Viber Messenger Extraction In Oxygen Forensic Detective

Viber is a cross-platform voice over IP and instant messaging software operated by Rakuten. The software app is provided as freeware for Android, Apple iOS, Microsoft Windows, macOS and Linux platforms. Initially the messenger was developed in 2010 by the Israel-based Viber Media, which was then bought by Rakuten in 2014. According to Statista, there were over 1.1 billion registered users as of March 2019.

Viber’s official website states the app offers end-to-end encryption and the encryption keys only exist on user’s devices. Additionally, they state no data is stored on the Viber server and that messages are only temporarily stored when they cannot be delivered to the mobile device.Public chats on Viber are not encrypted at all. However, in comparison with WhatsApp, Viber offers secret chats. This method of communication allows users to chat in an encrypted channel that will not be synchronized with the cloud service or with Viber Desktop. Secure, right? There is more. Secret chats offer self-destruct messages and also screenshot notifications. Unfortunately, once a message is self-destructed it cannot be recovered by forensic software, even if a physical extraction is done.

Almost every Messenger used today offers the ability to delete a chat for everyone within the sent messages. If a message was deleted for everyone in Viber only partial recovery is obtainable. We will show you what artifacts can be retrieved in the second part of our post.

Now let’s look into one more interesting Viber feature that is really unique. Viber offers users the ability to hide any chat by setting a PIN code for it in the Viber settings. Once a chat is hidden you need to enter a PIN code in the messenger search field to unhide it. What does this mean for investigators? Even if you have an unlocked phone this does not mean you will see all the conversations in Viber. This will also be covered in the second part of our blog.

Oxygen Forensic® Detective offers the most comprehensive Viber data extraction from all possible sources.

Viber extraction from mobile devices


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

We currently support Viber for Apple iOS and Android devices. Extraction from Apple devices is as easy as a simple iTunes backup with no need to jailbreak the device. As for Android we recommend a physical extraction or and if the device happens to be a Huawei, import the backup to get at the Viber data.

No matter what phone operating type you are dealing with you will be able to collect the same evidence set: account info, contacts (both Viber and the phonebook copied to its database), private and group chats with all the shared data. Also, secret chats are extracted and decrypted in full.

Messages that have been deleted for everyone will be partially recovered – there will be time stamps, remote party but no texts. Great news – hidden chats are fully extracted in our software.

Viber extraction from cloud

A user may also create a Viber message backup and send it to cloud storage (iCloud or Google Drive depending on the device OS). Unlike WhatsApp backups that can be locally stored on an Android device Viber does not store any backups on the device.

Moreover, unlike WhatsApp backups in the cloud, Viber’s cloud backups are not encrypted. You can access them in iCloud or Google Drive simply by inserting the credentials in our Oxygen Forensic® Cloud Extractor. The extracted evidence set will include contacts and chats but no secret or hidden chats since they are not saved to the backup.

Fast QR code extraction

Our QR code method has already proved to be efficient on WhatsApp and Line Messengers so we have also implemented it for Viber. This method can be a lifesaver when you have a phone unlocked, the extraction fails or the created image is encrypted. It is easy, simply open Viber in a mobile device and start our Cloud Extractor. You will need to scan a Viber QR code in our software to receive the account information, contacts and messages. Access via QR code can be also obtained via Viber QR token found by our innovative, and included, KeyScout utility.

Viber from PC

Viber Messenger can also be installed to desktops and synced when you scan the QR code from the Viber mobile app. Viber data on a PC is not encrypted and Oxygen Forensic® KeyScout utility can collect Viber contacts and chats with the exception of secret and hidden chats which are not saved to the PC.

As outlined Viber appears to not be positioned as a secure messenger but offers users a couple of features that enhance their privacy. No matter what functions are used Oxygen Forensic® Detective extracts the maximum amount of data possible from all available sources.

Leave a Comment

Latest Videos

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools. <br /><br />They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.<br /><br />Show Notes:<br /><br />A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf<br /><br />Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi<br /><br />A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi<br /><br />European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234<br /><br />YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/<br /><br />Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools.

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_7QiFTiuY7Vw

AI In CSAM Investigations And The Role Of Digital Evidence In Criminal Cases

Forensic Focus 22nd March 2023 12:44 pm

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_g6nTjfEMnsA

Tips And Tricks Data Collection For Cloud Workplace Applications

Forensic Focus 20th March 2023 12:00 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...