Demo

Graphite is a powerful commercial spyware product capable of entering a smartphone without its owner clicking a link, opening an attachment or knowingly downloading anything.

Developed by Paragon Solutions, the technology has been connected to surveillance targeting journalists and immigration activists in Europe. U.S. Immigration and Customs Enforcement also holds a $2 million contract with Paragon, raising questions about how American authorities may use the technology.

How Graphite Secretly Compromises Phones

Graphite belongs to the same category of commercial surveillance technology as Pegasus, the better-known spyware developed by NSO Group. Both are classified as mercenary spyware, meaning private companies develop and sell them to government intelligence and law enforcement agencies.

The two products come from separate companies, although both provide government customers with methods of secretly accessing targeted phones.

Paragon has reportedly designed Graphite primarily to retrieve information from messaging applications rather than assume complete control of every phone function. Once installed, it can potentially collect information from applications such as WhatsApp and Signal, even though those services use end-to-end encryption.

Encryption protects a message while it travels between devices. It does not prevent spyware operating inside one of those devices from reading the message after the application decrypts it. Graphite can therefore obtain readable messages without directly breaking WhatsApp or Signal’s encryption system.

The most dangerous infections require no mistake by the target. A zero-click attack works because phones automatically inspect incoming messages and files before displaying them.

An attacker sends specially designed data that takes advantage of a hidden flaw in that process. When the phone examines it, the flaw allows the data to run commands and place spyware inside legitimate applications. Graphite can then send messages and other private information to the operator without the owner seeing or opening anything.

Researchers have confirmed Graphite attacks through WhatsApp and iMessage, although the complete method remains secret.

Citizen Lab helped WhatsApp identify and block an active Graphite zero-click exploit in late 2024. WhatsApp warned approximately 90 users in January 2025 that Paragon’s spyware had targeted their accounts. The recipients included journalists and civil society figures in more than 20 countries.

Journalists and Activists Targeted

Researchers examined Android phones belonging to several people who received the WhatsApp warnings. They found evidence indicating that Graphite had loaded spyware components into WhatsApp and other applications on the devices of Italian immigration activists Luca Casarini and Giuseppe Caccia. Italian journalist Francesco Cancellato also received a warning from WhatsApp.

Italian prosecutors later provided independent confirmation of those infections. In March 2026, prosecutors in Rome and Naples announced that a technical report found spyware traces on the phones of Cancellato, Casarini and Caccia, all dating to the early hours of Dec. 14, 2024.

Investigators found operations against Casarini and Caccia on the Paragon server used by Italy’s domestic intelligence agency, but no corresponding record for Cancellato, leaving whoever infected the journalist’s phone unidentified.

Another investigation provided the first forensic confirmation that Graphite could target Apple devices. Researchers found that the spyware had successfully compromised an unnamed European journalist’s iPhone in January and February 2025. They also determined that an operator targeted Italian journalist Ciro Pellegrino using the same iMessage account associated with the first case.

The infection exploited a previously unknown iMessage vulnerability and would not have been visible to the target. Apple fixed the vulnerability in iOS 18.3.1.

Italy’s parliamentary intelligence committee later confirmed that Italian agencies used Graphite to monitor Casarini, Caccia and other immigration activists. The committee described that surveillance as legally authorized and related to immigration and national security matters. It concluded that Italian intelligence agencies had not used Graphite against Cancellato.

Paragon and Italian officials offered conflicting accounts of the resulting dispute. The company said it terminated its Italian contracts after authorities declined an offer to examine whether Graphite had been used illegally against Cancellato. Italian officials said the termination was mutual and allowing a foreign private company to inspect intelligence records would have exposed classified information.

A Spyware Dashboard Appears on LinkedIn

Graphite also attracted attention in February 2026 after a Paragon general counsel posted a photograph on LinkedIn with the spyware’s control panel visible on a large screen in the background. The post was quickly deleted, but cybersecurity researchers preserved the image.

The dashboard displayed a Czech telephone number identified as “Valentina,” interception records dated Feb. 10 and categories for applications, accounts and media. Researchers identified icons or interfaces apparently associated with WhatsApp, Signal, Telegram and LINE. The screen also appeared to show the interception’s status and a warrant expiration field.

Paragon’s Claims of Responsible Surveillance

Paragon was established in Israel in 2019 with backing from former Israeli Prime Minister Ehud Barak. Its founders also included Ehud Schneorson, a former commander of Israel’s Unit 8200 military intelligence division. In December 2024, Florida-based private equity firm AE Industrial Partners reportedly agreed to acquire Paragon for at least $500 million.

Corporate records later examined by Citizen Lab showed that Paragon’s shares transferred to a U.S. parent company on Dec. 13, 2024. Coincidentally, forensic evidence dates the infections of the Italian journalist and activists to the early hours of Dec. 14, one day after the share transfer.

Paragon has promoted itself as a more responsible surveillance vendor than companies previously connected to spyware abuses. It says it sells its technology only to vetted government agencies in democratic countries and prohibits customers from unlawfully targeting journalists or civil society figures.

The Italian cases exposed the limits of relying on contractual restrictions. A spyware company may threaten to disconnect a customer, but the public usually cannot see the warrants, target lists, audit records or evidence used to justify individual surveillance operations.

Victims may not know that anyone accessed their phones unless a technology company detects the attack or researchers find surviving forensic evidence.

Ehud Barak
Former Israeli Prime Minister Ehud Barak helped found Paragon Solutions, the company behind Graphite spyware. (Credit/Al Jazeera).
Credit: Al Jazeera

ICE’s $2 Million Paragon Contract

ICE signed a $2 million contract with Paragon in September 2024. The public contract summary did not identify Graphite by name or disclose the surveillance capabilities ICE planned to obtain. Officials initially imposed a stop-work order while the government reviewed whether the agreement complied with a 2023 executive order restricting the use of commercial spyware associated with security or human rights risks.

The government lifted the stop-work order in August 2025, allowing the ICE contract to proceed. Neither ICE nor Paragon publicly explained what safeguards would govern its use, who could become a target or whether the agency would use the technology inside the United States.

Graphite can give investigators access to communications they could not obtain through conventional searches. It can also place a journalist, activist or political opponent under surveillance without leaving any obvious warning. Once governments acquire that capability, promises from the manufacturer offer little protection.

Read the full article here

Share.
© 2026 Gun USA All Day. All Rights Reserved.