threat_intelligence3122 wordsRead on Huntaegis

The Secrets of the US Spyware King

Spyware maker Paragon Solutions has long positioned itself as the good guy in an industry seemingly filled with bad ones, vowing to never sell its mobile spyware to authoritarian regimes or ones with poor human rights records. It also promises to cut off any customer caught misusing its products against journalists, dissidents, or other non-legitimate targets. Yet weeks after Paragon, then Israeli-owned, was acquired by the US equity firm AE Industrial Partners in December 2024 and merged with REDLattice—an American offensive cyber firm owned by AE that this week announced plans to go public—WhatsApp alleged that Paragon’s Graphite spyware was used to infect the phones of more than 60 individuals in more than 20 countries, including journalists and activists. Most of the targets were not identified, but the University of Toronto’s Citizen Lab named two journalists and two activists in Italy. Italian authorities denied misuse. Paragon and its new US owners, despite their zero-tolerance policy for customer abuse of their software, initially declined to comment on the allegations, and reportedly was exploring potential legal action against WhatsApp after the company sent a cease-and-desist letter to Paragon. Within a week, however, Paragon had canceled the two contracts it had with Italy’s domestic and foreign intelligence agencies. From the outside, it seemed Paragon must have conducted an investigation and verified the allegations before canceling the contracts. But Paragon and RedLattice’s new CEO, Andrew Boyd, now says in an exclusive and surprisingly candid interview with WIRED that the company simply “fired” Italy because it “just was not worth it, from a risk perspective, to maintain the relationship” following the allegations. In other words, there was no Paragon investigation and no interest in conducting one to determine if the allegations were true—Italian government investigators concluded they were not. Paragon didn’t even follow up with WhatsApp or Citizen Lab to obtain details about the alleged abuse and determine if any contracts in the other countries named by WhatsApp should be canceled as well. More damning, according to critics, is what Boyd revealed next: Paragon has no technical way to know if customers misuse its software, because it can’t see who customers target or the data they extract from targeted devices. It can only learn about misuse if customers admit to it or third parties uncover it. He says WhatsApp and Citizen Lab did the company a great service when they exposed the alleged misuse last year. Paragon also doesn’t have a “kill switch” to disable customers when misuse occurs. All they can do is halt customers’ 24-hour support and system “updates.” But Boyd says the updates, the nature of which he won’t specify, are frequent and essential to using the spyware, and without them the system is rendered ineffective in about 12 hours. “Things start falling apart quite quickly,” he says. Boyd’s comments mark the first time a Paragon executive has spoken in detail about the secretive company or its handling of the Italian affair. He agreed to speak with WIRED now because he says more public discussion is needed about the offensive cyber industry and what it means for a US company to operate responsibly in this space. Prior to the interview, REDLattice founder John Ayers wrote in an email that they were “not looking for a favorable write-up.” “If the honest assessment is still damning, that's a conversation we're prepared to have,” he wrote. But Boyd’s admissions reveal that despite priding itself on being better than competitors, Paragon/RedLattice has less oversight and accountability than its most significant one—NSO Group, the Pegasus spyware maker, which has been excoriated for selling its tool to Saudi Arabia and other countries with poor human rights records. According to NSO’s transparency reports, which the company began publishing in recent years in response to criticism, it sets up infrastructure and portals that customers use to infect targets and, like Paragon, can’t see who customers target or detect misuse. But it claims it does have a kill switch to disable a customer’s access to the spyware if allegations of misuse arise, and NSO says its systems keep “tamper-proof” logs to record user activity. Customers are contractually obligated to provide these to NSO if allegations of misuse occur or else face “immediate suspension.” By contrast, Boyd says Paragon customers can enable logging on some systems if they opt to, but Paragon has no access to the logs, nor does it want access. Instead, he says, government oversight bodies can use the logs to investigate allegations of misuse among their agencies, as an Italian parliamentary committee did last year in the case of the Citizen Lab allegations. However, this raises the possibility that a government investigator could lie about misuse if they uncover it in logs. Rather than see Paragon’s lack of access to logs as an accountability problem, however, Boyd describes it as a selling point: No one would buy their products if the company could see a customer’s sensitive targeting information or logs that contain it. “There's a balancing act between privacy and security and being able to ensure that our customers are using these things correctly,” Boyd says. “And I think we've landed on the best balance.” That balance is achieved mostly through careful vetting of customers, he says, and rejecting any country that might be prone to abusing the spyware. John Scott-Railton, senior researcher at Citizen Lab, which has tracked government misuse of commercial spyware for years, calls the revelations astonishing and the lack of mandatory logging “reckless.” “What Paragon is saying in several substantial ways means [it has] less oversight, less transparency, less contractual protection against abuses than NSO Group,” he says. “It’s exactly the opposite of the picture that Paragon has painted for itself for years. The CEO admitting that his customers won’t tolerate oversight is refreshing honesty: Accountability is bad for business. And it signals to lawmakers and regulators that the spyware industry cannot be trusted to self-regulate." Scott-Railton also finds it ironic that Paragon relies on Citizen Lab and others to uncover customer misuse when Paragon actively works to hide its spyware on infected devices and prevent discovery—which inherently includes potential misuse. “We only find a very, very, very small subset [of infections], and the total numbers are always larger,” Scott-Railton says. “These companies spend millions trying to hide from us.” US senator Ron Wyden tells WIRED that surveillance tools that lack oversight and transparency are “inevitably abused.” “It’s easy to claim your powerful hacking tool isn’t being misused if you go out of your way to ensure you don’t know how customers use it,” Wyden says. “The fact that Paragon refuses to audit use of its tool, or even attempt to match the work of a small team of researchers at the Citizen Lab is a massive red flag.” Israeli Intelligence Roots Paragon was launched in 2019 by Israeli Brigadier General Ehud Schneorson, former commander of the Israeli military’s signals intelligence group, Unit 8200. He cofounded it with three other 8200 veterans and former Israeli Prime Minister Ehud Barak. Two years later, the company reportedly had no customers but was developing Graphite and hoping to conquer the lucrative US market. But then the US government began cracking down on foreign spyware companies after NSO’s Pegasus and Candiru’s DevilsTongue tools were misused by their customers against government workers, journalists, dissidents, activists, and academics. The US Commerce Department sanctioned both companies in 2021, and the Israeli government drastically cut the number of countries to which Israeli firms could sell spyware—from 102 countries to 37, excluding Saudi Arabia, the UAE, Morocco and Mexico. Over a year later, the Biden administration and Congress imposed guardrails making it difficult for the US government to purchase foreign-made commercial spyware if it posed a national security risk or could be misused by foreign governments. By then, Paragon reportedly already had a contract with the Drug Enforcement Agency to combat drug traffickers outside the US, but otherwise could not “make any substantial headway” in the US, Boyd says. So the company began looking for a US buyer to overcome its foreign-ownership handicap. In December 2024, AE acquired it for $900 million. The result is a company that is now American on paper, but is still effectively Israeli. Paragon is a RedLattice company—though Paragon has no working website, and the RedLattice website currently doesn’t mention Paragon—but, according to Boyd, it retains its name and offices in Israel, where it has more than 600 employees. Any Paragon-built products still require licensing approval from the Israeli government to sell abroad, while RedLattice-made products sold to non-US customers are governed by US International Traffic in Arms Regulations. Nonetheless, the US acquisition has served as an end-run around foreign-ownership guardrails. Once the AE deal closed, Boyd says, “everybody started talking” to them about Paragon products, and Paragon began looking to hire 150 new workers to handle its expected new business. Ayers, the REDLattice founder, told WIRED in an email that prior to acquisition, REDLattice and AE spent more than two years in discussion with US and allied governments and “didn't move without their buy-in.” But asked whether the government pushed back on the acquisition, Boyd says there were no objections, and no one imposed conditions or governance requirements on them either. “The US government in any form [was] never going to formally say … we approve this acquisition,” he says. “But they didn't have any discomfort with it. … If the [National Security Council] said, ‘this would be a colossally bad idea,’ we probably wouldn't have gone through with it.” Less than a year after Paragon merged with REDLattice, NSO Group and Candiru copied their savvy acquisition move. A US investment group acquired controlling ownership of NSO and appointed David Friedman, former US ambassador to Israel under President Donald Trump, as executive chairman. Candiru was acquired by the US-based Integrity Partners. Now all three companies are vying for US contracts. Boyd, who became CEO of RedLattice and Paragon eight months after the acquisition, gives the companies an edge in the US market. As a former military intelligence officer, State Department diplomat, and director of the CIA’s Center for Cyber Intelligence until retiring in 2023, he has many US government, military, and intelligence community connections to help secure contracts. During the interview, Boyd was open with many of WIRED’s questions, but also inexplicably opaque with others. He wouldn’t even, for example, confirm that Graphite is the name of a product the company sells or say how many products the combined companies possess. He says only that before the acquisition, Paragon had fewer than five products and together they now have between five and 10. Some of these do “over-the-horizon” data collection (by hacking devices and systems remotely) while others require physical access to targeted devices. He bristles at calling the tools “spyware,” though. He considers them “defensive” tools since, broadly speaking, they help defend against national security and criminal threats. But in truth, they are designed for surveillance, espionage, and possibly even disruptive cyber operations. Graphite, the only product ever publicly identified, extracts communications from chat applications, particularly encrypted messaging apps such as WhatsApp and Signal. This contrasts with NSO Group’s Pegasus, which can spy on all aspects of a mobile phone, including surreptitiously activating its microphone and camera to spy on targets. Reportedly, Graphite’s capabilities can be expanded through modules, though its full feature set is not publicly known. WhatsApp and Citizen Lab have reported that Graphite uses a powerful zero-click zero-day exploit to infect phones without user awareness. Boyd won’t say if the companies hunt for zero-day vulnerabilities and develop their own exploits or purchase them from others, but says both Paragon and RedLattice have “substantial” research and development teams. RedLattice’s website says the company has more than 200 “vulnerability research experts.” In addition to their products, Paragon and RedLattice build bespoke solutions for some customers, and some contracts provide customers with personnel who possess “appropriate clearances” to do a “variety” of tasks. Boyd won’t elaborate on the tasks but says his company doesn’t do offensive operations for customers; it just provides hardware and software. But after the Trump administration recently announced plans to contract with select private companies to conduct offensive cyber operations against cybercriminal groups, he says RedLattice will pursue these contracts. Customer Vetting Without the ability to monitor customer activity and detect misuse, Paragon relies on its governance model to prevent abuse. This involves customer vetting and contractual deterrence. Customers, and the countries in which they reside, are vetted by an internal risk committee that Boyd and other board members chair using various criteria to determine if a prospective country or customer might have a negative business or reputational impact on the company. “We don't want our products to be involved in things that they weren't intended to be used for,” he says. Boyd wouldn’t provide a full list of the country assessment criteria but mentioned several during the interview: political and government stability, human rights record, corruption-index ratings, strength of a country’s legal system, and whether a potential customer has a track record of adhering to its national laws. He says they lean more toward rejecting countries than approving them. They currently have between 20 and 30 countries on their approved list, and have more than 100 customers in 23 countries. “I think there's some people that would argue that we're too conservative [about who we’ll sell to],” he says, but notes that “it's better to take a hit on revenue” than sell to countries that could prove detrimental in the long run. (Boyd says, for example, that canceling Italy’s two contracts cost the company “seven figures” in revenue. He would not specify the exact value, but Israeli media have estimated the contracts were worth “tens of millions of dollars.”) In the year since he became CEO, he says a “handful” of countries have been rejected as potential customers but won’t say which ones. Paragon only sells to the US and select US allies (whether democratic or not) and only to national entities, not state and local governments and police forces. But being a US ally doesn’t guarantee a sale. They won’t sell to Saudi Arabia, even though it’s an ally. After the Saudi government reportedly used NSO’s Pegasus to spy on the fiancé and close associates of Washington Post opinion writer Jamal Khashoggi, who was murdered by Saudi government agents, the Israeli government reportedly asked Paragon to take over the Saudi Arabia contract from NSO Group, but Paragon reportedly refused. Boyd says they still won’t sell to Saudi Arabia, and also says the company has no commercial relationships with any country in the Middle East. “I think there's very important national security reasons why [the US] would want a close relationship with the Saudis from a nation-state to nation-state level,” he says. But that “does not translate into … this private-sector company having a business relationship with them. … I don't need to get into the why’s, because you probably know the why’s.” They also won’t sell to Venezuela, even with President Nicolas Maduro gone. “There's too much chaos,” Boyd says, “and it wouldn't fit our risk calculus for other variables.” Yet the company reportedly signed a lucrative contract in Singapore in 2023 worth tens of millions of dollars. Though an electoral democracy, Singapore imposes significant restrictions on free speech, media independence, and human rights. The customer vetting, Boyd says, “usually works 99 out of 100 times” to eliminate those who might misuse their tools – the assumption being that if they choose only reputable customers, the customers they choose will act only reputably. For the remaining 1 in 100, the customer contracts and zero-tolerance policy are meant to deter misuse. These prohibit using the tools against journalists, civil society members, opposition politicians, and anyone else who is not the target of a legitimate intelligence or criminal investigation. Also embedded in any system sold to non-US customers is a block that prevents targeting of any person in the US—that is, any number that requires the US +1 country code to dial. US law enforcement agencies who have a warrant can get the block disabled, he says. What if a US customer let a non-approved country use Graphite to spy on targets? During the first Trump administration, the CIA reportedly purchased NSO Group's Pegasus to give to an East African country to use. Boyd insists they would know if this occurred. “We know where the system is, because we [help customers] install it and train [them on it]…. And so we would know if it was not installed in the place where they intended it to be,” he insists. Would they also know if a customer used the tool on their own infrastructure but to spy on behalf of another non-approved country? He says they would, because the majority of customers have similar intelligence, military, or law enforcement backgrounds to RedLattice and Paragon employees, and they have robust relationships with customers. They would have a “sixth sense” if something were “fishy” about a customer, he says. Boyd insists that the fact that there has been only one allegation of misuse so far is evidence that the company’s vetting and governance model is effective. This, however, ignores the fact that the odds of someone uncovering misuse are low, especially because the company takes care to ensure its spyware won’t be easily detected on infected systems. All of this, of course, leads to questions about US customers. Based on Paragon’s vetting criteria some might wonder how the current Trump administration would meet it. Given reports of corruption, disregard for the rule of law and Trump’s unveiled threats to use government power against political opponents, fears of misuse by US agencies are not irrational. Asked what the company would do if there were allegations of misuse by a US customer, Boyd said an inspector general or legislative committee would likely investigate the matter, and if they found concrete evidence of misuse, Congress or the company would likely take action. A year after the acquisition, however, it’s unclear how much US sales have expanded. Shortly before the 2024 acquisition, Paragon signed a $2 million contract with Homeland Security Investigations, a division of US Immigration and Customs Enforcement, to help dismantle foreign terrorist operations and disrupt fentanyl traffickers, And RedLattice has had longstanding contracts with the US Air Force. But no other government contracts for the companies show up in a search of public databases, though classified contracts likely would not appear. Boyd won’t identify customers but indicates the company is particularly interested in Pentagon and CIA contracts. “There are offices across the national security enterprise that don't even know they need our product yet,” he says. “And I consider that an unaddressed market.” Comments Back to top

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.