Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
privacy-surveillance-policytrade-export-controlzero-day-acquisitionstate-sponsored-espionage

ICE Confirms Paragon Spyware Use as U.S. Commercial Spyware Policy Faces Scrutiny

Updated 17d agoFirst seen Mar 13, 20268 sources

U.S. Immigration and Customs Enforcement confirmed to lawmakers that it bought and used Paragon Solutions spyware, including Graphite, in investigations tied to drug trafficking, fentanyl networks, and other organizations using encrypted communications. Acting ICE Director Todd Lyons said the deployment complied with constitutional requirements and the 2023 executive order restricting government use of commercial spyware, but House Democrats including Rep. Summer Lee said ICE had not provided enough documentation, safeguards, or oversight to justify such invasive surveillance. The disclosure followed the reactivation of ICE’s Paragon contract after an earlier suspension for review, and came amid wider controversy over reports linking Paragon spyware to targeting of journalists and activists.

The admission intensified concerns that U.S. policy may be softening toward the commercial spyware industry even as evidence mounts that these vendors are driving serious cyber abuse. Reporting and research cited growing alarm over the lifting of sanctions on Intellexa executives, new U.S.-linked ownership of NSO Group and Paragon, and the expanding role of brokers, resellers, and other intermediaries that help spyware vendors evade export controls and obscure supply chains. Analysts also noted that Google attributed more zero-day exploitation to commercial surveillance vendors than to traditional state-backed groups in 2025, while lawmakers pressed for briefings on federal spyware use and U.S. investment in firms long associated with abuses involving Pegasus, Predator, and related surveillance tools.

Share:
ICE Confirms Paragon Spyware Use as U.S. Commercial Spyware Policy Faces Scrutiny
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 7, 20262mo ago

Rep. Summer Lee seeks Commerce briefing on spyware use

Rep. Summer Lee asked the Commerce Department to brief Congress on federal use of commercial spyware and on U.S. investment in spyware vendors, citing concerns about the administration's posture toward the industry.

One House Democrat is pressing Commerce on the government’s spyware use | CyberScoop
Apr 2, 20263mo ago

House Democrats criticize ICE spyware deployment

Three House Democrats—Summer Lee, Shontel Brown, and Yassamin Ansari—publicly criticized ICE's confirmed use of Paragon spyware, arguing the agency had not provided sufficient documentation, safeguards, or meaningful oversight.

ICE says it bought Paragon's spyware to use in drug trafficking cases | TechCrunch

ICE confirms use of Paragon spyware

ICE confirmed to lawmakers that it bought and used Paragon Solutions spyware in investigations involving drug trafficking and other targets using encrypted communications, saying the use complied with constitutional requirements and applicable policy restrictions.

ICE says it bought Paragon's spyware to use in drug trafficking cases | TechCrunch
Mar 18, 20263mo ago

Atlantic Council publishes spyware intermediaries report

The Atlantic Council published an issue brief examining how brokers, resellers, infrastructure providers, and other intermediaries enable proliferation in the offensive cyber capabilities and spyware market while obscuring accountability.

Mythical Beasts: Investigating the role of intermediaries in the proliferation of offensive cyber capabilities - Atlantic Council
Mar 11, 20264mo ago

OMB rescinds federal software supply chain guidance

A recent OMB memo rescinded earlier Biden administration federal software supply chain guidance, making mechanisms such as secure software development attestations and SBOM requests optional rather than durable requirements.

If consequences matter, they should apply to vendors, too | CyberScoop
Mar 6, 20264mo ago

Executive order targets cyber-enabled fraud

On March 6, the U.S. government issued an executive order aimed at raising costs for cybercriminals through coordination, disruption, prosecutions, intelligence sharing, resilience measures, and diplomatic pressure on states that shelter such operations.

If consequences matter, they should apply to vendors, too | CyberScoop
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

33 LINKEDOpen in app
Affected products
1 linked
Whatsapp
Organizations
27 linked
Paragon SolutionsNSO GroupMeta PlatformsIntellexaBloombergHacking TeamGooglePassitoraPalantir TechnologiesTechCrunchBlack DuckSonatypeOperation ZeroRecorded FutureDark ReadingAtlantic CouncilQuaDreamCyberScoopZerodiumGRAPHITEAE Industrial PartnersRCS LabCOSEINCInReach Technologies LimitedToru Group LimitedVASTechMATIC
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ICE Confirms Paragon Spyware Use as U.S. Commercial Spyware Policy Faces Scrutiny | Mallory