Paragon Solutions is an Israeli commercial spyware company associated in the provided content with the Graphite spyware platform. In early 2025, WhatsApp notified roughly 90 users that they had been targeted by Paragon Solutions; many of the targets were journalists and civil society members across Europe. Subsequent forensic analysis confirmed that two notified iOS users, both journalists, were infected with Graphite via a zero-click attack. The content states that Graphite exploited CVE-2025-43200, a logic flaw in iOS, and that maliciously crafted photos or videos shared via iCloud Links could trigger remote code execution without user interaction. The content also states that Paragon’s Graphite platform demonstrates that commercial surveillance vendors now possess iPhone zero-click exploitation capabilities. Reported targeting in the content is focused on journalists and civil society, and more broadly the surrounding reporting places such spyware activity in the context of surveillance against journalists, human rights defenders, political dissidents, critics, and political opponents. Known alias in the provided content: paragon_solutions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Israeli spyware company linked in the content to targeting journalists and civil society members in Europe using Graphite spyware delivered via zero-click attacks.
Paragon Solutions is a commercial surveillance vendor whose Graphite spyware platform uses zero-click vulnerabilities to compromise iOS devices, targeting journalists and high-profile individuals.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.