Threat reportMalwareTL-2026-3053

Paragon Graphite mercenary spyware: CEO admits no kill switch or misuse visibility; Citizen Lab confirmed 2025 zero-click targeting (CVE-2025-43200) of Italian and European journalists and activists

highACTIVE

Paragon Graphite mercenary spyware (TL-2026-3053), also tracked as Graphite spyware, is a high-severity malware campaign, first published 2026-10-08. It is attributed to Paragon Solutions with medium confidence, affects Apple iOS (iMessage), references 1 CVE (CVE-2025-43200), maps to 5 MITRE ATT&CK techniques (T1437, T1533, T1583.003), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
1Paragon Solutions
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-3053

Threat ID
TL-2026-3053
Also known as
Graphite spyware, Paragon spyware case, Italian Paragon affair
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Paragon Solutions
Attribution confidence
MEDIUM
Motivation
ESPIONAGE
Target sectors
news - media, civil society, human-rights, migrant-rights
Target regions
Europe, italy
Detection rules
9
Indicators of compromise
14

Malware and tooling in Paragon Graphite mercenary spyware

Malware and tooling: Graphite

How Paragon Graphite mercenary spyware works

Paragon Solutions' CEO Andrew Boyd told WIRED (Oct 2026) that the company cannot see how customers use its Graphite spyware and has no kill switch to disable them. Citizen Lab forensically confirmed in 2025 that Graphite was used against journalists and activists in Italy and Europe, including a zero-click iMessage attack on iOS 18.2.1 fixed in iOS 18.3.1 as CVE-2025-43200.

Paragon Solutions Ltd. was founded in Israel in 2019 and sells the Graphite mobile spyware to government customers. Citizen Lab's March 19, 2025 report 'Virtue or Vice? A First Look at Paragon's Proliferating Spyware Operations' described Graphite as a more restrained alternative to NSO Group's Pegasus that surveils messaging apps without taking full control of the phone. It mapped suspected Paragon infrastructure through two certificate fingerprints: Tier 1 victim-facing servers (self-signed certificates with a one-year validity and DNS-only SANs) and Tier 2 customer endpoints (issuer 'Internet Widgits Pty Ltd', often with 'forti.'-prefixed CNs). Suspected customer deployments appeared in Australia, Canada, Cyprus, Denmark, Germany, Israel and Singapore. WhatsApp notified about 90 users on January 31, 2025. Android forensic artifact BIGPRETZEL was found on devices of Mediterranea Saving Humans members Luca Casarini and Giuseppe Caccia, with Graphite infections between 2024-12-22 and 2025-01-31.

Citizen Lab's June 12, 2025 report ('First Forensic Confirmation of Paragon's iOS Mercenary Spyware Finds Journalists Targeted') gave high-confidence attribution of Graphite to the devices of an unnamed prominent European journalist and Ciro Pellegrino of Fanpage.it. Delivery was a zero-click iMessage attack from an iMessage account labelled ATTACKER1 (redacted in the report), seen on both devices. The exploited bug was CVE-2025-43200, which Apple says was mitigated in iOS 18.3.1; the European journalist's device ran iOS 18.2.1. The device contacted the Graphite server 46.183.184.91, rented from VPS provider EDIS Global, which matched the P1 fingerprint until at least April 12, 2025. Apple threat notifications went out on April 29, 2025. Citizen Lab reasons that each Graphite customer has dedicated infrastructure, so ATTACKER1 likely belongs to a single customer, but treats linking the two cases to one operator as an inference.

Italy's parliamentary committee COPASIR (June 5, 2025) acknowledged Graphite use against Casarini and Caccia. Paragon cancelled its Italian contracts after Italian authorities declined a technical verification in the Cancellato case. In March 2026, Italian prosecutors confirmed the hacking of Fanpage.it editor Francesco Cancellato, which Citizen Lab said validated its forensic analysis. On October 1, 2026 WIRED published an interview with new Paragon CEO Andrew Boyd, who said Paragon has no kill switch; its only lever is halting 24-hour support and system updates, which would leave the system ineffective in about 12 hours. He also said Paragon cannot see whom customers target and learns of misuse only from customer admissions or third-party discoveries, and that Italy was 'fired' without an internal investigation. Citizen Lab's John Scott-Railton said Paragon has less oversight, transparency and contractual protection against abuses than NSO Group. Paragon is reportedly owned by AE Industrial Partners and slated to merge with REDLattice, with Boyd listed on the board of a REDLattice parent per SEC filings.

The Citizen Lab page of Oct 8, 2026 is a media summary and names no new technical indicators; the technical indicators here come from the 2025 Citizen Lab reports. Defenders should patch iOS to current releases, enable Lockdown Mode for at-risk users, and treat Apple/WhatsApp/Meta threat notifications as incident triggers.

MITRE ATT&CK techniques used in TL-2026-3053

Command and Control

T1437 Application Layer Protocol

Collection

T1533 Data from Local System

Resource Development

T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.004 Develop Capabilities: Exploits

Initial Access

T1664 Exploitation for Initial Access

Affected products and versions in Paragon Graphite mercenary spyware

  • Apple — iOS (iMessage)
    Vulnerable versions: 18.2.1 (observed compromised); versions before 18.3.1
    Fixed in: 18.3.1
  • Meta — WhatsApp (Android)
    Vulnerable versions: Android builds targeted in the Dec 2024 - Jan 2025 campaign
    Fixed in: Patched server-side/app-side per WhatsApp notification of 2025-01-31

Remediation for Paragon Graphite mercenary spyware

Patches

  • Apple iOS 18.3.1 (CVE-2025-43200)

Immediate actions

  • Update iOS to the latest release (CVE-2025-43200 mitigated in iOS 18.3.1 and later)
  • Enable Apple Lockdown Mode for journalists, activists and other at-risk users
  • Treat Apple, WhatsApp and Meta threat notifications as incident triggers and contact a civil-society forensic team such as Citizen Lab or Amnesty Tech
  • Hunt network logs for the published Graphite infrastructure indicators

Workarounds

  • Lockdown Mode
  • Disable iMessage for users at elevated risk where operationally feasible

Longer-term hardening

  • Keep high-risk users on current OS and messaging app versions
  • Run periodic mobile forensic triage for high-risk users
  • Apply export-control and procurement scrutiny to commercial spyware vendors

CVEs associated with Paragon Graphite mercenary spyware

CVE-2025-43200

Timeline of Paragon Graphite mercenary spyware

  • Paragon Solutions Ltd. founded in Israel (founders include Ehud Barak and Ehud Schneorson); product is the Graphite mobile spyware. Year per Citizen Lab; exact date not stated.
  • Apple sends a threat notification to David Yambio; Citizen Lab finds iOS indicator SMALLPRETZEL (CloudKit activity by appleaccountd on 2024-06-13), not attributed to Paragon.
  • Earliest Graphite (BIGPRETZEL) Android infections of Mediterranea Saving Humans members Luca Casarini and Giuseppe Caccia; infections continue through 2025-01-31.
  • WhatsApp notifies about 90 users, including journalists and civil society, of a Paragon zero-click compromise.
  • Citizen Lab publishes 'Virtue or Vice?' mapping Paragon infrastructure (fingerprints P1-P4) and suspected customer deployments.
  • Apple sends threat notifications to the European journalist and Ciro Pellegrino of Fanpage.it.
  • Italian parliamentary committee COPASIR report acknowledges Graphite use against Casarini and Caccia.
  • Citizen Lab publishes first forensic confirmation of Graphite on iOS: zero-click iMessage attack, CVE-2025-43200, server 46.183.184.91.
  • Italian prosecutors confirm the hacking of journalist Francesco Cancellato; Citizen Lab says this validates its forensic analysis. Day of month not sourced.
  • WIRED publishes interview in which Paragon CEO Andrew Boyd says there is no kill switch and no visibility into customer misuse.
  • Citizen Lab posts 'The Secrets of a US Spyware King' summarizing the WIRED interview.

Sources cited for Paragon Graphite mercenary spyware

Detection coverage for TL-2026-3053

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3053 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats