Chinese Authorities Utilize New Method to Hack Seized Phones and Access Data
Security specialists indicate that Chinese authorities are utilizing a new form of malware to extract information from seized smartphones. This allows access to text messages—even those from apps such as Signal—along with images, GPS locations, voice memos, contacts, and other data.
On Wednesday, the mobile security firm Lookout published a report for TechCrunch detailing a hacking tool called Massistant, which they claim was developed by the Chinese technology company Xiamen Meiya Pico.
Lookout characterizes Massistant as Android software designed for forensic data extraction from mobile devices, suggesting that officials must physically possess the phones for it to be effective. Although Lookout couldn’t identify which police units in China use this tool, its presumed widespread application signals that both residents and travelers in China should remain vigilant about its implications.
“It’s a major concern. Anyone traveling to the area should understand that their device may be taken and any information on it could be harvested,” Kristina Balaam, a Lookout researcher who examined the malware, told TechCrunch before the report’s release. “Travelers should exercise caution.”
Balaam found numerous threads on local Chinese discussion boards where users expressed their discontent upon discovering the malware on their devices following interactions with law enforcement.
“It seems to be widely utilized, particularly when observing conversations in these Chinese forums,” Balaam commented.
The malware must be installed on an unlocked phone and works in conjunction with a hardware tower linked to a desktop computer, according to descriptions and visuals found on Xiamen Meiya Pico’s website.
Balaam explained that Lookout was unable to analyze the desktop component, nor did they encounter a version of the malware for Apple devices. Xiamen Meiya Pico’s website features images of iPhones attached to its forensic hardware, suggesting a possible iOS variant of Massistant capable of extracting data from Apple gadgets.
Law enforcement personnel do not require advanced techniques to utilize Massistant, such as exploiting zero-day vulnerabilities—undisclosed weaknesses in software or hardware—because “people simply hand over their phones,” Balaam noted, based on insights gathered from Chinese forums.
Since at least 2024, Chinese state security police have been authorized to search phones and computers without a warrant or an active criminal investigation.
“If an individual goes through a border checkpoint and their device is taken, they must grant access to it,” Balaam elaborated. “There’s no need for sophisticated exploits in lawful interception; it’s simply unnecessary.”

The positive aspect, according to Balaam, is that Massistant leaves indicators of its installation on the compromised device, allowing users to potentially identify and remove the malware—whether it appears as an application or can be located and deleted using advanced tools like the Android Debug Bridge, a command-line utility that connects a device to a computer.
However, the downside is that once Massistant is installed, the harm is irreversible, and authorities have likely already accessed the individual’s data.
Lookout claims that Massistant is a successor to a similar mobile forensic tool called MSSocket, also created by Xiamen Meiya Pico, which security analysts examined back in 2019.
Reports suggest that Xiamen Meiya Pico commands a 40% share of China’s digital forensics market and was sanctioned by the U.S. government in 2021 for its involvement in supplying technology to Chinese authorities.
The company has yet to respond to inquiries from TechCrunch for comments.
Balaam emphasized that Massistant is merely one of many spyware and malware solutions developed by Chinese surveillance technology firms, which she describes as “a significant ecosystem.” She noted that the company tracks at least 15 distinct malware families operating within China.


