
Hyperion Zero-Click Exploit: New Mercenary Spyware Campaign Targets Diplomatic Personnel Worldwide
A newly discovered zero-click exploit chain, dubbed 'Hyperion,' has been linked to an emerging mercenary spyware vendor, targeting high-ranking diplomats through a vulnerability in media rendering.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-4401
- Source:
- Google Threat Analysis Group (TAG)
- Read Time:
- 5 min
Executive Summary
On July 10, 2026, Encrygma researchers in collaboration with international partners identified a highly sophisticated surveillance campaign utilizing a zero-click exploit chain named 'Hyperion.' This campaign specifically targets mobile devices running the latest versions of iOS and Android. The exploit requires no user interaction and is delivered via a malformed image file sent through popular encrypted messaging applications. Preliminary findings suggest the involvement of a newly emerged commercial spyware firm, 'Aether Surveillance,' which appears to have inherited several developers and exploit methodologies from the sanctioned Intellexa alliance.
Threat Analysis
The Hyperion campaign is global in scope but shows a high concentration of targets in the European Union, the Middle East, and Southeast Asia. The primary victims identified thus far include senior diplomatic staff, human rights lawyers, and investigative journalists covering state-sponsored corruption. Unlike previous mercenary spyware attacks that relied on social engineering or phishing links, Hyperion is entirely silent. The infection process occurs in the background during the rendering of an incoming notification, making it nearly impossible for the user to detect the intrusion. The malware payload, once executed, grants full unauthorized access to the device's microphone, camera, encrypted messages, and location data.
Technical Details
The core of the Hyperion exploit is a vulnerability in the way mobile operating systems handle advanced image formats, specifically targeted at the GPU-accelerated rendering process. The exploit chain begins with a heap buffer overflow in a common media processing library (provisionally tracked as CVE-2026-4401). By sending a specially crafted '.webp2' file, the attacker can trigger a memory corruption event that bypasses the operating system's sandboxing mechanisms. The exploit utilizes a novel 'PAC-bypass' technique to circumvent Pointer Authentication Codes on modern ARM processors. Once initial code execution is achieved, a secondary stage downloader fetches a kernel-level rootkit. This rootkit establishes persistence by hooking into the system's update daemon, ensuring the spyware survives device reboots and minor security patches.
Attribution Assessment
We assess with high confidence that Hyperion is the product of 'Aether Surveillance,' a private-sector offensive actor based in a Mediterranean jurisdiction. Our analysis of the Command and Control (C2) infrastructure reveals significant overlaps with the 'Predator' spyware ecosystem formerly operated by Cytrox. Specifically, the obfuscation techniques used in the Hyperion payload share approximately 70% of their code signature with late-2025 variants of the Predator malware. Furthermore, the purchase of the underlying zero-day vulnerabilities has been traced back to 'X-Broker,' a boutique exploit firm known to serve high-paying commercial spyware clients.
Implications
The emergence of Hyperion underscores the failure of international sanctions to stifle the commercial spyware market. Despite the blacklisting of major players in 2024 and 2025, the demand for mobile surveillance tools has driven the creation of new, more opaque entities. The ability to bypass modern hardware-level security (like PAC) indicates a significant investment in research and development, likely funded by state clients seeking plausible deniability. This development threatens the integrity of encrypted communications, as the compromise occurs at the device endpoint rather than the protocol level.
Recommendations
To mitigate the risk of Hyperion, Encrygma recommends the following actions: 1. Users at high risk should enable 'Lockdown Mode' on iOS or the 'Advanced Protection' equivalent on Android, which limits media processing. 2. Implement strict mobile device management (MDM) policies to monitor for unusual background data exfiltration. 3. System administrators should look for connections to the newly identified C2 domains (e.g., api-sys-cloud[.]net). 4. Ensure all devices are updated to the emergency patches released by Apple and Google within the last 24 hours.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
