QuaDream is a private sector offensive actor and commercial spyware vendor known for developing and selling mobile surveillance capabilities. It is associated with the Reign spyware platform and has been discussed alongside other mercenary spyware providers such as NSO Group and Intellexa. Microsoft has tracked QuaDream as DEV-0196 and categorized it within its private sector offensive actor class under the Tsunami family. QuaDream is known for supplying zero-click, zero-day exploitation capabilities against mobile devices, including Apple iOS devices, and has been referenced in the broader context of advanced spyware operations targeting smartphones. Reported capabilities include covert device compromise, surveillance, and theft of passwords and two-factor authentication codes from infected devices. Tradecraft associated with this class of actor includes stealthy initial access via mobile exploit chains, post-exploitation collection, credential theft, and data exfiltration. Like other mercenary spyware vendors, its tooling has been linked to surveillance of high-risk individuals rather than conventional cybercrime or disruptive operations. QuaDream is best understood as a commercial offensive cyber provider rather than a state intelligence service, although such vendors typically operate by supplying governments or government customers. Known aliases and related references include Reign for its spyware platform and Microsoft’s DEV-0196 designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.