Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatinternet-facing-service-vulnerabilityprivacy-surveillance-policy

WhatsApp Spyware Campaign Linked to Paragon Triggers Italy Contract Fallout

Updated 1mo agoFirst seen May 25, 202611 sources

WhatsApp said it disrupted a zero-click spyware campaign that targeted about 90 users, including journalists and civil society members across more than two dozen countries, and linked the activity to Israeli spyware maker Paragon. The company said attackers used malicious PDF files sent through WhatsApp groups to compromise devices, patched the attack path, notified affected users, and sent Paragon a cease-and-desist letter. Researchers at Citizen Lab said they had also observed Paragon using the same vector, marking one of the first public cases tying the company to alleged surveillance of journalists and activists.

The disclosure escalated into a political dispute in Italy after journalist Francesco Cancellato was identified among the targets. Paragon said it terminated contracts with Italian government customers after Rome refused its help in determining whether its Graphite spyware had been used unlawfully, while Italian officials said broader access to spyware logs would have exposed sensitive intelligence information and described the suspension as mutual. Italy’s parliamentary committee COPASIR said there was no evidence that intelligence agencies targeted Cancellato, though it confirmed the agencies were Paragon customers and found that some other individuals had been lawfully surveilled in investigations, intensifying scrutiny of Paragon’s claims that it operates as a more responsible spyware vendor.

Share:
WhatsApp Spyware Campaign Linked to Paragon Triggers Italy Contract Fallout
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Oct 18, 20258mo ago

US court bars Paragon from targeting WhatsApp users

A US court ordered Israeli spyware firm Paragon not to target WhatsApp users, marking a new legal action stemming from the earlier spyware campaign linked to the platform. The ruling represents a judicial escalation beyond WhatsApp's prior cease-and-desist and technical mitigations.

US court bars Israeli spyware firm from targeting WhatsApp users | Cybersecurity News | Al Jazeera
Sep 3, 202510mo ago

EFF says ICE used Paragon spyware

The Electronic Frontier Foundation published a statement asserting that US Immigration and Customs Enforcement used Paragon Solutions malware. This introduced a new alleged government deployment of Paragon spyware beyond the previously documented Italian cases.

EFF Statement on ICE Use of Paragon Solutions Malware | Electronic Frontier Foundation
Jun 9, 20251y ago

Paragon says it ended Italian contracts over refusal to investigate journalist attack

Paragon said it terminated contracts with Italian government customers after the government refused the company's help in determining whether its Graphite spyware had been used unlawfully against Francesco Cancellato. Italian government sources disputed Paragon's account, saying the suspension and termination were mutual and that sharing logs would have exposed sensitive intelligence data.

Apr 29, 20251y ago

COPASIR says Italian intelligence bought Paragon spyware but denies targeting Cancellato

Italy's parliamentary committee COPASIR concluded there was no evidence that journalist Francesco Cancellato had been targeted by intelligence agencies AISI or AISE, while confirming both agencies were Paragon customers. COPASIR also said some other individuals were lawfully targeted in investigations tied to alleged illegal immigration and found no evidence of surveillance against priest Mattia Ferrari.

Jan 31, 20251y ago

Italian spyware scandal expands after victim identification and scrutiny of Paragon

Following WhatsApp's notifications, journalist Francesco Cancellato was identified among the targets, helping trigger broader scrutiny in Italy over possible misuse of Paragon's Graphite spyware. The case drew attention because Paragon had marketed itself as a more responsible spyware vendor.

WhatsApp blocks attack path, notifies victims, and sends Paragon a cease-and-desist

After detecting the campaign, WhatsApp deployed a fix to block the PDF-based attack vector, directly notified affected users, and sent spyware maker Paragon a cease-and-desist letter. This marked the first public reporting linking Paragon to a campaign allegedly targeting journalists and civil society.

WhatsApp says Paragon spyware campaign targeted users in December

WhatsApp said a spyware campaign using Paragon infrastructure targeted about 90 users, including journalists and civil society members, during December 2024 across more than two dozen countries. The attack reportedly used malicious PDF files sent in WhatsApp groups to compromise targets in a zero-click manner.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.