An international initiative known as the Pall Mall Process is moving from government-focused norms to developing opt-in guidelines for the commercial cyber intrusion/spyware industry, amid debate over how to define the market and constrain abuse without eliminating tools used for legitimate purposes such as law enforcement. Participants have been grappling with core design questions including who the rules should apply to, how to draw boundaries between legitimate security research and illicit intrusion activity, and whether the scope should include adjacent capabilities such as reconnaissance tooling.
At a discussion held under Chatham House rules alongside Washington, D.C.-area events, stakeholders from government, industry, and civil society weighed how to incentivize participation and measure compliance, and how to handle vendors with a “checkered past.” Commentary around the effort emphasized that voluntary, non-binding standards may have limited impact without stronger state action, pointing to existing government levers already used to shape the market—such as Entity List designations, financial sanctions, and visa restrictions targeting actors involved in the misuse of commercial spyware.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Paragon Solutions was later acquired by AE Industrial Partners in a deal reportedly valued at $500 million. The acquisition underscored the continued commercial viability of spyware vendors amid international debate over regulation and accountability.
After the Italy-related controversy, Paragon Solutions later received a contract from US Immigration and Customs Enforcement. The development was highlighted in discussion of how governments continue to engage commercial spyware vendors despite abuse concerns.
Paragon Solutions reportedly ended its relationship with the Italian government after its spyware was allegedly used in Italy to target journalists and activists. The case was cited as an example of a spyware vendor trying to present itself as compliant despite controversy over prior use.
At DistrictCon in Washington, D.C., government, industry, and civil society representatives debated what the voluntary standards should cover, including reconnaissance tools, customer due diligence, and possible vendor kill switches. They also discussed how procurement pressure and other incentives might encourage compliance without driving vendors toward non-participating governments.
Participants in the Pall Mall Process moved from government-use rules toward drafting voluntary standards for commercial cyber intrusion vendors. The effort is intended to shape expectations for vendor behavior even though the guidelines would be non-binding.
The international Pall Mall Process initially focused on developing a voluntary code of conduct for how governments should use commercial cyber intrusion tools. This first phase preceded later work on standards aimed directly at the commercial hacking industry.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.