Reign is a commercial mobile spyware platform developed by the Israeli vendor QuaDream (also referenced as Quadream in the source material). The provided content identifies it as spyware targeting Apple iOS devices and explicitly describes it as a zero-click threat. Reign is repeatedly grouped with other high-end mercenary spyware families such as NSO Group’s Pegasus and Intellexa’s Predator, indicating use in targeted surveillance operations. The content also notes that in 2017 Quadream established InReach Technologies Limited as a reseller created to promote products such as Reign outside Israel, reportedly to bypass EU dual-use export restrictions. Reign is mentioned in the context of forensic detection on iOS devices, including use of Amnesty International’s Mobile Verification Toolkit and the iShutdown method for identifying signs of spyware infection. High-confidence details in the provided material are limited; no specific exploit chain, persistence mechanism, command-and-control infrastructure, or indicators of compromise unique to Reign are given in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
With system access, intermediaries are able to collect, exploit, extract, intercept, retrieve, alter, delete, or transmit content.
Intermediaries are fundamentally different than other entities that operate within the marketplace for OCC. Intermediaries are largely found as partners within the OCC supply chain, complimenting product development through vulnerability research to complete exploit chains or as auxiliary support during technology deployment.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial iOS spyware product from QuaDream listed as supporting zero-click attacks.
Spyware product from Quadream discussed in the context of reseller-facilitated international sales.
Mercenary spyware referenced as another spyware family excluded during forensic analysis of the iPhone case.
Referenced as an example of targeted spyware infecting iOS devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.