News Room
16
Share
Mediterranean Broker 'AegisLink' Deploys 'VoidLoom' Zero-Click Against High-Value Mobile Targets
criticalOffensive Tools

Mediterranean Broker 'AegisLink' Deploys 'VoidLoom' Zero-Click Against High-Value Mobile Targets

Researchers discovered a sophisticated zero-click exploit chain, 'VoidLoom', targeting iOS 19 and Android 16. Attributed to AegisLink, it bypasses modern hardware memory protections.

16 July 2026Last updated 20 August 20265 min readGoogle Threat Analysis Group (TAG)
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
Source:
Google Threat Analysis Group (TAG)
Read Time:
5 min

Executive Summary

On July 15, 2026, a joint report by the Google Threat Analysis Group (TAG) and Citizen Lab detailed the discovery of a sophisticated, multi-stage zero-click exploit chain dubbed 'VoidLoom'. This exploit, sold by the emerging mercenary surveillance firm AegisLink, has been observed in the wild targeting journalists and political dissidents across three continents. The discovery highlights the persistent evolution of the commercial surveillance industry, which continues to provide nation-state-level capabilities to clients with minimal oversight. VoidLoom is particularly notable for its ability to bypass the latest hardware-level memory protections introduced in the most recent flagship mobile chipsets.

Threat Analysis

VoidLoom represents a significant escalation in the mobile threat landscape. Unlike traditional spyware that requires user interaction via phishing links, VoidLoom is a zero-click delivery mechanism that initiates through the processing of a maliciously crafted media file sent via encrypted messaging applications. The exploit chain leverages a chain of three vulnerabilities: a remote code execution (RCE) flaw in a shared media codec library, a kernel memory leak to bypass Address Space Layout Randomization (ASLR), and a final privilege escalation bug to gain root access. This allows for the silent installation of a modular surveillance payload capable of exfiltrating messages, location data, and live audio/video feeds.

Technical Details

The core of the VoidLoom exploit resides in a previously unknown heap buffer overflow within the 'libmediaproc' framework, used by both iOS 19 and Android 16. Researchers found that by sending a specific sequence of malformed HEVC packets, an attacker can trigger a memory corruption event. This event is carefully choreographed to overwrite specific pointers in the heap, allowing for the execution of a primary ROP (Return-Oriented Programming) chain. Following the initial breakout, the exploit utilizes a race condition in the GPU driver's memory management unit to escalate privileges. The payload is non-persistent by default, residing only in the volatile memory of the target device's secure enclave, making forensic detection exceptionally difficult.

Attribution Assessment

Based on infrastructure analysis and unique code snippets found in the command-and-control (C2) binaries, TAG attributes VoidLoom with high confidence to AegisLink, a Cyprus-based firm composed of former intelligence contractors. The code overlaps significantly with previous tools associated with the now-defunct 'LoomingGlass' group, suggesting a re-branding or a transfer of intellectual property. AegisLink operates as a boutique exploit broker, providing end-to-end surveillance solutions to governmental clients. Telemetry data indicates that the C2 infrastructure was primarily active in regions undergoing political transition, suggesting the tool was purchased for domestic monitoring.

Implications

The emergence of VoidLoom confirms that despite increased regulatory pressure and sanctions on legacy firms, the demand for high-end surveillance tools remains robust. The exploit’s success against the latest OS versions underscores the limitations of current sandboxing and memory safety measures. This development will likely lead to a new round of emergency security updates from Apple and Google, but the underlying issue of the commercial exploit market persists. For high-risk individuals, the threat of silent, zero-click infection remains the most significant digital risk in 2026.

Recommendations

Organizations and high-risk individuals are advised to take the following actions: 1. Ensure all mobile devices are updated to the emergency patches released on July 16, 2026. 2. Enable 'Lockdown Mode' on iOS devices, as it successfully mitigated several stages of the VoidLoom chain in laboratory testing. 3. Monitor for unusual battery drain or unexpected reboots, which may indicate a failed exploit attempt. 4. Implement advanced mobile threat defense (MTD) solutions that provide real-time memory monitoring and network traffic analysis to detect C2 heartbeats. 5. Limit the public exposure of personal contact information used for messaging apps.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo