Privacy Tips

Recognize and remove states trojans?

Started by hostage73 · Feb 13, 2026

#8934
In the last weeks i have chatted with some guys that are also into fraud and stuff like that. I met them online in December. Now they accidently dropped my Citys Name and a bit more of information they shouldnt know and after I did a bit of research I also found out that they behaved like Feds.

Now my Wifi has issues, my VPNs and also my tor connection on my graphene os phone stop connecting, Data disapeared and so on.

I didnt download anything, didnt open any link without checking if they are legit.

So I just want to be sure if it is a states trojan that is imstalled on my devices or not.

Here in germany police is allowed to install them on suspicious devices.

Is there any tool with that I can check for them and remove them?

I need answers fast
#8935
↳ Replying to @hostage73
Accidently dropped ur citys name? does not sound like the feds at all, i dont know which app you met them on so i cant give for possible answers on how they got ur information but you could use MTV or packet capturing like wireshark but state trojans are encrypted

Reflash the factory firmware image to get rid of the state trojan
#8936
↳ Replying to @hostage73
Graphene OS is very secure from tampering. Every time it boots it verifies that the bootloader hasn't been tampered with. So your phone is almost surely ok. Of course if your password is not guessable or reused. Did you install any APK from an untrusted platform? If not you are probably safe from software viruses. If you are paranoid then try monitoring your network with Wireshark, wIth and without access to the global internet. Same for your laptop, depends on what OS. If you are posting from windows 11 for example then malware comes preinstalled.
#8937
↳ Replying to @hostage73
sounds a little like ur a bit overparanoid. depending on what vpn u use connection issues are very normal, same with tor. data disappearing as in files are just gone? if the feds would've installed some sort of tracking or malware dont u think it would act silently in the background and not make itself known like "here look im blocking ur wifi temporarily so that u know im installed on ur system". if theres actual concerns u have reset ur network settings on ur wifi, run some basic diagnostics and test, reinstall ur os and so forth, basic things. if u would have an actual "states trojan" on ur devices or systems u wouldnt even know. and it'd be very very hard to detect since well thats kinda their job
#8938
↳ Replying to @rebelmouse
Telegram needs approval due to fighting Spammers.

Telegram needs approval due to fighting Spammers.

This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.
#8939
↳ Replying to @hostage73
check if you have in your city local branch of amnesty international, they have tools to check if anything is modified in phone, but dont mention them cops, tell them you are suspicious that secret service could spy you because you participate in protests.

nobody can find traces of pegasus, pegasus is not installed in your phone, it is remote exploiting android and so on. it is not one appl that should be installed and play a role of trojan.

so, try to get information what spying software are bought, possessed by german local and federal cops. maybe there are official order and it is not hidden what software they bought.

in my country, we know which comnpanies supply cops and secret service with spying devices and then you can check their websites what products they sell.

I suppose germans order spying shit from isreal, NSO, cellebritte, and similar.

Company Main Focus Type of Tool

NSO Group Remote spyware (Pegasus) Mobile device exploitation

Cellebrite Digital forensics & extraction Law enforcement data access

Candiru Commercial spyware Exploit‑based implants

Quadream Spyware similar to Pegasus Zero‑click targeting

Paragon Solutions Spyware (Graphite) Device and app tracking

Cytrox / Intellexa Spyware and network exploits Covert monitoring

Gamma Group FinFisher spyware Government interception

SS8 Communications surveillance Telecom interception

First Wap Network‑level tracking Telecom infrastructure

Government units Custom offensive tools Intelligence operations

Cellebrite

• Israeli digital intelligence company known for phone unlocking and data extraction tools used by law enforcement worldwide.

Candiru (Saito Tech Ltd.)

• Provides spyware and cyber‑espionage tools used by governments.

• Products exploit vulnerabilities to implant persistent spyware.

Quadream

• Founded by former NSO employees, sold zero‑click iPhone spyware similar to Pegasus. (Suspected to shut down as of 2023.)

Paragon Solutions

• Israeli spyware firm offering tools like Graphite, used to monitor devices including messaging apps. It has been implicated in real‑world spyware campaigns.

Cytrox (Intellexa)

• Cyber‑espionage tools used for covert surveillance; part of the Intellexa consortium and sanctioned by U.S. regulators.

Gamma Group — Known for FinFisher spyware (often compared with commercial surveillance tools).

SS8 / SS8 Technologies — U.S. firm historically known for lawful interception and communications surveillance solutions.

Intellexa Consortium — A group including Cytrox and other cybersecurity firms selling commercial spyware.

First Wap / Altamides — Indonesian‑based firm providing different types of surveillance capabilities (network‑level tracking rather than device implants).

Various government‑linked units — In many countries, national intelligence agencies build and operate their own bespoke offensive tools (e.g., U.S. NSA, UK GCHQ.....).