Hacking collective Ghost Security Group says ISIS created its own encrypted messaging app
this illustrates the futility of communication surveillance Rob Jackson / Phandroid : ISIS creating own Android App to coordinate terror attacks Tweets: Craig Mod / @craigmod : A gift from ISIS to Americans — their own messaging app. Maybe now we can quell our idiotic anti-encryption babble. http://www.defenseone.com/... Kenn White / @kennwhite : According to reports, includes “rudimentary” encryption features. Unsigned Android apk is floating around the web. http://twitter.com/... Pavel Durov / @durov : As I predicted, ISIS launched its own messaging app. Lobbying backdoors in mainstream apps makes little sense now. https://twitter.com/...
Context & Ripple Effects
This report lands mid-arc in ISIS' operational-security migration. The group had already been shedding trackable consumer products after a drone strike killed a British ISIS hacker, and its OPSEC manual codified the shift toward Tor, Tails, and hardened phones. Building its own Android messaging app is the logical endpoint: if every mainstream channel is assumed compromised, own the channel.
The reaction quotes frame why it matters beyond one app: Pavel Durov reads it as vindication that lobbying backdoors into mainstream apps just pushes determined users onto self-built tools, while Kenn White notes the shipped APK carries only rudimentary encryption — meaning the group traded vetted cryptography for control.
First-order effects
- ISIS supporters now face a trust problem the mainstream apps never had: an unsigned Android APK circulating outside any app store, with rudimentary encryption per Kenn White's read, where installing the wrong copy exposes them directly.
- Surveillance efforts aimed at mainstream platforms lose their target at the moment of adoption — once coordination moves to a proprietary app, the intercept points that made WhatsApp or Twitter useful to monitors stop applying.
Second-order effects
- Adversaries adapt through the distribution layer itself: within months someone was distributing fake versions of ISIS Android apps, seeding infiltration fears among the group's own supporters — the app's independence from app stores becomes its biggest attack surface.
- Mainstream platform operators gain an argument against government backdoor demands: Durov's framing suggests compelled weaknesses in Telegram-class apps accelerate exactly the off-platform migration that makes monitoring harder, not easier.
Third-order effects
- The pattern doesn't end with self-built tools — by 2019 ISIS had moved back to free public chat apps like RocketChat, Viber, and Discord, suggesting bespoke apps proved too brittle to sustain, and the durable structure is a rotating target: coordination fragments across whichever service is currently under-monitored.
- For signals-intelligence doctrine, this points toward chasing people and distribution channels rather than specific apps — a structural shift from platform-level access toward endpoint and identity exploitation, since any single app compromise has a short shelf life.
The trend: Militant groups are locked in a recurring cycle between mainstream platforms and self-built or niche encrypted tools, with each migration resetting what surveillance can see and pushing both sides toward distribution- and endpoint-level countermeasures.