Citizen Lab has released a recent report regarding Paragon’s spyware:
Key Insights:
- Introducing Paragon Solutions. Established in Israel in 2019, Paragon Solutions markets spyware known as Graphite. The firm sets itself apart by asserting that it has measures in place to avert the types of spyware misconduct for which NSO Group and similar firms are infamous.
- Examination of Paragon Spyware Infrastructure. Following a lead from a partner, we delineated the server infrastructure that we associate with Paragon’s Graphite spyware tool. We pinpointed a group of suspected Paragon implementations, including locations in Australia, Canada, Cyprus, Denmark, Israel, and Singapore.
- Uncovering a Potential Canadian Client of Paragon. Our inquiry revealed possible connections between Paragon Solutions and the Ontario Provincial Police in Canada, along with evidence of an expanding network of spyware capabilities among police services in Ontario.
- Assisting WhatsApp in Identifying a Zero-Click. We provided our findings on Paragon’s infrastructure to Meta, who indicated that the information was crucial for their ongoing investigation into Paragon. WhatsApp successfully detected and neutralized an active Paragon zero-click exploit, subsequently alerting over 90 individuals believed to be targeted, including members of civil society in Italy.
- Android Forensic Examination: Italian Group. We conducted a forensic analysis of several Android devices belonging to Paragon targets in Italy (an acknowledged user of Paragon) who were alerted by WhatsApp. We discovered definitive signs that spyware had infiltrated WhatsApp, along with other applications on their devices.
- A Related Instance of iPhone Spyware in Italy. We scrutinized the iPhone of an individual closely tied to confirmed Android Paragon targets. This person received a notification of a threat from Apple in November 2024 but did not receive any notification from WhatsApp. Our examination indicated an attempt to compromise the device with new spyware in June 2024. We relayed the specifics to Apple, who confirmed that they had addressed the vulnerability in iOS 18.
- Additional Surveillance Technology Used Against the Same Italian Group. We also highlight the warnings issued by Meta in 2024 to several individuals within the same organizational cluster, including a Paragon target, indicating a need for further investigation into other surveillance technologies employed against these individuals.