
Paragon Solutions Admits Inability to Monitor Misuse of Graphite Spyware Amid Global Surveillance Concerns
Paragon Solutions CEO Andrew Boyd has confirmed the company lacks technical visibility into how clients deploy its Graphite spyware, sparking renewed debate over the accountability of exploit brokers.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Digital Watch Observatory
- Read Time:
- 4 min
Executive Summary
In a candid admission on October 1, 2026, Andrew Boyd, CEO of the commercial spyware firm Paragon Solutions, revealed that the company possesses no technical mechanism to monitor or audit the specific targets of its flagship 'Graphite' mobile surveillance tool. This disclosure follows the cancellation of several high-profile contracts in Italy and highlights a systemic lack of oversight within the mercenary spyware industry. As these tools become increasingly sophisticated, the inability of vendors to enforce contractual 'end-use' restrictions poses a critical risk to human rights and global digital security.
Threat Analysis
Mercenary spyware, such as Graphite and the more widely known Pegasus, represents the pinnacle of offensive cyber capabilities. These tools often utilize zero-click exploits—vulnerabilities that require no user interaction to compromise a device—to gain full administrative access to mobile operating systems. The threat is characterized by its extreme cost and high level of stealth, making detection nearly impossible for the average user. The recent admission by Paragon underscores that even when vendors claim to implement 'ethical' safeguards, the underlying architecture of these tools often allows for unchecked surveillance once the software is deployed to a government client.
Technical Details
Graphite is designed to bypass modern mobile security protections, including sandboxing and encrypted messaging protocols. By leveraging undisclosed vulnerabilities in iOS and Android, the spyware can exfiltrate real-time location data, private communications, and media files. Because the software operates at the kernel level, it can persist across reboots and evade standard mobile security software. The core issue, as identified by security researchers, is that the command-and-control (C2) infrastructure is managed by the end-user (the government agency), effectively blinding the vendor to the operational activities of their own product.
Attribution Assessment
Paragon Solutions, now under the ownership of AE Industrial Partners and integrated with RedLattice, operates as a commercial entity providing 'intelligence-grade' capabilities to state actors. While the company maintains that it vets its customers, the lack of technical oversight suggests that the 'mercenary' model prioritizes profit and operational secrecy over the prevention of human rights abuses. This mirrors the ongoing controversies surrounding NSO Group, whose Pegasus spyware has been repeatedly linked to the targeting of journalists, activists, and political dissidents globally.
Implications
The inability of vendors to control their own products creates a 'black box' of surveillance. When these exploits are sold to regimes with poor human rights records, there is no fail-safe to prevent the targeting of civil society. Furthermore, the proliferation of these tools increases the risk that exploits will be leaked, reverse-engineered, or repurposed by criminal syndicates, thereby expanding the threat landscape beyond state-sponsored espionage.
Recommendations
Organizations and high-risk individuals should adopt a 'zero-trust' approach to mobile security. This includes enabling Lockdown Mode on iOS devices, regularly auditing device logs for anomalous behavior, and minimizing the storage of sensitive data on mobile hardware. Policymakers must push for stricter export controls on dual-use surveillance technologies and mandate that vendors implement 'kill-switch' capabilities or transparent, third-party auditing of their C2 infrastructure to ensure accountability.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Surge in Mercenary Spyware Attacks Triggers Mass Apple Security Alerts

Global Surge in Mercenary Spyware Alerts: Apple Targets 110 Countries in Latest Security Push

