Mercenary Spyware and Exploit Brokers: A Rising Threat in Central Asia
Recent intelligence indicates that advanced persistent threat (APT) groups in Central Asia are increasingly leveraging mercenary spyware and exploit brokers, elevating the cyber threat landscape to a high level.
Encrygma is selling the entire Full Cyber Weapon Research of Mercenary Spyware and Exploit Brokers: A Rising Threat in Central Asia for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- High
- Actor Type:
- APT
- Geography:
- Central Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In early 2026, intelligence assessments have identified a significant escalation in cyber activities within Central Asia, attributed to advanced persistent threat (APT) groups. These actors are increasingly utilizing mercenary spyware and exploit brokers, indicating a high-level threat to regional cybersecurity.
Mercenary Spyware and Exploit Brokers
Mercenary spyware refers to surveillance tools developed by private companies and sold to government clients for cyber espionage purposes. Notable examples include NSO Group's "Pegasus," Intellexa's "Predator," and Candiru's "DevilsTongue." These tools exploit zero-day vulnerabilities to gain unauthorized access to target devices. Exploit brokers are intermediaries who discover and sell these vulnerabilities to surveillance companies or directly to state actors.
Recent Developments in Central Asia
In December 2025, leaked internal documents from Intellexa revealed the use of "Predator" spyware targeting Kazakhstan. The documents showed infection domains mimicking legitimate Kazakhstani news websites, such as kz-news[.]cc and kz-ordas[.]com, designed to deceive users into clicking malicious links. This operation underscores the growing use of mercenary spyware in the region. (securitylab.amnesty.org)
Additionally, in April 2023, researchers from Citizen Lab reported that QuaDream, an Israeli surveillanceware vendor, exploited a zero-click vulnerability in iOS 14 to deploy spyware against individuals in Central Asia. The attack targeted journalists, political opposition figures, and NGO workers, highlighting the region's vulnerability to sophisticated cyber espionage. (thehackernews.com)
Implications for Regional Security
The deployment of mercenary spyware by APT groups in Central Asia poses several risks:
-
Erosion of Privacy: Widespread surveillance undermines individual privacy rights and can lead to self-censorship among journalists and activists.
-
Undermining Trust: The use of deceptive tactics, such as fake news websites, erodes public trust in digital platforms and institutions.
-
Geopolitical Tensions: Attribution of cyber operations to state actors can strain international relations and lead to retaliatory measures.
Recommendations
To mitigate these threats, the following actions are recommended:
-
Enhanced Detection Capabilities: Invest in advanced cybersecurity tools to detect and neutralize spyware activities.
-
Public Awareness Campaigns: Educate the public and organizations about the risks of spyware and safe online practices.
-
International Collaboration: Engage in information sharing and joint efforts with international partners to track and counteract cyber espionage activities.
Conclusion
The increasing use of mercenary spyware and exploit brokers by APT groups in Central Asia represents a significant escalation in cyber threats. Proactive measures are essential to safeguard privacy, maintain public trust, and ensure regional stability.
Highlights:
- To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab, Published on Wednesday, December 03
- Israel-based Spyware Firm QuaDream Targets High-Risk iPhones with Zero-Click Exploit, Published on Tuesday, April 11
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Paragon Admits Inability to Monitor Misuse of Graphite Spyware Amid Global Surveillance Concerns

Paragon Solutions Admits Inability to Monitor Misuse of Graphite Spyware Amid Global Surveillance Concerns

