CSIDB logo
Incident

SecureDrop

Incident posture

Attack window
Sep 2019
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-09-26 19:36

Linked entities

Victim
SecureDrop
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Guardian's SecureDrop whistleblower submission site was impersonated by a phishing page that harvested sources' unique codenames and promoted a malicious Android app advertised as a location‑hiding tool; the app contained extensive permissions enabling RAT‑like functions such as monitoring calls, texts, location, camera, storage and executing commands via a command‑and‑control server at 213.188.152.96. After the phishing site was disclosed, it was taken offline, though the potential compromise of harvested codenames and installed apps may have already allowed attackers to access sources' communications and device data.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The phishing campaign targeting The Guardian’s SecureDrop whistleblowing submission site was uncovered over a weekend when darknet and underground market researcher Sh1ttyKids identified a fraudulent web page that closely mimicked the legitimate Tor‑hosted SecureDrop service at the 33y6fjyhs3phzfjj.onion address. The counterfeit page was designed to harvest the unique codenames assigned to sources who had submitted information through SecureDrop, noting that knowledge of a codename allows anyone to view a source’s past communications with journalists. In addition to stealing codenames, the phishing site promoted an Android application advertised as a tool to “hide your location,” which users were encouraged to download from the page. Sh1ttyKids reported the discovery on Twitter, after which the phishing page was taken offline, though it remains unclear whether the removal was initiated by The Guardian’s security team or by the attackers themselves.

The Android app distributed via the phishing page was later obtained and decompiled by security researcher Robert Baptiste, revealing a broad set of permissions that enable remote‑access‑trojan‑style functionality. The app can monitor a victim’s activity, location, phone calls, text messages, contacts, call logs, clipboard, storage, camera, and Wi‑Fi state, as well as capture voice calls, take pictures, list installed apps, and upload, download, or delete files. It operates by connecting to a command‑and‑control server at the IP address 213.188.152.96 to retrieve instructions for executing malicious commands such as creating system alerts, blocking automatic screen locking, placing phone calls, and reading or sending SMS messages. Baptiste noted that this IP address has a history of association with various malware campaigns. The article states that, even though the phishing page is now down, the harm may have already been done because sources who entered their codenames or installed the app could have had their communications and device data compromised.

Following the tweet by Sh1ttyKids, The Guardian’s security team was notified of the phishing incident and the associated malicious app. The article does not specify any further technical containment steps taken by the organization, nor does it detail whether any affected sources were identified or contacted. The uncertainty surrounding who took the phishing page offline leaves the exact response actions ambiguous, but the notification to The Guardian’s security team confirms that the organization was made aware of the threat. The narrative concludes with the acknowledgment that the potential impact on whistleblower anonymity and device security remains uncertain pending any additional forensic analysis that may have been conducted after the takedown.

Sources

Sources available to members: 1 source.

CSIDB