Researchers have uncovered extensive evidence linking Israeli firm Paragon Solutions to a sophisticated spyware operation that exploited a zero-day vulnerability in WhatsApp to target journalists and civil society members.
Following the investigation, WhatsApp notified approximately 90 potential victims and confirmed the attack was mitigated.
Established in Israel in 2019, Paragon Solutions was founded by notable figures, including former Israeli Prime Minister Ehud Barak and Ehud Schneorson, former commander of Israel’s Unit 8200 intelligence unit.
The company markets its Graphite spyware as a more targeted tool that accesses messaging applications rather than taking “complete control” of devices like NSO Group’s notorious Pegasus spyware.
A senior Paragon executive previously claimed the company would only sell to governments that “abide by international norms and respect fundamental rights and freedoms.”
Citizen Lab investigation after starts from a tip about distinctive server infrastructure. Using unique fingerprinting techniques, they identified approximately 150 certificates linked to Paragon’s command and control servers.
The investigation revealed suspected Paragon deployments across multiple countries, including Australia, Canada, Cyprus, Denmark, Israel, and Singapore.
The investigation surfaced potential links between Paragon and the Ontario Provincial Police (OPP) in Canada.
Researchers found suspicious IP address registrations under the name “Integrated Communications,” with one registration matching the OPP’s General Headquarters address.
This discovery aligns with previous reports of Canadian law enforcement agencies expanding their use of spyware technologies without adequate public oversight.
The attack involved sending malicious PDF files to targets via WhatsApp group chats. When received, the victim’s device would automatically process the PDF, exploiting the vulnerability to load the Graphite spyware implant into WhatsApp without any user interaction.
Researchers shared their infrastructure analysis with Meta, which proved “pivotal” to the company’s ongoing Paragon investigation.
This collaboration helped WhatsApp identify, mitigate, and attribute a zero-click exploit actively deployed against targets.
On January 31, 2025, WhatsApp notified approximately 90 accounts believed to have been targeted by Paragon’s spyware. Multiple WhatsApp notification recipients in Italy consented to forensic analysis of their devices.
The investigation confirmed the presence of a unique forensic artifact dubbed “BIGPRETZEL” on multiple devices, which WhatsApp confirmed is associated with Paragon infections.
The victims included Francesco Cancellato, editor-in-chief of Fanpage.it, and multiple members of Mediterranea Saving Humans, an organization that rescues migrants in the Mediterranean Sea.
A related case involved David Yambio, founder of Refugees in Libya, who received an Apple notification about spyware targeting in November 2024.
Forensic analysis revealed an attempt to infect his iPhone with novel spyware in June 2024, which Apple confirmed they patched in iOS 18.
After initial denials, the Italian government eventually confirmed it was a Paragon customer, though officials denied targeting journalists and activists.
The government later announced a suspension of Paragon deployments pending investigation.
This case challenges Paragon’s claims of having developed an abuse-proof business model, demonstrating that commercial spyware, even when sold to democratic governments, remains vulnerable to misuse against legitimate civil society actors.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…