Digital forensics, digital investigation and cybercrime expert Alexis Mavros has explained the main methods through which mobile phones can be monitored, while also outlining practical measures that can reduce the risk of spyware infections. He also stressed the need for a clear legal framework, judicial oversight and robust safeguards.
Speaking on Politis 107.6 & 97.6 radio during the programme Proini Epitheorisi with Katerina Eliadi, Mavros referred to three main forms of surveillance: lawful interception through telecommunications providers, the use of a device that acts as a fake mobile phone antenna and the infection of a phone with spyware.
As he explained, the traditional surveillance method is lawful interception, through which authorised law enforcement agencies gain access to telecommunications providers' infrastructure and systems, allowing them to monitor or record calls, messages and information such as device activity and the characteristics of a phone and SIM card in real time.
The “suitcase” and the fake antenna
The second method involves the use of a special device commonly known as a “suitcase.”
The device replaces the area's legitimate mobile phone tower with a fake one, causing communications to pass through it.
In this way, conversations, messages and identifying information related to a phone and its SIM card can be monitored or recorded.
Mavros noted that the infamous “black van” had such capabilities.
"It had the ability to do that. Whether it actually did so, I hope will one day become clear," he said.
Infecting the phone
Mavros described the infection of a device with malicious software exploiting vulnerabilities in an operating system or application as the most invasive and dangerous method.
A phone may be infected if a user is persuaded to click on a malicious link received through email, text message or an application.
"If someone convinces you through email, a message or an app to click on a link, that is one way your phone can be infected with malware that exploits vulnerabilities in your operating system or one of your applications," he explained.
If the infection is successful, an attacker can gain extensive access to the device.
"The access is unlimited. It is as if the person who infected your phone is using it remotely. They can listen while you are speaking, they can listen when you are not using it for calls, they can access photos, messages, everything," he said.
Attacks without clicking a link
According to the expert, there are also technologies that allow a device to be infected without the user clicking on anything. These are known as "zero-click" attacks.
Such capabilities are extremely expensive and, in his view, are unlikely to be used widely against ordinary citizens.
He said these technologies can cost a state more than €100 million per year, while spyware targeting a single individual may cost tens of thousands of euros.
“They happened, they happen and they will likely continue”
Asked whether surveillance activities take place in Cyprus, Mavros replied in the affirmative, citing his professional experience, research and information that has emerged publicly over the years.
Are messaging apps safe?
The expert explained that messaging applications with strong encryption can protect communications while messages are being transmitted.
However, that protection can be bypassed if the operating system of a phone has already been compromised.
In such cases, spyware can access information before it is encrypted or after it appears on a user's screen.
Protection measures
Mavros recommended the use of a reliable VPN as an additional layer of protection, while noting that it is not a complete defence against every type of attack.
He placed particular emphasis on keeping operating systems and applications updated.
According to him, most software updates are primarily intended to fix security vulnerabilities rather than simply improve functionality.
"Ninety per cent of updates close security vulnerabilities," he said.
He also referred to enhanced security features offered by technology companies for users who believe they may be at risk.
For iPhone users, he highlighted Lockdown Mode.
"Someone who believes they may become a target of a spyware attack can dramatically reduce the chances of infection by enabling Lockdown Mode," he said.
He also referred to enhanced security programmes available to Android users and specialised operating systems that can be installed on certain devices through Google.


