A while ago, a message as displayed below (Table-1) arrived in one of my WhatsApp groups. However questions started to be asked by the people I know regarding this message which I considered as a hoax[1] message and didn’t pay much attention to in the begging. So instead of making explanations to everyone on an individual basis I published an explanation on my personal website not only to show the true colors of the situation but also so share the decision I made with the public[2].
| Table 1- Full text spread through WhatsApp |
| VERY IMPORTANT! Dear Friends, A mail sent by a holding in turkey to its users… As Enterprise Information Technologies we aim to protect both your data and our company’s by announcing cyber risks at every opportunity. Now we share the information below in order for you not to be accused of “terrorist organization membership”. Therefore please beware of especially our security warnings. It has been determined that certain applications used on mobile devices are redirected to a FETO communication app, ByLock. It is estimated that the main purpose of these applications are to make it harder for the real communication and structure of the organization to be detected. Most of these known applications are free apps belonging to “Mor Beyin Yazılım” (Listed below). In addition to these, there are also a few free apps developed by “Alper Yıldız”. Once you download these apps on your mobile devices, a link on the advertisements page sized 1×1 pixels which is impossible to be seen, establishes a 1 second connection with the ByLock servers. This and all your other internet connections are saved and shared with the security units under the law number 5651 by your internet service providers (Turkcell, Avea, Superonline etc.). Thus you might be arrested for the accusation of “ByLock signals have been received from your phone” even if ByLock is not installed on your devices. For the present the number of arrestees accused of only “ByLock signals has been received from the phone” is around 10.000 none of which has ByLock App installed or has no verified connections with FETO related schools or organizations. How to be safe? – Do not download apps that you don’t need. – In case you need an app, prefer known, branded and widely used applications. – Do not share your home or mobile internet with your neighbors. – Do not Google search “mor beyin yazılım” and click links upon reading this message. So far identified Mobile apps redirecting to ByLock servers: 1- Best Free Music (Search&Play) 2- Freezy-Müzik Bul Dinle 3- Freezy-Play Free Music Online 4- Mor German English Dictionary 5- En Ucuz Fiyat 6- Mor Almanca-Türkçe Sözlük 7- Music Search-Beta 8- Araba2.com 9- Namaz vakitleri Diyanet(Alper yıldız) 10-Namaz Vakitleri TR(Alper yıldız) 11- Namaz vakitleri (Alper yıldız) For your kind information. |
Please find my explanation in (Table-2) below.
| Table 2 – Initiative Text |
| It is useful to underline several points in this text cited as if it is a message sent to the holding employees by the Enterprise Information Technologies department of an anonymous holding; First of all almost all these apps are no longer available for download neither in Google Play nor in App Store. Even if these apps are downloaded from third party websites they will not work as the servers the apps connect to are not accessible anymore. It is known that ByLock server was accessible on 12th of March 2016 and after that date the server was shut down. Thus access to the servers until that time are used as base during the investigations, and access after that date is not taken into consideration by the courts. Sufficient amount of numeric data has not been acquired to confirm that as stated in certain websites the relevant apps send requests to ByLock servers in an i-frame sized 1×1 pixels. In order to clarify this matter, necessary investigation needs to be conducted over the legal copies of the phones known to be used during the relevant dates and acquired material and the communication details belonging to these phones should be compared. Regarding the subjects mentioned above it is obvious this message sent over WhatsApp is a message to overshadow FETO investigations. In my opinion, this situation, however; does not make these allegations stating that applications developed by “Mor Beyin” send requests to Byblock.net domain, unworthy of discussion/investigation/research. I have received requests from hundreds of people to investigate if ByLock is installed on their phones and I gave most of them a negative answer. Yet as I understand, this has turned into a matter of profit. In order to enlighten this issue I have prepared a wide-ranging report on ByLock covering all the details and I will share this report with public very soon. Moreover, in order to clarify the claims on Mor Beyin Apps sending requests to bylock.net domain I will take initiative, analyze the phones of those whom I believe to be victimized and share the results personally both with the phone owners and the relevant state authorities. If you or people you consider to be victimized regarding the subject own phones with features listed below, it will be sufficient for you to send me an e-mail summarizing your situation to the address [email protected]. The more information you state about yourself or your relative in your mail, the more useful it will be for the analysis. Above mentioned applications should be installed on the phone at the moment or existed in the past. Phone shouldn’t be rebooted or restored to factory settings. Phone should be in operating state. Besides the initiative I have taken I know that relevant state authorities have been working on this subject to remove any possible victimization and I have full faith in the fact that this matter too will be enlightened in a very short time. |
I have had the opportunity to run several analyses over mobile devices and communication details sent to me by many people after the blog post above. While some of the information included in this report is obtained from these analyses, some other findings are the ones I acquired through my studies before starting this initiative. I would especially like to thank Gökmen Güreşçi for his extensive support for the gathering of the information and analysis processes.
The information in this report contains the results of technical analyses on the ByLock application and its communication infrastructure alleged to be used by the FETO members. All of these analyses were conducted by applying open source information and they are available to be re-conducted by other experts, as well.
The platforms that involve numerical evidences related to a mobile messaging application could be grouped under three different categories. These are;
- The devices used by the user (End-user devices such as mobile phones and computers)
- Network Components used for accessing to the relevant messaging platform (the network components operated by GSM operators and/or Internet service providers enabling internet access )
- Application Servers where the server of the mobile messaging application operates and could generally be found at internet
In this context, the diagram below shows the platforms that might contain digital evidences which could be collected in order to determine the ByLock application usage.

Figure 1 – The platforms that might contain digital evidences related to ByLock usage
This report is prepared by Halil ÖZTÜRKCİ in order to answer which digital trace, and on which components above, we could find out related to the ByLock usage; it is not prepared upon a request from any institution/organization or individual. The information in this report is basically grouped under three sub-headings. The choice of the sub-headings is based on the platforms that might contain digital traces related to the ByLock usage.
You can find my technical report as a PDF file at this link.
https://drive.google.com/open?id=1VSrirYJCgkxmSStIYrut4o6mCQ9-9tqT
[1] https://dictionary.cambridge.org/dictionary/english/hoax
[2] http://halilozturkci.com/bylock-mor-beyin-uygulamalari

