News Room
16
Share
mediumOffensive Tools

State-Sponsored Mercenary Spyware in South Asia: A Rising Threat

State-sponsored mercenary spyware is increasingly targeting South Asia, with nation-state actors leveraging commercial offensive tools and exploit brokers to conduct surveillance-as-a-service operations.

₿

Encrygma is selling the entire Full Cyber Weapon Research of State-Sponsored Mercenary Spyware in South Asia: A Rising Threat for ₿ 0.10 BTC. Contact us.

22 March 2026Last updated 22 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Medium
Actor Type:
Nation-State
Geography:
South Asia
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

In recent years, South Asia has witnessed a surge in cyber activities attributed to nation-state actors employing mercenary spyware. These operations involve the use of commercial offensive tools, exploit brokers, and surveillance-as-a-service models to achieve strategic objectives.

Mercenary Spyware and Exploit Brokers

Mercenary spyware refers to surveillance tools developed by private companies and sold to government clients for intelligence and law enforcement purposes. A notable example is Candiru, an Israeli firm that provides spyware capable of exploiting zero-day vulnerabilities across various operating systems and web browsers. Their products, such as "DevilsTongue," enable remote control of target devices, facilitating extensive data exfiltration. (en.wikipedia.org)

Exploit brokers play a crucial role in these operations by discovering and selling zero-day vulnerabilities to entities like Candiru. This collaboration allows for the development of sophisticated spyware capable of compromising a wide range of devices.

Commercial Offensive Tools and Red Team Frameworks

Nation-state actors often utilize commercial offensive tools and red team frameworks to simulate adversary tactics and identify vulnerabilities within their own systems. These tools, while primarily intended for defensive purposes, can be repurposed for offensive cyber operations. The dual-use nature of such tools raises concerns about their potential misuse in cyber espionage campaigns.

Surveillance-as-a-Service

The surveillance-as-a-service model involves the outsourcing of cyber espionage capabilities to private companies. This approach allows nation-state actors to conduct covert operations while maintaining plausible deniability. For instance, the Indian company Appin, founded in 2003, provided hacking services to various clients, including government agencies and private entities. Appin's operations included hacking emails, computers, and phones, as well as monitoring operations and downloading stolen data. (en.wikipedia.org)

Case Study: APT 36's Activities

APT 36, also known as Transparent Tribe, is a Pakistan-based advanced persistent threat group that has conducted cyber espionage against Indian government and military networks. In 2025, APT 36 utilized advanced spyware called DeskRAT to infiltrate Indian systems. Additionally, in November 2025, Pakistani intelligence operatives attempted to compromise Indian security personnel by impersonating senior officials on WhatsApp, leading to the installation of Trojan malware on devices. (en.wikipedia.org)

Conclusion

The integration of mercenary spyware, exploit brokers, and surveillance-as-a-service models by nation-state actors in South Asia signifies a complex and evolving cyber threat landscape. These developments underscore the necessity for robust cybersecurity measures and international cooperation to mitigate the risks associated with state-sponsored cyber espionage.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo