News Room
16
Share
New Intelligence Report Links Commercial Surveillance Vendors to 40% of Recent Mobile Zero-Day Exploits
criticalOffensive Tools

New Intelligence Report Links Commercial Surveillance Vendors to 40% of Recent Mobile Zero-Day Exploits

A new analysis of the exploit ecosystem reveals that commercial surveillance vendors (CSVs) are now responsible for nearly half of all mobile zero-day activity, shifting focus toward telecom signaling vulnerabilities.

07 August 2026Last updated 20 August 20264 min readVulnCheck / Google TAG
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
Source:
VulnCheck / Google TAG
Read Time:
4 min

Executive Summary

As of August 7, 2026, recent intelligence synthesized from the VulnCheck 2026 Exploit Intelligence Report and updated findings from Google’s Threat Analysis Group (TAG) indicates a significant surge in the activity of commercial surveillance vendors (CSVs). These mercenary entities are increasingly filling the gap for nation-states lacking indigenous cyber capabilities, providing turn-key espionage solutions. The data shows that CSVs were definitively linked to 18 of the 42 attributed zero-day exploits over the past year, with a specific focus on mobile operating systems and telecommunications infrastructure.

Threat Analysis

The threat landscape has undergone a fundamental shift. While traditional Advanced Persistent Threats (APTs) continue to prioritize edge devices and security appliances for initial access, CSVs have pivoted toward the total compromise of personal mobile devices. This trend is driven by the high demand for real-time geolocation, encrypted communication interception, and remote microphone activation. Intelligence suggests that the 'surveillance-as-a-service' model is no longer limited to high-tier actors like NSO Group; a new tier of mid-market exploit brokers is now providing sophisticated capabilities to a broader range of clients, including domestic law enforcement agencies in over 25 countries.

Technical Details

Recent technical analysis highlights two primary vectors of concern. First is the 'Coruna' iOS exploit kit, which has been observed in the wild since early 2025. This kit utilizes a chain of 23 distinct exploits, including non-public mitigation bypasses that target the latest iOS kernel versions. Second, researchers have identified a sophisticated bypass of the Signaling System No. 7 (SS7) and Diameter protocols. Unlike traditional device-side malware, these attacks exploit vulnerabilities in the global telecommunications signaling infrastructure. By posing as legitimate cellular providers, surveillance vendors can track a target's location with meter-level accuracy and intercept SMS-based two-factor authentication codes without ever touching the target's device.

Attribution Assessment

Attribution remains complex due to the use of multi-layered proxy infrastructures, but recent findings from Citizen Lab and Enea have identified several key players. The NSO Group remains a dominant force, but newer entities like Candiru and the developers of the 'Webloc' advertising-based tracking system are gaining market share. Webloc, in particular, has been attributed to use by domestic intelligence services in El Salvador and several U.S. law enforcement departments, leveraging ad-tech data to track over 500 million devices globally. The 'Coruna' kit is currently linked to a Mediterranean-based exploit broker that serves as a primary supplier for several Gulf-state intelligence agencies.

Implications

The democratization of high-end surveillance tools means that the cost of digital repression is falling. The shift toward infrastructure-level attacks (SS7/Diameter) is particularly concerning because it renders many device-side security measures, such as encrypted messaging apps, less effective for location privacy. Furthermore, the reuse of these tools by cybercriminal elements, as seen with the 'AVKiller' and 'ZeroDayRAT' mobile variants, suggests a dangerous bleed-over from the mercenary market to the broader criminal underground.

Recommendations

Encrygma recommends that high-risk individuals enable 'Lockdown Mode' on iOS and Android devices to reduce the attack surface. Organizations should implement hardware-based security keys (FIDO2) to mitigate the risk of SS7-based SMS interception. Furthermore, telecommunications partners must be pressured to implement advanced signaling firewalls and ASN.1 protocol validation to detect unauthorized location queries at the carrier level.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo