Spyware companies, officially known as Commercial Surveillance Vendors (CSV), have surpassed state-sponsored hacker groups in the exploitation of zero-day vulnerabilities for the first time in 2025.
Governments, including intelligence agencies, police, and immigration authorities, are the primary customers of these firms, who justify their services by claiming to combat terrorism and crime. However, there have been numerous reports of such software being used to surveil journalists, human rights advocates, and political opponents.
Understanding CSV
Commercial Surveillance Vendors develop, market, and sell surveillance software to government clients. In the literature, they are also referred to as Private Sector Offensive Actors (PSOA), which includes non-state entities conducting offensive cyber operations. This category encompasses providers of commercial spyware.
“PSOAs are typically known as cyber mercenaries. They are commercial entities that create and sell cyber weapons to clients and then use these for attacks on specific targets,” states a report by the international digital security firm CWIS.
Unlike cybercriminal organizations, commercial spyware providers generally operate under contracts with government clients. However, their products can be used for illegal surveillance. These companies market their offerings as solutions for counterterrorism and crime prevention.
From a technical perspective, spyware firms do not merely conduct attacks or provide isolated malware; they offer comprehensive "turnkey" solutions. Their packages may include delivery mechanisms, vulnerability chains, command-and-control infrastructure, and tools for processing collected data.
Google's Threat Analysis Group monitors around 40 such companies of varying sizes and public visibility.
Scope of Activity
In 2025, researchers from Google documented 90 zero-day vulnerabilities exploited in real-world attacks, a figure lower than the record of 100 in 2023 but higher than the 78 recorded in 2024.
Importantly, there has been a shift in authorship: for the first time, commercial spyware vendors have overtaken state hacker groups in attributed attacks. Of the 42 vulnerabilities with identifiable origins, 15 were linked to CSVs such as NSO Group, Intellexa, and Candiru.
Source: Google.According to Fortune Business Insights, government spending on the global cyber weapons market reached $54.83 billion in 2025, with nearly 40% of this amount attributed to North America.
A report from Freedom on the Net noted that 49 governments are suspected of accessing sophisticated spyware or data extraction technologies, including Morocco, Uganda, Saudi Arabia, India, and Mexico. At least 19 of the 48 countries involved in transnational repression utilize such software.
Key Players
The commercial spyware market is not uniform; it consists of several major vendors, each offering a unique set of services, operating in different countries, and having their own histories of scandals.
NSO Group
NSO Group, established in 2010 in Israel, is the most well-known and criticized player in this industry. The company develops the Pegasus product, which can remotely infect iOS and Android devices, intercept messages, track locations, and activate microphones and cameras.
Since 2016, it has supplied software to intelligence agencies, law enforcement, and military clients worldwide, including 14 EU countries, the UAE, Saudi Arabia, Mexico, and Morocco.
CEO of NSO Group Shalev Hulio (center) with Israeli officials Eyal Blum and Ramon Ashkar. Source: ForbiddenStories.NSO Group has been on the U.S. sanctions list since 2021 and is currently seeking to be removed from it. In 2025, the company was embroiled in a scandal involving Meta, which revealed a campaign to surveil WhatsApp users. A U.S. court ruled against NSO Group, initially ordering them to pay $167 million, later reduced to $4 million. The firm was also barred from attacking users of the messaging platform. However, in 2026, Meta filed another lawsuit against NSO Group for violating this order, accusing the company of a new phishing wave.
Paragon Solutions
This Israeli company develops the Graphite product, which, unlike Pegasus, employs zero-click vulnerabilities, such as through PDF previews in WhatsApp. In spring 2025, Citizen Lab confirmed that Graphite was used to surveil journalists and human rights defenders in Europe, particularly in Italy, affecting migration activists and reporters.
Following a political scandal and a parliamentary committee investigation, the Italian government officially terminated contracts with Paragon.
In a separate case, the U.S. Immigration and Customs Enforcement (ICE) agency gained access to Paragon's technologies through a $2 million contract, drawing sharp criticism from human rights advocates. The Biden administration froze the contract, but it was reactivated in 2025 under Donald Trump. The U.S. Department of Homeland Security has since stated that ICE has "no connections" with Paragon.
Candiru
Founded in Israel in 2014 by former NSO Group employees, Candiru's flagship product, DevilsTongue, is modular spyware for Windows that provides deep access to infected devices. Authorities in Hungary, Saudi Arabia, Indonesia, and Azerbaijan have used their products. Candiru is also under sanctions from the U.S. Department of Commerce.
Researchers believe the company may have rebranded to evade restrictions. In early 2025, American firm Integrity Partners acquired Candiru's assets for $30 million and transferred them to a new legal entity—Integrity Labs.
Intellexa
This international consortium develops the Predator product, which is used against civil society representatives globally. Google linked the organization's activities to at least 15 zero-day attacks identified since 2021, one of the highest rates among commercial spyware vendors.
Despite U.S. sanctions, Predator deployments were recorded in Iraq, Pakistan, Mozambique, Saudi Arabia, Kazakhstan, and other countries in 2025. In December, Amnesty International reported an attack via Predator on a human rights defender in Pakistan. In Greece, the company faced allegations of violating telephone privacy, unauthorized access to information systems, and illegal processing of personal data.
RCS Lab
Its product, Hermit, has been used for surveillance in Italy, Kazakhstan, Syria, and other jurisdictions. The company's modular spyware for Android can record audio, redirect calls, and gather data from devices. Infections occur through messages and push notifications disguised as legitimate Samsung, Vivo, and Oppo applications. Google’s Threat Analysis Group linked RCS Lab to attacks exploiting zero-day vulnerabilities in the Chrome browser.
According to WikiLeaks leaks, the firm was a distributor for another Italian spyware supplier, HackingTeam, known today as Memento Labs, as early as 2012.
Pricing and Contracts
The cost of spyware ranges from several million to tens of millions of dollars, depending on the vendor, the number of simultaneous targets, and geography.
NSO Group (Pegasus): From 2018 to 2020, the company charged European government clients a "standard price" of $7 million for using a platform capable of hacking up to 15 devices simultaneously. The company also had several subscription plans—Heaven, Eden, and Erised.
This information comes from the testimony of NSO's Vice President for Global Business Operations Sarit Blizinski Gil in a lawsuit against Meta. The annual license for Pegasus could cost up to $6.8 million, with one-off contracts sometimes reaching $60-80 million. The CIA and FBI collectively paid NSO about $7.6 million.
Paragon Solutions (Graphite): The cost for intercepting one target is approximately €20,000, according to Italian media reports.
The contract with ICE included a fully configured software package with licensing, hardware, training, and technical support. In 2024, American investment fund AE Industrial Partners acquired Paragon for $500 million.
Intellexa (Predator): According to a 2022 leak, using spyware on 100 devices cost around €8 million. The base version of the system ranged from €4 million to €8 million, while a complete package with support and training reached €13.6 million. In 2020, the Vietnamese Ministry of Public Security signed a $6 million contract with Intellexa for "infection solutions."
Candiru (DevilsTongue): The standard contract price started at €16 million, allowing for unlimited attempts to infect with monitoring of ten devices simultaneously.
Candiru's price list. Source: CyberSecurityNews.For an additional €1.5 million, the client could track 15 more devices and extend the contract's applicability to another country.
Who Becomes Targets
CSV claims to fight terrorism and crime, but documented practices show that governments systematically use these tools to surveil their own citizens.
Serbia: Surveillance of Journalists
In February 2025, Amnesty International reported attacks using Pegasus on two journalists from BIRN. One of them, pseudonymously named Bogdana, received a message on Viber on February 14 with a link to an article and a question from an unknown sender. Clicking the link led to the infection of her iPhone. The second journalist, Jelena Velkovic, also received suspicious messages. Technical analysis confirmed traces of Pegasus on their devices.
“This was a targeted attack on investigative journalists—a form of pressure and intimidation. Whether it was a personal attack on me or on BIRN as a media outlet, I am not sure,” stated Bogdana.
The Serbian authorities have not initiated a public investigation. BIRN filed a complaint with the prosecutor's office, but there has been no response.
The organization and its employees frequently face threats, harassment, and lawsuits, including from high-ranking government officials. Currently, BIRN is involved in four legal disputes, most initiated by pro-government representatives, including the current mayor of Belgrade, Aleksandar Sapic.
Amnesty International has previously documented the use of Pegasus against local activists. Researchers believe that Serbian authorities "abuse invasive spyware and other digital surveillance technologies."
Greece: Predatorgate
In March 2022, a scandal known as Predatorgate erupted when journalist Thanasis Koukakis discovered that his phone was infected with Predator spyware and being monitored by the Greek National Intelligence Service. The authorities had access to his device for at least two months. Investigations revealed that other journalists and politicians, including the leader of the opposition party, Nikos Androulakis, may also have been surveilled.
In February 2026, an Athens criminal court convicted four individuals linked to the case, including Intellexa founder Tal Dilian. Each received a sentence of 126 years and 8 months, but under Greek law, this was limited to eight years. The execution of the sentence has been postponed pending an appeal. Koukakis took the case to the European Court of Human Rights in 2026.
The intelligence services and political figures were exonerated, not recognizing any wrongdoing.
Hungary: "Devil's Tongue"
Hungary frequently appears in reports regarding the use of spyware against its own citizens. Human rights organizations report that nearly 300 individuals in the country have been targeted with Candiru's DevilsTongue, including journalists, entrepreneurs, and local politicians.
In November 2021, Lajos Kósa, the head of the parliamentary defense and law enforcement committee, confirmed that Hungary's Ministry of Interior had purchased Pegasus from NSO Group. He claimed that the software was used exclusively with the sanction of judges or the Ministry of Justice and never against Hungarian citizens.
In 2025, German Green Party MEP Daniel Freund stated that his devices were targeted with DevilsTongue. He filed a complaint against Hungarian Prime Minister Viktor Orbán and unnamed individuals.
“During the peak of the 2024 European Parliament election campaign, they unsuccessfully tried to install spyware on my devices,” Freund wrote.
IT experts estimate that the Hungarian government may have spent over €1 million surveilling Freund's Brussels office.
Mexico: Impunity
Mexico is one of the oldest markets for Pegasus, with reports of surveillance against journalists and human rights defenders dating back to 2016.
According to Freedom House, more than 450 devices belonging to Mexicans were hacked using Pegasus within the first month of Andrés Manuel López Obrador's presidency.
In 2024, a federal court acquitted the only person charged in the country related to cyber espionage. The court acknowledged that human rights defender Carmen Aristegui had indeed been surveilled but acquitted the only defendant, Juan Carlos García Rivera, due to a lack of evidence.
Despite years of investigations and documented cases, no high-ranking clients of surveillance in Mexico have been held accountable.
Spain: Catalan Separatists
In 2022, it became known that around 65 individuals associated with the Catalan independence movement were surveilled using Pegasus. This included current and former representatives of the Catalan government, such as former President Pere Aragonès and former regional leader Artur Mas. It later emerged that 18 of them were monitored by Spain's National Intelligence Center with court authorization, but the remaining cases lack a specific "client."
In November 2025, the European Court of Human Rights dismissed a complaint by Catalan politicians led by former Vice President of the Parliament Josep Costa, finding no grounds for consideration. Costa remarked that after this ruling, the victims of surveillance remain "defenseless."
The Catalan government has also requested full disclosure of three court orders authorizing surveillance of politician Pere Aragonès. In October 2025, the Spanish Supreme Court rejected the request, ruling that disclosing documents would harm national security.
The Cat-and-Mouse Game
Efforts to regulate the commercial spyware market remain fragmented. The primary tool has been U.S. sanctions. NSO Group, Candiru, and Intellexa have been added to the Entity List and SDN List.
However, these measures have proven largely ineffective. In December 2025, the Trump administration lifted restrictions on three Intellexa executives, drawing criticism in Congress.
CSV circumvent sanctions by changing ownership. This has been the case with major players like Paragon Solutions and Candiru.
At the international level, the main countermeasure remains the Pall Mall Process, an initiative by the UK and France launched in 2023. This initiative developed a voluntary code of conduct signed by 27 states.
Negotiations on basic principles for the spyware industry began in July 2026. Nonetheless, human rights organizations criticize this approach for lacking enforceability and risking "corporate capture."
Amnesty International asserted that the code should limit access of non-state actors to spyware and establish clear standards for exceptional circumstances under which such technologies can be sold.
***
Sanctions are easily evaded, international initiatives remain voluntary, and attempts to impose bans at the EU level have yet to produce binding norms. Lawsuits may have localized effects but do not change the market structure. Until a mandatory and universal control mechanism emerges, the industry will adapt faster than regulators. The core question in the coming years is whether international law can develop effective tools, or if commercial surveillance will become the norm rather than the exception.
Follow ForkLog on social media
Telegram (main channel) Facebook X