News Room
16
Share
Hyperion Zero-Click Exploit: New Mercenary Spyware Campaign Targets Diplomatic Personnel Worldwide
criticalOffensive Tools

Hyperion Zero-Click Exploit: New Mercenary Spyware Campaign Targets Diplomatic Personnel Worldwide

A newly discovered zero-click exploit chain, dubbed 'Hyperion,' has been linked to an emerging mercenary spyware vendor, targeting high-ranking diplomats through a vulnerability in media rendering.

11 July 2026Last updated 20 August 20265 min readGoogle Threat Analysis Group (TAG)
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-4401
Source:
Google Threat Analysis Group (TAG)
Read Time:
5 min

Executive Summary

On July 10, 2026, Encrygma researchers in collaboration with international partners identified a highly sophisticated surveillance campaign utilizing a zero-click exploit chain named 'Hyperion.' This campaign specifically targets mobile devices running the latest versions of iOS and Android. The exploit requires no user interaction and is delivered via a malformed image file sent through popular encrypted messaging applications. Preliminary findings suggest the involvement of a newly emerged commercial spyware firm, 'Aether Surveillance,' which appears to have inherited several developers and exploit methodologies from the sanctioned Intellexa alliance.

Threat Analysis

The Hyperion campaign is global in scope but shows a high concentration of targets in the European Union, the Middle East, and Southeast Asia. The primary victims identified thus far include senior diplomatic staff, human rights lawyers, and investigative journalists covering state-sponsored corruption. Unlike previous mercenary spyware attacks that relied on social engineering or phishing links, Hyperion is entirely silent. The infection process occurs in the background during the rendering of an incoming notification, making it nearly impossible for the user to detect the intrusion. The malware payload, once executed, grants full unauthorized access to the device's microphone, camera, encrypted messages, and location data.

Technical Details

The core of the Hyperion exploit is a vulnerability in the way mobile operating systems handle advanced image formats, specifically targeted at the GPU-accelerated rendering process. The exploit chain begins with a heap buffer overflow in a common media processing library (provisionally tracked as CVE-2026-4401). By sending a specially crafted '.webp2' file, the attacker can trigger a memory corruption event that bypasses the operating system's sandboxing mechanisms. The exploit utilizes a novel 'PAC-bypass' technique to circumvent Pointer Authentication Codes on modern ARM processors. Once initial code execution is achieved, a secondary stage downloader fetches a kernel-level rootkit. This rootkit establishes persistence by hooking into the system's update daemon, ensuring the spyware survives device reboots and minor security patches.

Attribution Assessment

We assess with high confidence that Hyperion is the product of 'Aether Surveillance,' a private-sector offensive actor based in a Mediterranean jurisdiction. Our analysis of the Command and Control (C2) infrastructure reveals significant overlaps with the 'Predator' spyware ecosystem formerly operated by Cytrox. Specifically, the obfuscation techniques used in the Hyperion payload share approximately 70% of their code signature with late-2025 variants of the Predator malware. Furthermore, the purchase of the underlying zero-day vulnerabilities has been traced back to 'X-Broker,' a boutique exploit firm known to serve high-paying commercial spyware clients.

Implications

The emergence of Hyperion underscores the failure of international sanctions to stifle the commercial spyware market. Despite the blacklisting of major players in 2024 and 2025, the demand for mobile surveillance tools has driven the creation of new, more opaque entities. The ability to bypass modern hardware-level security (like PAC) indicates a significant investment in research and development, likely funded by state clients seeking plausible deniability. This development threatens the integrity of encrypted communications, as the compromise occurs at the device endpoint rather than the protocol level.

Recommendations

To mitigate the risk of Hyperion, Encrygma recommends the following actions: 1. Users at high risk should enable 'Lockdown Mode' on iOS or the 'Advanced Protection' equivalent on Android, which limits media processing. 2. Implement strict mobile device management (MDM) policies to monitor for unusual background data exfiltration. 3. System administrators should look for connections to the newly identified C2 domains (e.g., api-sys-cloud[.]net). 4. Ensure all devices are updated to the emergency patches released by Apple and Google within the last 24 hours.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo