Investigations and legal filings described a growing mercenary spyware market in which private vendors developed and sold intrusion capabilities to government customers, with NSO Group emerging as the best-known example but not the only one. Reporting tied NSO’s Pegasus spyware to attacks on activists, journalists, and government personnel, including the targeting of UAE activist Ahmed Mansoor and more than 1,400 devices via a WhatsApp exploit that reportedly required no answer from the victim. Microsoft, Google, Cisco, GitHub, LinkedIn, VMware, and others backed WhatsApp’s lawsuit against NSO, arguing the company should not receive sovereign immunity for operating as a private offensive cyber actor, while broader reporting said Facebook had identified seven spyware firms targeting roughly 50,000 people across its platforms.
Separate investigations showed the industry stretching beyond NSO into Europe and Asia. Lighthouse Reports linked Italy’s RCS Lab and its Tykelab unit to covert mobile-phone tracking through telecom signaling weaknesses and to Hermit spyware infrastructure, while Citizen Lab and Motherboard connected a fake WhatsApp phishing campaign to Italian vendor Cy4Gate and its Epeius lawful-intercept product. Earlier reporting on Hacking Team and allegations about APT17 selling stolen data underscored how surveillance and intrusion capabilities have been commercialized, repackaged, and marketed across borders, despite repeated scandals, lawsuits, and sanctions aimed at curbing abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
An investigation alleged that Rome-based Tykelab, part of RCS Lab, had conducted large-scale covert mobile-phone tracking worldwide by exploiting telecom signaling vulnerabilities and sending tens of thousands of tracking packets through dozens of networks.
Takeover disclosures made to shareholders revealed that Tykelab was part of RCS Lab, a relationship the investigation said had remained undisclosed until December.
Reuters reported that U.S. State Department officials had been hacked using Pegasus, marking a significant allegation that the spyware had affected American government personnel.
The United States imposed sanctions on NSO Group, escalating official pressure on the spyware vendor after years of abuse allegations.
Citizen Lab and Motherboard uncovered an iPhone phishing campaign impersonating WhatsApp and tied its infrastructure to Italian surveillance vendor Cy4Gate, including domains, certificates, and an Epeius-branded login portal.
New reports in mid-2021 alleged abuse of NSO Group's Pegasus spyware involving Western government contexts, broadening scrutiny beyond earlier cases centered on authoritarian misuse.
Microsoft, joined by Cisco, GitHub, Google, LinkedIn, VMware, and the Internet Association, filed an amicus brief opposing NSO Group's attempt to claim sovereign immunity in the WhatsApp litigation.
Citizen Lab and later reporting said the United Arab Emirates targeted human rights activist Ahmed Mansoor using NSO Group's Pegasus spyware. The case became an early high-profile example of Pegasus being used against a dissident.
Researchers later found fake domains attributed to RCS Lab that were purchased as early as 2015, suggesting the company may have been running mobile hacking infrastructure for years.
Hacking Team was hacked in 2015, and the leaked internal emails later exposed dealings including the failed Grenada procurement attempt. The breach also contributed to the company's later loss of business and export ability.
The Italian firm Hacking Team became a major public example of the hacker-for-hire industry, amid accusations that it sold untraceable spyware to dozens of countries without regard for human rights or privacy abuses.
Leaked Hacking Team documents described an October 31, 2013 letter presenting Jan Marsalek as a Grenada representative interested in Hacking Team's smartphone interception platform, followed by a reported November 27 meeting in Milan. Subsequent reporting said the letter was fraudulent and the deal never went through.
Apple filed suit against NSO Group, adding to the legal pressure already created by Facebook's litigation over Pegasus-related abuse allegations.
Facebook reported that seven hacker-for-hire firms had targeted about 50,000 people on its platforms, identifying four Israeli companies as well as firms from China, India, and North Macedonia.
Citizen Lab reporting cited by Microsoft said Pegasus was used between July and August of that year to hack 36 phones belonging to Al Jazeera journalists, producers, anchors, and executives.
Intrusion Truth alleged that APT17 not only hacked Western targets but also circulated a price list within China's hacking community offering stolen data for sale, including information from Chinese victims.
WhatsApp brought a legal case against NSO Group alleging Pegasus was used via WhatsApp to compromise more than 1,400 mobile devices, including those of journalists and human rights defenders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
lighthousereports.nl
Open sourcetechnologyreview.com
Open sourcetechnologyreview.com
Open sourcevice.com
Open sourceblogs.microsoft.com
Open sourcevice.com
Open sourceintrusiontruth.wordpress.com
Open sourcecitizenlab.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.