The drug cartels in Mexico are constantly in competition for the business of being able to ship huge amounts of drugs across that border. The advantage of using low frequency you don't need as many cell towers, you cannot use SMS on their network, but you can access data. Hey everyone, Yaniv Ofman here and today I am joined by Master Hacker Occupy the Web to explore a fascinating case where a Mexican cartel built its own cellular network.
And this wasn't just a few walkie talkies or some mobile phone. This was a full scale, independent communication system with relay towers, repeater and even a military grade encryption, allowing them to operate completely off the grid. So we will break down how they built it, why it was so effective and what this means for cyber security and law enforcement and no better one than Master Occupy the Web to speak about it.
So looking forward to it. Welcome Occupy the Web. Thank you Yaniv.
It's always an honor to be asked to appear on your show. So thank you very much. So let's talk about this.
This is kind of an interesting story. It's one that I think that a lot of people aren't familiar with and obviously there's a lot of money that's involved. And so as a result, have a organization, the cartels, the drug cartels in Mexico.
So most of the drugs that make their way into the United States come across the southern border of the U. S. from Mexico.
It's not necessarily anything that we want to say, hey, Mexico was wrong. It's just that there's just a lot of money involved and they have a very long border. It's like a 2000 mile border, which is a huge border with the United States.
And this has been going on for a long, long time. And as a result, the cartels are going very, very rich. We're talking about hundreds of billions of dollars.
We're talking about a lot of money and also that, you know, the cartels, their business, this is their business. You know, I'm going to stick strictly to the fact that this is a business we can talk another time about legalities or drugs and ethical moral issues. But this is a business for them.
It's a very big business and it is illegal. Right. So as a result, they need to keep their information not only safe from government spies, but also from their competitors.
So there's multiple cartels. And as a result, they're constantly in competition for the business, the business of being able to ship huge amounts of drugs across that border. And they have a lot of money and they've done lots of things to be able to get those drugs across.
But one of the things that they have done is they've built their own cellular network. Right. They built their own cellular network.
Why? Well, they wanted to avoid being surveilled, spied on by the government, most probably the Mexican government and the US government, as well as their competitors. And we know, for instance, most of you know that there is this flaw in the cellular networks that's called SS7.
Right. And this the SS7 flaw or vulnerability allows easily allows an organization with a lot of money to be able to be able to top that vulnerability and see the traffic that goes between cellular networks. Right.
So it's basically it's a it's an area between their network where they come together, where intelligence agency or even very good hackers can actually access and get inside and see the listen to and see the traffic there. And so we now we know that at the very moment we're talking that there has been this breach of the US telecom nine telecom systems in the United States have been breached by Chinese state sponsored hackers. And it's not that difficult to do if you have a state sponsor behind you.
Right. And so this is what they're trying to avoid. And it's one of the things that is often overlooked is that there's a lot of different ways to get into cell systems.
Right. You've done an excellent show on the Pegasus Pegasus is the the piece of malware to zero click malware that was developed by NSO is used by governments all over the world and used prominently by the Mexican government. In part to be able to hide the stuff to spy on the drug cartels and spy on their activities.
So I think Mexico was the very first government to buy the Pegasus. So the drug cartels have a lot of money and they feel very threatened. So what do you do?
You have built your own cell network. And that's exactly what they did. And they did some really interesting things in building it.
One of the things that they did is that, well, first of all, they used some of the older technologies. This is this is a system that is probably still running today, but certainly was running just as of a couple of years ago. Right.
And they used OpenBTS. Therefore, your viewers are familiar with this. OpenBTS is a cellular open source cellular network.
It's a base station, actually. It's a BTS is a base station. And so they use the OpenBTS, which was originally developed to be able to bring cell service to underserved areas.
Like you had a small village or a town that was outside of the cellular network. You could use OpenBTS to build your own 2G, 3G. So notice this is not 4G and 5G.
You can build your own using OpenBTS. And there's a lot of excellent tools that are available if you know how to use them and to build your own private mobile network. And that's exactly what the Mexican cartels did is that they use their money and their expertise to be able to build their own network so they could communicate throughout Mexico and maybe even into the U.
S. across the border without ever being intercepted or surveilled by government or intelligence agencies. I know this kind of first hand and a second hand.
It's called second hand because one of my students works for Homeland Security and his job is to surveil the Mexican drug cartels. And so he keeps me up and brings me the problems that they have and ask for my advice and how they might be able to break it. So this is kind of, you know, kind of it's not first hand, it's second hand, but something that's close to my heart.
Close to my heart and my brain. So the drug cartels started working on this as early as like 2007, so 16 years ago. And we probably know the name Las Zetas.
It's a bunch of former military folks who basically built their own drug cartel and they're pretty dangerous and powerful in Mexico. So they're the ones who started this, but it's not just them, it's other cartels have done similar things as well. And these networks are working at the relatively low frequencies that we've seen in 2G and 3G.
So 2G and 3G oftentimes, most of them, were operating about 700 megahertz to about 900 megahertz, 950. And that's where they were operating at. And so the advantage of using low frequency and the advantages of low frequencies, you don't need as many cell towers.
And that's a big plus for where they're trying to work in very remote areas. So if you're using 5G, for instance, 5G operates at a very high frequencies, at like 3 gigahertz to 15 gigahertz. We don't really see much in that area.
Most of the 5Gs in the 3 gigahertz area. But when you go up to that high frequency, the signal doesn't travel as far. So this is one of the problems with rolling out cellular networks, 5G cellular networks around the world, is you need a lot more cell towers because the frequencies are so much higher.
There's an inverse relationship between the frequency and the distance that will travel without being blocked by buildings and trees and mountains and what have you. So they built theirs on the old lower frequencies, 700, 850, 950 in that area. And then they use OpenBTS, which anybody can download.
It's available on GitHub. And they use the Edis USRP N210 SDR. So SDRs are one of the things that we're doing at HackersRise is we're exploring all the things that we can do with SDRs.
And this is one of the things that you can do with an SDR. You can build your own cellular network. You're not going to do it with a $35 SDR, but with a $2,000 SDR.
Then you have lots of possibilities. And OpenBTS is opening doors to remote villages and remote communities who need a cell service. That's why they developed it.
This is OpenBTS. This has been around for a while. It's a GSM GPRS radio access network node.
And so it has the newest UHD universal hardware drivers and supporting Ubuntu. So you can build this on Ubuntu and be able to have your own base station, cellular base station. There's some newer versions that have come out that actually will do 4G and 5G.
But this has been around. This is tried and true. It works great.
It's also built into Drgon OS. Most of you probably are familiar that there's this operating system called Drgon OS that's designed specifically for let's call it signals intelligence. That's what I prefer to call it.
Signals intelligence. So SDR, software divine radio, is simply a way of creating a radio out of your computer. It has a lot of excellent things you can do with it.
But it also allows you to do what the military and the intelligence community call signals intelligence. That means you're able to pick up signals and decode them, decrypt them, what have you. And a lot of them aren't even encrypted.
Like we did the satellite hack and we used Drgon OS for that. And we found out that a lot of the signals that are traversing the satellites are not encrypted. We were able to pick them up and read them.
And so on Drgon OS, we do have I'll show you. There's a series open BTS right here. All right.
This is one and there's gate is another. And then there's also Calypso BTS. So these are three different phone systems that you can build with a build software using Drgon OS and some hardware.
You have to have a computer. You have to have a high speed, high performance SDR. The ones that we use for classes, they'll work OK, but they're not going to be giving the kind of performance that you need.
So let's go back there and let's talk. Let's talk more about what the Mexican drug cartels. So they were able to use these kind of off the shelf.
They actually they wouldn't bought some hardware that's used by the cell companies as well. They didn't use just off the shelf equipment, but they started with the off the shelf equipment, the open BTS, the USRP, the NSUSRP. And they built this network.
One of the things that's most interesting about the ways that they approach it, right, is that to keep anybody else. You know, remember that cell signals are just traveling through the air. So the cell signals are traveling through the air like so many other signals are.
Why fly to this satellite signals? They're all going just through the air, which means that anybody can intercept them. And if anybody can intercept them, then there's a potential for being able to read them, to drop on them.
And so this is what the cartels were trying to avoid. So one of the things that they did that was probably most interesting building this network is they put in a set of encryption that was pretty sophisticated. So we know this from some captured equipment in 2022.
And what they did there is that they used. Well, they use, of course, Diffie -Hellman to be able to do a key exchange. Diffie-Hellman is asymmetric.
It's used oftentimes for key exchange and public key infrastructure and what have you. But one of the most interesting they did, though, is that they generated temporary encryption keys. Temporary encryption keys that were based upon the geographic location, time of day and atmospheric conditions.
So think about that. So without being at that location, physically being at that location, you would not likely have, say, the GPS coordinates, the time of the day and say the humidity and temperature. So they were using those inputs, local inputs that are relatively random, not truly random, but relatively random, to be able to create encryption keys that you couldn't duplicate.
It would be very difficult to duplicate. Therefore, protecting their communications from anybody else who's trying to snoop on them. So this was kind of a brilliant idea, I think.
So we don't usually see that type of thing being done by criminal organizations, which just kind of tells you how much sophistication they have. If you have enough money, of course, you can be pretty sophisticated. Do you think they got some inside help from the local telecoms company?
Or how did they maintain it? That's a good question, because what they did do is they kidnapped a fellow from the local telecom, and they used him to help build it. He was an engineer.
He goes by the name of Jose Gonzalez. That's not his real name, because we want to protect his identity. But Jose was a former Telcel engineer in Mexico, and they basically kidnapped him and made him build this network for it.
So there's an awful lot that we've learned over these years of how they built it, which makes it easier for somebody else who wants to do the same thing. So one of the things that we're beginning to see is companies and organizations who want to confidentiality, who are building their own private cell networks. So if an organization doesn't want their competitors to be able to eavesdrop on them, if they don't want foreign governments to eavesdrop on them and see what they're working on, what they're talking about, what their location is, they're building private cellular networks.
And what is happening now is that these private cellular networks are getting relatively inexpensive. We're not talking about millions of dollars. We're talking, in some cases, tens of thousands of dollars to be able to build your own private cellular network.
Now, these private cellular networks would not be able to connect to the larger cellular network, but that may not be an issue because you just want to communicate with your own people. In the case of the cartels, they didn't want to call home. What they wanted to do is they wanted to talk to all the people who were working for them.
And what we're seeing now is there's other organizations who have the same need of confidentiality, and they don't want to, for instance, have their information compromised by, say, the Chinese state -sponsored actors who are inside the U. S. telecom system or, for that matter, any telecom system, because it's not that difficult to be able to intercept an eavesdrop on cellular data by using, among other things, the SS7 vulnerability that connects all the cell networks together.
And so we now know that the Chinese are inside, and probably still are, the U. S. network, and they're probably in other networks as well around the world.
And this has kind of created a little bit of paranoia by a lot of organizations and companies that their data can be intercepted. So if you are, for instance, building a new drug or you're building a new chip, and you don't want the Chinese to be able to intercept your communication between your people, your scientists, your engineers, you might want to have a private cellular network that only your people can access. Therefore, it gives almost, you've always got to be careful about saying, because there's always a way to crack everything.
There's always a way to hack everything. Nothing is truly secure if given enough money, resources, and skill. So when you're talking about national security issues, you have very talented people with almost unlimited amounts of money.
They can break just about anything. But this is a next level of security in communication for organizations who maybe they still use the general cellular network for calling home, calling the kids, calling the wife, calling their friends. But when they're working on a project, say building a new chip for artificial intelligence, as an example, you don't want the Chinese to be able to pick up that communication.
Now, I'm not just picking on the Chinese. Let's say you don't want anybody to intercept that communication. And so this is a way to be able to keep those conversations and that data from being intercepted by anybody.
Now, one of the things that would be important here is to do something similar to what the cartels did. That's why I wanted to talk about this is because the cartels have done this and we can learn from what they did and the mistakes that they made. One of the things they did right is they used this unique form of encryption that was based upon this data that's only local.
So the temperature, humidity, the GPS coordinates would go into generating a pseudo-random key. So most encryption algorithms require some element of randomness. It's often referred to as a nonce or sometimes it's referred to as a pseudo-random key.
And so that, without that, without that element, then what happens is it becomes really easy for somebody with enough compute power to decrypt the information. So you need to have some source of randomness to put into the algorithm. And these guys came up with this idea of using the conditions.
It's probably somebody, it's probably not the cartels who came up with it, but somebody who they hired. But they came up with this idea of using as a source of randomness the GPS coordinates and the temperature, environmental conditions, the geographic location, time of day and atmospheric conditions, which would be really hard for if you're trying to crack that encryption. You would need to have that information.
And that information is going to be changing constantly. Temperature is changing constantly, atmospheric pressure is changing constantly. And so this is, I think, an ingenious way to be able to encrypt your data to make sure that it doesn't get broken by the intelligence agencies or some foreign actor, state-sponsored actor, if that's what you're concerned about.
Now most hackers don't have the kind of resources or the ability to crack that type of encryption, even AES-based encryption. But the intelligence agencies do. So that's what you're concerned about.
Or it might be that if you're, say, let's again use a chip manufacturer, say Arm. Arm is a chip manufacturer, chip designer in the UK, and they're gearing up to start generating chips for the AI market. They are selling some now, but NVIDIA is the big player here.
And if you're Arm and you want to make sure that your new chips don't get stolen, your intellectual property doesn't get stolen by a foreign actor, this might be a way for you to communicate confidentially and confidentially and not worry about your information being being dropped on, which would be the case if you're using the commercial cellular networks. So I want to speak about it in a second. I want to park it.
You mentioned before that the cartel did a mistake, probably that let their network to be exposed and then dismantled. So what was that? I don't know that it was a technical flaw.
I think it was a human flaw. I think what happened is that the government compromised a human that then was able to point them in the right direction. So Occupy the Web, I'm coming back into your statement about the privacy.
So if I'm a private person or I want to keep my data confidential, my voice records confidential, do I have solutions today in the private market of such private networks that can be used not necessarily definitely for illegal activities? Just confidential. Yeah.
Well, there are at least one or two companies out there who are currently offering that for companies and for organizations. And it's one of those markets that we at HackersArise are considering entering as well. And so we might have a product coming.
I'm just saying we might. We're working on it. Okay, a product coming out soon.
But there are other companies that are offering. For the individual who wants privacy, you can create your own base station, cellular base station, all very little. It doesn't cost that much.
Well, it depends on what you consider not much for $2,000 or $3,000. And for $2,000 or $3,000, then you can have, say, a 5G base station that will allow you to connect to the water cellular network only for data, not for phone calls or SMS. Because that is regulated by those SIM cards that only the network carriers have access to.
So you can have a SIM card in your base station. But because that SIM card is recognized by the broader network, you cannot make phone calls on their network. You cannot use SMS on their network, but you can access data.
Now, one of the things that may not be clear to most people is that SMS and, say, something like WhatsApp or Signal, WhatsApp and Signal are not text messages. They might seem like they're text messages, but all they are really is an IP-based communication protocol. SMS is a telecom-based protocol.
Only telecoms can provide SMS messages. WhatsApp is simply, it's an internet-based, it's an IP-based system, so that what I'm discussing here about building your own base station would allow you to be able to connect to the cellular network to send data, which would include things like WhatsApp and Signal, in which case then you know that your data is secure, because there's no identifying marks to your data. That's like when it comes, all your data that goes over the cellular network is identified by a number of identifiers that the cellular carriers use.
The SIM card has an IMSI and an IMEI. These are all identifying marks of the device that the message came from. That's not necessarily going to be the case if you have your own cell base station.
That's one of the things that's kind of the leading edge of what's going on in SDR and in cellular networks is building these cellular base stations that are off and separate from the cellular network. Because of recent technological developments, it's possible to do this relatively inexpensively with a little bit of skill, a little bit of knowledge. I think it's the leading edge.
That's one of the reasons why I wanted to talk about what the cartels did, because a lot of people think that I'm talking science fiction, and I'm not talking science fiction. I'm talking about something that's already been done before, but done by an organization with a lot of money. Well, now what they have done just a few years ago successfully is that it can be done by somebody with a few thousand dollars and being able to have confidential communication without being concerned about interception and eavesdropping.
Now I heard also they are continuing to innovate, so they have even shifted some of them, shifted some cartels, shifted to hijacking, extorting Wi-Fi networks, so focusing on local people, threatening them to access the network, and then they pay them some fee as well. It's easier, less sophisticated, of course. It's not confidential, but more for money generation.
And that kind of makes it emphasize my point, in that I think that the leading edge of cybersecurity is this radio hacking or signals intelligence, right? That's what the military in the U. S.
calls it. They call it signals intelligence. It's the ability to intercept other people's signals, and because these signals are just going through the air all around us, it's possible to intercept them, decode them, and maybe decrypt them.
It depends upon how secure the encryption is. So this is an underestimated area of cybersecurity. Here's all of these signals traveling around us, around the air, and SDR now makes all of us, gives all of us the capability to be signals intelligence officers or signals intelligence engineers.
So we can go and intercept these signals, and that's kind of a really important development, whether it be Wi-Fi, Bluetooth, or cellular, or satellite. These are exciting areas that cybersecurity is only beginning to enter. I agree.
I agree. I think this is a fascinating case. You know, I wrote to myself a few points.
One, definitely the cartels are more tech savvy than what we think. They don't use just burner phones. They build their own private cell networks, as you mentioned, using OpenBTS to stay off the government radar.
It also allowed them to communicate securely, coordinate probably their operation, avoid law enforcement, et cetera. At the end, it was dismantled a few times. I think the last time was even in 2021 or 2023.
And you know, at the end, what I'm learning, if a criminal cartel can build a private telecom network, what does it mean for nation-state hackers, right? Exactly. Or even organizations.
So the line between the cyber crime and the traditional crime is disappearing. And these malicious organizations always advance, innovate as well, not only the defenders. Right.
Exactly. And they've kind of led the way. Because they have so much at stake and because there's so much money, they've led the way and have broken trail for this type of private cellular network that I don't think most people are aware of, that this is a capability that the average IT guy can build.
Right. The average IT guy with some cybersecurity and some IT skills and some radio knowledge can build their own cellular network. Okay.
This was great. So everyone is watching. If you want to learn more about hacking cybersecurity, real practical use cases, I suggest you go over and I will put it in the description.
I will leave the link in the description on the screen for Hacker Arise, the school of Master Hacker Occupy the Web. You will find there many vast or many courses in regards to SDR, hacking, reconnaissance, exploitation, et cetera. And Master Hacker Occupy the Web, thank you very much again for another fascinating session.
And I welcome everyone that liked this video or have any comment or suggestion. Leave your comments in the description. What do you think about it?
Do you have different examples on other cartels or organized crimes that did it around the world? If you are still not a subscriber, please do. It will only take you a second and see you in the next video.