddit accounts have long since been deleted, leaving no online trail. Phineas 将这次发生在 2016 年的攻击隐瞒了三年,之后才宣布了“黑客活动家漏洞赏金计划”(Hacktivist Bug Bounty Program),这是一项旨在奖励那些揭露公司非法和不道德活动的黑客活动家的倡议。当开曼国民银行确认此次攻击时,声称自己“是多个被攻击银行中的一个”。Phineas 则证实他们多年来一直在攻击多家银行。那是他们最后一次公开露面。他们的 Twitter 和 Reddit 账号早已被删除,没有留下任何在线痕迹。
FinFisher never contacted law enforcement, according to a former company employee. The Italian authorities’ investigation into the Hacking Team hack ended without finding any evidence pointing to Phineas’ real identity. What I can say, from my own reporting, is that Phineas is alive and well — they have been in contact with me within the last couple of years. 据一位前公司员工称,FinFisher 从未联系过执法部门。意大利当局对 Hacking Team 入侵事件的调查最终无果,没有发现任何指向 Phineas 真实身份的证据。根据我自己的报道,我可以肯定的是,Phineas 还活着,而且过得很好——在过去几年里,他们一直与我保持着联系。
So who is Phineas Fisher? Taking their claims at face value, they’re a hacktivist with anarchist ideals, but also a cybercriminal. Could they instead be a fabricated persona controlled by a spy agency — Russia, say, which has a history of inventing hacktivists to muddy the waters after its own hacks? Phineas has denied being a Russian spy, and it’s unclear why Moscow would go after all of Phineas’ chosen targets. 那么 Phineas Fisher 到底是谁?如果从表面上看,他们是一位怀揣无政府主义理想的黑客活动家,但同时也是一名网络罪犯。他们会不会是由某个间谍机构控制的虚构人物?比如俄罗斯,该国曾有在发动黑客攻击后编造黑客活动家来搅浑水的历史?Phineas 否认自己是俄罗斯间谍,而且目前尚不清楚莫斯科为何要针对 Phineas 选择的所有目标。
Their origins are equally murky. Phineas has name-dropped Spanish-speaking anarchists, wrote the Hacking Team post-mortem in Spanish, and followed numerous Latin American leftist accounts on Twitter. They told me their first language is neither English nor Spanish, though they have acknowledged living in a Spanish-speaking country. It’s all worth taking with a grain of salt. “Everything I say that contains clues about my identity is half trolling,” Phineas once told me. “I’m in the habit of saying misinformation.” 他们的出身同样模糊不清。Phineas 曾提及讲西班牙语的无政府主义者,用西班牙语撰写了 Hacking Team 的事后分析报告,并在 Twitter 上关注了许多拉丁美洲的左翼账号。他们告诉我,他们的母语既不是英语也不是西班牙语,尽管他们承认自己居住在一个讲西班牙语的国家。这一切都值得持保留态度。“我所说的任何包含我身份线索的话,有一半是在钓鱼(trolling),”Phineas 曾告诉我。“我习惯于散布虚假信息。”
It’s also possible that the Phineas persona was passed around between 2014 and 2019 and used by different individuals. But there is no evidence of that, and after 10 years of conversations, my gut says Phineas truly is the hacktivist they claim to be. 也有可能 Phineas 这个角色在 2014 年到 2019 年间被多人轮流使用。但目前没有证据支持这一点,在经过 10 年的交流后,我的直觉告诉我,Phineas 的确就是他们所声称的那位黑客活动家。