logo

Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations

ID: 2fba921a-bd42-575a-a03c-2f38d68da915

STIX ID: report--2fba921a-bd42-575a-a03c-2f38d68da915

Feed Name: The Citizen Lab

Threat Score
88/100

Date Published: 2025-03-19

Date Updated: 2026-04-19

Author: Bill Marczak

...
...

**Executive summary:** The Citizen Lab report details Paragon Solutions’ Graphite spyware operations, mapping victim-facing and customer infrastructure (distinct TLS certificate fingerprints and IP ranges), identifying suspected deployments across multiple countries (including Italy and a possible Canadian customer), documenting WhatsApp’s mitigation of a Paragon zero‑click exploit and notifications to ~90 accounts, and presenting forensic evidence of Android (BIGPRETZEL) and iPhone (SMALLPRETZEL) infections affecting journalists and civil-society actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.