Intelligence Hub

Mercenary Spyware & Commercial Surveillance

A global industry of private cyber-arms dealers sells nation-grade mobile surveillance to governments worldwide. Track vendors, victims, regulatory actions, and technical capabilities.

Overview

The mercenary spyware industry represents one of the most consequential — and legally contested — sectors of the global cyber arms market. Companies like NSO Group (Pegasus), Intellexa (Predator), Paragon Solutions, and dozens of less-publicized vendors sell mobile device intrusion capabilities to government clients, enabling covert surveillance of journalists, opposition politicians, activists, and business leaders.

Zero-click exploits targeting iOS and Android — the crown jewels of these toolkits — exploit vulnerabilities in iMessage, WhatsApp, cellular protocols, and other attack surfaces with no user interaction required. Forensic research by Citizen Lab, Amnesty International, and Access Now has exposed hundreds of confirmed spyware victims across 50+ countries.

Regulatory responses have accelerated: the US sanctioned NSO Group and Candiru, the EU launched formal investigations into Predator use by member states, and the Pall Mall Process established multilateral norms discussions. Yet the industry persists through corporate rebranding, jurisdictional arbitrage, and the persistent demand from authoritarian and democratic governments alike.

Key Threat Areas

Zero-Click Exploits

No-interaction iOS and Android exploits enabling silent device compromise.

Lawful Intercept Abuse

Surveillance tools sold for criminal investigations used against civil society.

Corporate Rebranding

Sanctioned firms relaunching under new names and jurisdictions.

Broker Ecosystem

Exploit brokers (Zerodium, Crowdfense) supplying zero-days to spyware vendors.

Telecommunications Interception

SS7, Diameter, and IMSI catcher capabilities bundled with software implants.

Cloud-Enabled Exfiltration

Spyware silently exfiltrating cloud backups, encrypted messages, and location data.

Latest Intelligence

View all articles

The Vendor Ecosystem

Beyond NSO Group and Intellexa, the mercenary spyware market includes Paragon Solutions (Israel), FinFisher/FinSpy (Germany/UK), Cobwebs Technologies, Candiru (also sanctioned), Cytrox, Wintego, and dozens of less-known entities. Many operate as holding companies with shifting corporate structures to evade sanctions and export controls.

Forensic Detection Methods

The Mobile Verification Toolkit (MVT) developed by Amnesty International's Security Lab is the primary open-source tool for spyware forensics on iOS and Android devices. Citizen Lab's PWNAGE and iVerify's threat detection are additional consumer-facing options. Detection focuses on network traffic analysis, process anomalies, and IOC matching against known spyware artifacts.

Frequently Asked Questions

Weekly Briefing

Get the Weekly Cyberwarfare Briefing

State cyber operations, AI-powered attack campaigns, and offensive cyber industry developments — delivered to your inbox every week.

Defensive intelligence only. No spam — unsubscribe anytime.