Mercenary Spyware and the Rise of Commercial Offensive Cyber Capabilities in Western Europe
The proliferation of mercenary spyware and commercial offensive cyber tools poses a significant threat to Western Europe, with ransomware groups increasingly leveraging these capabilities.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- Western Europe
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
The landscape of cyber threats in Western Europe has evolved markedly in recent years, with ransomware groups increasingly leveraging mercenary spyware and commercial offensive cyber tools. This shift has introduced new challenges for cybersecurity professionals and organizations across the region.
Proliferation of Mercenary Spyware
Mercenary spyware refers to surveillance tools developed by private companies and sold to government agencies, law enforcement, and, in some cases, non-state actors. These tools are designed to infiltrate and monitor target devices, often exploiting zero-day vulnerabilities. Notable examples include:
-
NSO Group's Pegasus: A sophisticated spyware capable of remotely accessing and extracting data from mobile devices. Despite its intended use by government clients, instances have emerged where Pegasus was misused, raising concerns about oversight and accountability.
-
Cytrox's Predator: Another advanced spyware tool that has been linked to surveillance activities targeting journalists, activists, and political figures. The U.S. Department of Commerce added Cytrox to its Entity List in July 2023, citing threats to national security and foreign policy interests.
Commercial Offensive Cyber Tools and Exploit Brokers
The market for commercial offensive cyber capabilities has expanded, with private vendors offering a range of tools and services:
-
Exploit Brokers: Entities that acquire and sell zero-day vulnerabilities to the highest bidder. The case of Peter Williams, a former general manager at L3Harris, illustrates this trend. Williams was sentenced in February 2026 for selling stolen exploit components to a Russian exploit broker, highlighting the lucrative and clandestine nature of this market.
-
Red Team Frameworks: Tools designed to simulate adversary tactics, techniques, and procedures (TTPs) to assess and improve organizational defenses. Open-source frameworks like MITRE Caldera and Atomic Red Team have gained popularity, but their availability also means that malicious actors can adopt similar methodologies to enhance their attacks.
Surveillance-as-a-Service and Ransomware Groups
The convergence of surveillance-as-a-service offerings and ransomware operations has created a potent threat vector:
-
Integration of Spyware in Ransomware Attacks: Ransomware groups are increasingly incorporating surveillance tools into their operations. By deploying spyware, they can gather intelligence on target organizations, identify critical assets, and tailor their attacks for maximum impact.
-
Case Study – UNC6691: A financially motivated Chinese threat actor, UNC6691, utilized the Coruna exploit kit in late 2025. This kit, which targets iOS devices, was initially developed by a commercial surveillance vendor and later acquired by cybercriminals. The integration of such tools enabled UNC6691 to conduct large-scale cryptocurrency theft operations, demonstrating the evolving tactics of ransomware groups.
Implications for Western Europe
The integration of mercenary spyware and commercial offensive tools into ransomware operations poses several challenges:
-
Escalated Threats: The sophistication of attacks has increased, with ransomware groups now capable of conducting more targeted and damaging operations.
-
Erosion of Trust: The use of surveillance tools against private entities can erode public trust in digital platforms and services.
-
Regulatory Challenges: Existing legal frameworks may be inadequate to address the complexities introduced by these advanced cyber capabilities.
Conclusion
The rise of mercenary spyware and commercial offensive cyber tools has significantly altered the cyber threat landscape in Western Europe. Ransomware groups' adoption of these capabilities underscores the need for enhanced vigilance, robust cybersecurity measures, and comprehensive regulatory approaches to mitigate the associated risks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Escalating Pegasus Deployments: New Zero-Click Campaigns Target Civil Society in Serbia

Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts to Targets Across 110 Countries

