Graphite is a malware name used in the provided content for two distinct threats. First, it refers to an APT28/Sednit/Fancy Bear espionage implant documented in January 2022 that used the Microsoft Graph API to communicate with a OneDrive account acting as command-and-control. In that campaign, Graphite was deployed against several governments in Europe and Asia through spear-phishing emails delivering an Excel downloader that exploited CVE-2021-40444, followed by a second-stage downloader, Graphite, and then PowerShell Empire. The content also notes that broader hunting for APT28 tooling surfaced Graphite samples alongside SlimAgent, and that shared packaging traits included bad checksums, patched timestamps, 64-bit DLL structure, and "Microsoft Corporation" as the listed company name.
Second, and more prominently in the content, Graphite is the commercial mercenary spyware platform sold by Israel-based Paragon Solutions, founded in 2019. Paragon sells Graphite to government agencies, and the content describes it as no-click or zero-click spyware capable of compromising smartphones without user interaction and accessing messages, calls, geolocation, microphones, and cameras. Reported targeting included about 90 WhatsApp users across more than two dozen countries, including journalists and civil society members. Citizen Lab and WhatsApp linked Android infections to the BIGPRETZEL forensic artifact, while a related iPhone case involved the SMALLPRETZEL artifact, though that iPhone case was not conclusively attributed to Paragon. Citizen Lab later confirmed with high confidence that two journalists, including Ciro Pellegrino, were targeted with Paragon’s Graphite via a sophisticated zero-click iMessage exploit; Apple said the attack was mitigated in iOS 18.3.1 and assigned CVE-2025-43200. Infrastructure associated with Paragon Graphite included servers matching Citizen Lab’s Fingerprint P1, including 46.183.184[.]91. The content associates Graphite deployments or suspected customer use with Italy, Canada, Australia, Cyprus, Denmark, Israel, Singapore, and U.S. government entities including reported use by DEA, ICE, and possible Ontario Provincial Police-linked infrastructure. Confirmed or reported victims in Italy included journalists and migrant-rights or rescue activists, and Italian intelligence agencies AISE and AISI were confirmed Paragon customers in the reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In January 2022, Symantec found the discovery of Graphite—malware that used the Graph API to communicate with a OneDrive account that was acting as a C&C server. | Graphite was deployed in a campaign against several governments in Europe and Asia. Attacks began with spear-phishing emails that delivered an Excel downloader containing a remote code execution exploit (CVE-2021-40444). This led to the installation of a second-stage downloader, followed by Graphite and a secondary payload—PowerShell Empire.
Apple confirms to us that the zero-click attack deployed in these cases was mitigated as of iOS 18.3.1 and has assigned the vulnerability CVE-2025-43200. | Our analysis finds forensic evidence confirming with high confidence that both a prominent European journalist ... and Italian journalist Ciro Pellegrino, were targeted with Paragon’s Graphite mercenary spyware.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we find 2 APT28 samples that are not PixyNetLoader: ... efa5b49bdd086125b2b7d4058d09566f1db5f183c2a6332c597322f85107667a APT28 Graphite
Associated Malware & Tools graphon ... Graphican GoGra remsec_strider BirdyClient Grager graphite
Our analysis finds forensic evidence confirming with high confidence that both a prominent European journalist ... and Italian journalist Ciro Pellegrino, were targeted with Paragon’s Graphite mercenary spyware.
“...only a few exceptions, such as the Graphite malware documented by Trellix in 2021...”
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers analyzed the unnamed journalist’s devices and found that one of them was infected with Graphite, based on forensic evidence showing that the spyware communicated with a server that the researchers had previously established with “high confidence” was part of Paragon’s infrastructure.
Freedom of information requests... revealed that the 5th Floor had by January 2015 met with what was then the U.S. arm of the controversial, then-Israeli cellphone spyware manufacturer NSO Group... Reporting from the New York Times in 2022... noted that the DEA was combating drug trafficking through usage of the Graphite spyware product...
COPASIR said it verified that to use Paragon’s spyware, an operator has to log in with a username and password, and each deployment of the spyware leaves detailed logs.
WhatsApp discovered and mitigated an active Paragon zero-click exploit... We found clear indications that spyware had been loaded into WhatsApp, as well as other apps on their devices.
Graphite can start monitoring a phone — including encrypted messages — just by sending a message to the number. The user doesn't have to click on a link or a message.
logs on the device indicated that it made a series of requests to a server that, during the same time period, matched our published Fingerprint P1.
This led to the installation of a second-stage downloader, followed by Graphite and a secondary payload—PowerShell Empire.
"GoGra ... uses the Microsoft Graph API to interact with a command-and-control (C&C) server hosted on Microsoft mail services..."; "Grager ... used the Graph API to communicate with a C&C server hosted on Microsoft OneDrive"; "Onedrivetools ... authenticates to Microsoft Graph API and downloads the second stage payload from OneDrive... fetching the new commands to execute from a file called cmd"
Paragon makes no-click spyware, which means users do not have to click on any link or attachment to be infected; it is simply delivered to the phone.
Paragon appears to silently load their spyware into the device’s existing legitimate apps and processes, which serve as the spyware’s unwitting hosts.
The Citizen Lab reported “a growing ecosystem of spyware capability” among Ontario police services, after identifying server infrastructure that indicated potential use of Paragon Solutions’ Graphite spyware by the Ontario Provincial Police.
due to the fact that Android has limited logs, as well as “efforts by Paragon to delete traces of the infection,” it may be impossible to confirm that.
ФСБ России объявила об обнаружении масштабной операции иностранных спецслужб, которые использовали вредоносное ПО для слежки за российскими высокопоставленными служащими через мобильные устройства.
The 5th Floor has been most widely criticized for its telephone surveillance programs — particularly its cross-border USTO and AT&T-based domestic Hemisphere/Data Analytical Services programs... Reporting from The Intercept... revealed that the SOD’s bilateral wiretapping arrangements with foreign governments were serving as cover for large-scale NSA wiretapping operations, including full-take audio surveillance... through a program known as MYSTIC.
The researchers analyzed the unnamed journalist’s devices and found that one of them was infected with Graphite, based on forensic evidence showing that the spyware communicated with a server that the researchers had previously established with “high confidence” was part of Paragon’s infrastructure.
The infrastructure appears to be consistent with a dedicated command and control infrastructure (“Tier 1”)... Pivoting to Tier 2: Paragon and Customer Endpoints... we suspected that they might be run directly from Paragon and customer premises.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An APT28-associated tool identified through shared binary characteristics and code packaging habits linked to PixyNetLoader investigations.
Commercial spyware attributed to Paragon Solutions; the content describes potential use by Ontario Provincial Police based on identified server infrastructure.
Commercial spyware attributed to Paragon Solutions; the content describes it as potentially used by Ontario police services based on identified server infrastructure.
Commercial mobile spyware that can compromise smartphones without user interaction and access messages, calls, geolocation, microphone, and camera.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.