# Paragon Graphite mercenary spyware: CEO admits no kill switch or misuse visibility; Citizen Lab confirmed 2025 zero-click targeting (CVE-2025-43200) of Italian and European journalists and activists

> Paragon Solutions' CEO Andrew Boyd told WIRED (Oct 2026) that the company cannot see how customers use its Graphite spyware and has no kill switch to disable them. Citizen Lab forensically confirmed in 2025 that Graphite was used against journalists and activists in Italy and Europe, including a zero-click iMessage attack on iOS 18.2.1 fixed in iOS 18.3.1 as CVE-2025-43200.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3053
- **ID:** TL-2026-3053
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Paragon Solutions
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-43200

## Description

Paragon Solutions Ltd. was founded in Israel in 2019 and sells the Graphite mobile spyware to government customers. Citizen Lab's March 19, 2025 report 'Virtue or Vice? A First Look at Paragon's Proliferating Spyware Operations' described Graphite as a more restrained alternative to NSO Group's Pegasus that surveils messaging apps without taking full control of the phone. It mapped suspected Paragon infrastructure through two certificate fingerprints: Tier 1 victim-facing servers (self-signed certificates with a one-year validity and DNS-only SANs) and Tier 2 customer endpoints (issuer 'Internet Widgits Pty Ltd', often with 'forti.'-prefixed CNs). Suspected customer deployments appeared in Australia, Canada, Cyprus, Denmark, Germany, Israel and Singapore. WhatsApp notified about 90 users on January 31, 2025. Android forensic artifact BIGPRETZEL was found on devices of Mediterranea Saving Humans members Luca Casarini and Giuseppe Caccia, with Graphite infections between 2024-12-22 and 2025-01-31.

Citizen Lab's June 12, 2025 report ('First Forensic Confirmation of Paragon's iOS Mercenary Spyware Finds Journalists Targeted') gave high-confidence attribution of Graphite to the devices of an unnamed prominent European journalist and Ciro Pellegrino of Fanpage.it. Delivery was a zero-click iMessage attack from an iMessage account labelled ATTACKER1 (redacted in the report), seen on both devices. The exploited bug was CVE-2025-43200, which Apple says was mitigated in iOS 18.3.1; the European journalist's device ran iOS 18.2.1. The device contacted the Graphite server 46.183.184.91, rented from VPS provider EDIS Global, which matched the P1 fingerprint until at least April 12, 2025. Apple threat notifications went out on April 29, 2025. Citizen Lab reasons that each Graphite customer has dedicated infrastructure, so ATTACKER1 likely belongs to a single customer, but treats linking the two cases to one operator as an inference.

Italy's parliamentary committee COPASIR (June 5, 2025) acknowledged Graphite use against Casarini and Caccia. Paragon cancelled its Italian contracts after Italian authorities declined a technical verification in the Cancellato case. In March 2026, Italian prosecutors confirmed the hacking of Fanpage.it editor Francesco Cancellato, which Citizen Lab said validated its forensic analysis. On October 1, 2026 WIRED published an interview with new Paragon CEO Andrew Boyd, who said Paragon has no kill switch; its only lever is halting 24-hour support and system updates, which would leave the system ineffective in about 12 hours. He also said Paragon cannot see whom customers target and learns of misuse only from customer admissions or third-party discoveries, and that Italy was 'fired' without an internal investigation. Citizen Lab's John Scott-Railton said Paragon has less oversight, transparency and contractual protection against abuses than NSO Group. Paragon is reportedly owned by AE Industrial Partners and slated to merge with REDLattice, with Boyd listed on the board of a REDLattice parent per SEC filings.

The Citizen Lab page of Oct 8, 2026 is a media summary and names no new technical indicators; the technical indicators here come from the 2025 Citizen Lab reports. Defenders should patch iOS to current releases, enable Lockdown Mode for at-risk users, and treat Apple/WhatsApp/Meta threat notifications as incident triggers.

## MITRE ATT&CK

- T1664 Exploitation for Initial Access
- T1587.004 Develop Capabilities: Exploits
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1437 Application Layer Protocol
- T1533 Data from Local System

## Sources

- [The Secrets of a US Spyware King (Citizen Lab, In the Media)](https://citizenlab.ca/the-secrets-of-a-us-spyware-king/)
- [The Secrets of the US Spyware King (WIRED)](https://www.wired.com/story/the-secrets-of-the-us-spyware-king/)
- [First Forensic Confirmation of Paragon's iOS Mercenary Spyware Finds Journalists Targeted (Citizen Lab)](https://citizenlab.ca/research/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/)
- [Virtue or Vice? A First Look at Paragon's Proliferating Spyware Operations (Citizen Lab)](https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/)
- [Italian Prosecutors Confirm Journalist Was Hacked with Paragon Spyware (Citizen Lab)](https://citizenlab.ca/italian-prosecutors-confirm-journalist-was-hacked-with-paragon-spyware/)
- [Italy: New case of journalist targeted with Graphite spyware (Amnesty International)](https://www.amnestyusa.org/press-releases/italy-new-case-of-journalist-targeted-with-graphite-spyware-confirms-widespread-use-of-unlawful-surveillance/)
- [Paragon spyware deployed against journalists and activists, Citizen Lab claims (The Register)](https://www.theregister.com/2025/03/21/paragon_spyx_hacked/)
- [Report on Paragon Spyware (Schneier on Security via Getoto mirror)](https://noise.getoto.net/2025/03/25/report-on-paragon-spyware/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3053
