MOBILE FORENSICS

Government-sponsored malware (e.g. Pegasus) – the scope and limitations of investigations

The suspicion that a so-called ‘state Trojan’ – such as Pegasus – has been used places particularly high demands on an IT forensic investigation. Such malicious programmes are designed to leave as few traces as possible. An investigation must therefore be strictly fact-based and clearly distinguish technical findings from conjecture.

Forensic extractions
System and diagnostic logs
Known Indicators of Compromise (IoCs)
Network and communication artefacts
Databases and system files
Further technical anomalies in the overall context

TECHNICAL BACKGROUND

Technical Fundamentals

Depending on the device, operating system and available data, the following, amongst other things, can be analysed:

  • Forensic extractions
  • System and diagnostic logs
  • Known Indicators of Compromise (IoCs)
  • Network and communication artefacts
  • Databases and system files
  • Further technical anomalies in the overall context

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
The investigation is carried out using appropriate forensic data backups and a structured analysis of relevant artefacts. Known IoCs can – where appropriate – be checked using suitable tools. In addition, a manual plausibility check is carried out on all relevant findings. The absence of evidence is not taken as proof that a device has definitely not been compromised; similarly, a single indication is not regarded as proof of infection without further investigation.
2
LanCologne produces private expert reports for private individuals, companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, anonymised extracts from our client references can be provided.

TYPICAL QUESTIONS

When is this analysis required?

  • Is there any technical evidence to suggest that the system has been compromised?
  • Can any known IoCs be detected?
  • Are there any unusual system artefacts?
  • How significant are the existing traces?
  • What are the limitations of the investigation?

LIMITATIONS & CONCLUSION

What you should know

Sophisticated malware can deliberately avoid leaving traces or leave only limited evidence following a compromise. Operating system limitations, deleted data and previously unknown attack techniques can limit the conclusiveness of an investigation. These limitations are documented transparently.

The investigation into a suspected state Trojan requires an objective and technically verifiable analysis. The aim is to carry out a robust assessment of the available digital evidence – not to confirm preconceived assumptions.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Do you suspect that your smartphone has been compromised by sophisticated malware? LanCologne can assist you with an objective IT forensic investigation and a transparent technical assessment.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

Can Pegasus always be detected?
No. Whether it can be verified depends on the artefacts available and the specific case.
Does a negative result rule out an infection?
No. The absence of evidence does not necessarily prove that no breach has taken place.
Are known IoCs checked?
Yes, provided they are suitable for the case in question.
Can an expert report be drawn up?
Yes, provided that this is requested.
Are iPhones and Android devices being examined?
Yes, provided that this is technically feasible and forms part of the contract.