Tracking & Law Enforcement Amnesty Reveals Cellebrite Zero-Day Android Exploit on Serbian Student Activist Amnesty International publishes technical details on zero-day vulnerabilities exploited by Cellebrite’s mobile forensic tools to spy on a Serbian student activist. Ryan NaraineFebruary 28, 2025
Artificial Intelligence OpenAI Bans ChatGPT Accounts Used by Chinese Group for Spy Tools OpenAI has banned ChatGPT accounts used by Chinese threat actors, including ones leveraged for the development of spying tools. Eduard KovacsFebruary 24, 2025
Mobile & Wireless Italian Government Denies It Spied on Journalists and Migrant Activists Using Paragon Spyware The Italian government denied it hacked seven cellphones with military-grade surveillance technology from Paragon Solutions. Associated PressFebruary 12, 2025
Malware & Threats FireScam Android Malware Packs Infostealer, Spyware Capabilities The FireScam Android infostealer monitors app notifications and harvests credentials and financial data and sends it to a Firebase database. Ionut ArghireJanuary 3, 2025
Government Android Zero-Day Exploited in Spyware Campaigns, Amnesty International Points to Cellebrite Israeli forensics firm Cellebrite has been linked to an Android zero-day used to secretly install spyware on Serbian journalists' phones. Ryan NaraineDecember 16, 2024
Malware & Threats Mobile Surveillance Tool EagleMsgSpy Used by Chinese Law Enforcement Lookout details EagleMsgSpy, a surveillance tool used by Chinese law enforcement to collect data from Android devices. Ionut ArghireDecember 12, 2024
Mobile & Wireless Thai Court Dismisses Activist’s Suit Against Israeli Spyware Producer Over Lack of Evidence A Thai court dismissed a lawsuit brought by Jatupat Boonpattararaksa which alleged spyware made by NSO Group was used to hack his phone. Associated PressNovember 21, 2024
Malware & Threats LightSpy Spyware Operation Expands to Windows The Chinese APT behind the LightSpy iOS backdoor has expanded its toolset with DeepData, a modular Windows-based surveillance framework. Ionut ArghireNovember 15, 2024
Mobile & Wireless Recent Version of LightSpy iOS Malware Packs Destructive Capabilities A newer version of the LightSpy malware for iOS includes over a dozen new plugins, many with destructive capabilities. Eduard KovacsOctober 30, 2024
Tracking & Law Enforcement US Sanctions Intellexa Executives as Surveillance Spyware Crackdown Expands Sanctions target five individuals linked to Intellexa Consortium as the US government expands its crackdown on commercial spyware merchants. Ryan NaraineSeptember 16, 2024
Nation-State Predator Spyware Resurfaces With Fresh Infrastructure Recorded Future observes renewed Predator spyware activity on fresh infrastructure after a drop caused by US sanctions. Ionut ArghireSeptember 9, 2024
Malware & Threats Thousands Download New Mandrake Android Spyware Version From Google Play Five Android applications containing the Mandrake spyware have been downloaded over 32,000 times from Google Play since 2022. Ionut ArghireJuly 30, 2024
Tracking & Law Enforcement Spain Reopens a Probe Into a Pegasus Spyware Case After a French Request to Work Together The judge with Spain’s National Court said there is reason to believe that the new information provided by France can “allow the investigations to... Associated PressApril 23, 2024
Government Google Links Over 60 Zero-Days to Commercial Spyware Vendors More than 60 of the Adobe, Google, Android, Microsoft, Mozilla and Apple zero-days that have come to light since 2016 attributed to spyware vendors. Eduard KovacsFebruary 6, 2024
Tracking & Law Enforcement US to Roll Out Visa Restrictions on People Who Misuse Spyware to Target Journalists, Activists Officials said the visa restriction policy can apply to citizens of any country found to have misused or facilitated the malign use of spyware Associated PressFebruary 5, 2024
Mobile & Wireless At Least 30 Journalists, Lawyers and Activists Hacked With Pegasus in Jordan, Forensic Probe Finds Pegasus spyware from NSO Group was used in Jordan to hack the cellphones of journalists, lawyers, human rights and political activists. Associated PressFebruary 1, 2024
Data Protection Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat iVerify, a seed-stage startup spun out of Trail of Bits, ships a mobile threat hunting platform to neutralize iOS and Android zero-days. Ryan NaraineDecember 6, 2023
Privacy & Compliance France, UK Seek Greater Regulation of Commercial Spyware France and the UK are calling for greater regulation of commercial surveillance software in the wake of recent Pegasus and Predator spyware scandals. AFPNovember 10, 2023
Malware & Threats Spyware Caught Masquerading as Israeli Rocket Alert Applications A threat actor targets Israelis with spyware masquerading as an Android application for receiving rocket alerts. Ionut ArghireOctober 16, 2023
Mobile & Wireless Android’s October 2023 Security Updates Patch Two Exploited Vulnerabilities The October 2023 security update for Android patches two vulnerabilities exploited in attacks, both likely linked to spyware vendors. Ionut ArghireOctober 3, 2023