
AI-Automated 'SILENT-WHISPER' Zero-Click Exploit Chain Targets Encrypted Messaging Apps
Encrygma researchers have identified a new zero-click exploit chain developed by a mercenary spyware collective using LLM-driven vulnerability discovery to target iOS and Android messaging protocols.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Middle East
- Confidence:
- High Confidence
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
On August 10, 2026, intelligence reports surfaced regarding a sophisticated zero-click exploit chain targeting the latest versions of iOS and Android. The exploit, identified as 'SILENT-WHISPER,' is attributed to a burgeoning mercenary spyware collective operating out of the UAE. Unlike previous manual exploit developments, this chain appears to have been synthesized using advanced Large Language Model (LLM) fuzzing techniques, significantly reducing the time-to-market for high-value mobile vulnerabilities. This development follows recent warnings from Apple regarding mercenary spyware attacks and the increasing role of commercial vendors in the zero-day market.
Threat Analysis
The commercial surveillance landscape has reached a tipping point. As reported by Google Threat Intelligence Group, the number of zero-days exploited by commercial vendors has surpassed those used by traditional state-sponsored groups. SILENT-WHISPER represents a documented case of an 'automated' exploit discovery process. The threat actor, likely a successor to the sanctioned Advance Security Solutions, is marketing this capability to regional intelligence agencies for targeted espionage against high-profile activists and financial executives. The use of AI to find vulnerabilities, as seen in recent WordPress RCE discoveries, has now fully transitioned into the mobile surveillance sector.
Technical Details
The exploit chain begins with a sophisticated SS7 bypass technique to intercept TCAP layer signaling. This allows the attacker to initiate a silent session with the target device. Once the connection is established, the primary payload exploits a heap buffer overflow in the media processing library of several encrypted messaging applications. Encrygma's analysis suggests the vulnerability was discovered using a proprietary LLM-based offensive platform that automates the identification of memory corruption bugs in closed-source binaries. The exploit achieves Remote Code Execution (RCE) without any user interaction, bypassing modern sandboxing through a secondary kernel-level privilege escalation. This aligns with reports of hackers turning AI jailbreaks into offensive platforms.
Attribution Assessment
While the specific group has not yet been named, the infrastructure overlaps significantly with the 'Operation Zero' and 'Advance Security Solutions' networks sanctioned by the U.S. Treasury. The command-and-control (C2) servers utilize residential proxy networks, a tactic increasingly favored by mercenary vendors to evade detection. Microsoft MSTIC has indicated a high degree of confidence that the developers are former members of the Intellexa consortium who have reorganized under a new corporate identity to bypass international blacklists.
Implications
The emergence of AI-automated exploit discovery fundamentally alters the risk calculus for mobile security. The speed at which new zero-days can be identified and weaponized threatens to outpace the patch cycles of major platform providers. Furthermore, the democratization of these tools through the mercenary market means that even smaller nation-states or well-funded criminal organizations can now possess capabilities previously reserved for top-tier intelligence agencies.
Recommendations
Organizations are advised to enforce strict mobile device management (MDM) policies and encourage the use of 'Lockdown Mode' for high-risk individuals. Security teams should monitor for anomalous SS7 signaling patterns and implement network-level protections against known residential proxy exit nodes. Regular device reboots remain a critical defense against non-persistent mobile spyware, as noted in recent Apple security advisories.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
