Spyware: when the State outsources the spying on your phones
ANSSI has just published a detailed report on the threat targeting mobile phones. Vulnerabilities, "zero-click" infection chains, cybercriminals, but above all a private surveillance market that sells spying capabilities to States with little regard for civil liberties.

ANSSI has just published a detailed report on the threat targeting mobile phones, titled "Téléphones mobiles : état de la menace depuis 2015" (Mobile phones: state of the threat since 2015). Forty-three pages on vulnerabilities, on "zero-click" infection chains, on cybercriminals, but also on a private surveillance market that sells spying capabilities to States, some with little regard for civil liberties.
Translation: the spying on your smartphone is partly outsourced to dealers of digital weapons. And that deserves a real political debate, not just a set of best-practice sheets.
In my book Être en cybersécurité, I had already devoted an entire chapter to the risks tied to the use of your mobile phones. For many reasons, I am delighted to see this alignment with ANSSI. But what exactly does this report say?
What does the ANSSI report actually say?
In the report, ANSSI explains very clearly that mobile intrusion capabilities are no longer reserved for a handful of ultra-tech intelligence services.
Since the 2010s, we have seen the rise of private "offensive cyber operations" companies (LIOP) that develop, package and sell turnkey spying tools to governments, to their intelligence services, and even to para-public bodies. ANSSI says it bluntly: these firms give access to advanced capabilities to States that do not own them in-house, or that want to make the attribution of their attacks harder.
Concretely, these outfits offer:
- highly intrusive spyware (Pegasus and the like), capable of taking control of a phone with no action from the user;
- hijacked advertising intelligence (ADINT), which exploits online real-time ad auctions to profile, geolocate and target individuals or entire populations;
- solutions that rely on internet service providers (ISPs) to inject malicious code directly into network traffic;
- more "consumer" tools for businesses and individuals: stalkerware, surveillance suites, business intelligence.
We are no longer in the cliché of the "hacker in his garage". We are in an industrial ecosystem with product catalogs, trade shows, commercial demos, multi-year contracts and, inevitably, lobbying. ANSSI states that over the past three years it has handled multiple compromises of phones belonging to senior government officials or to the executive committees of strategic companies, and that in most cases it was the victims' personal phones that were targeted.

Pegasus, Predator, Graphite: who sells turnkey spying?
The report does not stop at generalities, it names names.
The best known remains Pegasus, from the Israeli group NSO, observed both in "1-click" campaigns (in Serbia, in Mexico) and in sophisticated zero-click chains. Then comes Predator, from the Intellexa alliance, whose zero-click infection chain ANSSI details: it relies on the complicity of a local ISP, with two modules named Mars and Jupiter that hijack the target's traffic and recover the decryption keys before dropping the spyware. And above all, the novelty of recent months: Graphite, sold by the Israeli company Paragon.
The Graphite affair is emblematic. In 2025, Citizen Lab confirmed that this software had compromised targets in Italy through WhatsApp: the attackers added the victim to a group, then sent a booby-trapped PDF that the phone processed automatically. Around 31 January 2025, roughly 90 people were notified by WhatsApp that they had been targeted, among them journalists and members of civil society. Citizen Lab then obtained the first forensic confirmation of a zero-click Graphite infection on iOS, via iMessage, exploiting the CVE-2025-43200 flaw that Apple only patched from iOS 18.3.1 onward. An Italian parliamentary report dated 5 June 2025 eventually established the responsibility of the Italian intelligence services in the use of Graphite against two members of the NGO Mediterranea Saving Humans.
This market is not dangerous only because of what it sells, it is dangerous because of what escapes it. In 2015, the leak of more than 400 GB of data from the Italian company Hacking Team revealed the sale of its tools to authoritarian regimes, but it also allowed Russian, Chinese and North Korean actors to reuse its vulnerabilities in the following months. More recently, between the end of 2023 and the summer of 2024, ANSSI notes that operators linked to Russia (Nobelium) used exploitation chains showing similarities with those of Intellexa and NSO. Once the weapon is built, it always ends up circulating.
And at the very bottom of the catalog sits business intelligence: companies such as the Israeli firm Black Cube or the Indian firm Belltrox offer spying services to businesses that want to keep an eye on their competitors. A threat, ANSSI stresses, that is barely visible today and therefore largely underestimated.
The comfortable hypocrisy of States and the Pall Mall Process
The most troubling part is the double standard.
On one side, ANSSI warns, rightly, about:
- the uncontrolled proliferation of these tools;
- their irresponsible use against opponents, journalists, NGOs, business leaders;
- the risk that these capabilities leak or get reused by other actors (third-party States, cybercriminals, paramilitary groups).
On the other side, those same States:
- buy these solutions for millions of euros;
- take advantage of the legal grey area to run operations that would be politically hard to own if they were carried out "in-house";
- hide behind a form of denial: "we are responsible, it's the others who abuse them".
The report highlights the Pall Mall Process, the Franco-British initiative launched at the Paris Peace Forum in November 2023, formalized in London in February 2024, which led in April 2025 to a code of practice aimed at States. The text even defines "irresponsible use" as one that threatens human rights, fundamental freedoms or the stability of cyberspace, or that operates without safeguards and oversight mechanisms. Very fine on paper. But at bottom, we remain within the following logic:
"We keep the right to buy software weapons, we just ask others to be nice about it."
A code of good conduct is not a binding treaty. We know the tune: we have already seen this with conventional arms sales, with mass-surveillance technologies, with certain intelligence decisions.
We create a market, we feed it, then we pretend to be surprised when it spills over.
When your phone becomes a geopolitical weapon
What ANSSI describes, without daring to say it quite so bluntly, is this:
a compromised smartphone is a neutralized individual.
The campaigns cited in the report show that these tools serve to:
- track elected officials and senior civil servants, often on their personal phones;
- spy on the leadership of strategic companies, and therefore influence economic and industrial choices;
- monitor opponents, journalists, rights defenders, sometimes abroad, sometimes at home;
- conduct economic intelligence: understand who talks to whom, when, in what context.
And behind this, it is not only about major powers. ANSSI documents, for instance, the Iranian operation Domestic Kitten, which has targeted more than 1,200 individuals since 2017, political dissidents and members of the Kurdish minority, using the FurBall spyware. Middle-tier States, which have neither the culture nor solid democratic safeguards, end up with eavesdropping and intrusion capabilities worthy of a major intelligence agency.
We are literally selling "turnkey political police services" to whoever can pay.
What was once reserved for the top of the range becomes a catalog product. And once the technology exists, it always ends up being used beyond what was officially intended.

The real risk: the normalization of the exceptional
What worries me most is not only the technology. It is the way we are normalizing the exceptional.
A few years ago, a State that planted a mic in an opponent's bedroom took an enormous political risk. Today, all it needs to do is compromise their phone: no search warrant, no physical trace, and the ability to capture everything remotely, sound, image, messages, contacts. ANSSI confirms this on the technical side: the implants deployed after the intrusion are generally non-persistent and leave very few traces, which makes investigations enormously harder.
The political danger is right there:
- what should be an absolute exception, strictly governed (and even then), becomes an almost routine operation;
- democratic oversight is two wars behind: judges, members of parliament and oversight authorities have neither the technical means nor, sometimes, the political will to dig into these subjects;
- part of the state apparatus is getting used to this convenience: "why investigate at length when a phone infection can tell us everything?".
This is exactly the kind of drift I describe in Être en cybersécurité: we invoke security, terrorism, the fight against organized crime, but along the way we install tools that could one day very well serve to monitor social, economic or political dissent.
What can you do about spyware? Three levels of response
We are not going to wait for a sudden revelation from governments to react. There are at least three levels to work on.
1. Individual: stop playing naive
No, you are not "too small" to be of interest to anyone.
You can be targeted indirectly:
- because you work in a strategic company;
- because you are close to an elected official, a decision-maker, a journalist;
- because your phone can serve as a pivot toward other systems.
So yes, you have to raise the baseline:
- separate work and personal use as much as possible;
- update, restart and clean your phone regularly (a non-persistent implant does not always survive a reboot);
- limit apps, permissions and hyper-intrusive "free" services;
- delete or regularly rotate your advertising identifier, the main way in for ADINT;
- learn to react when in doubt: do not tinker with everything, and contact CERT-FR or professionals rather than improvising.
That is exactly what I lay out, step by step, in Être en cybersécurité: simple reflexes, usable by everyone, without jargon.
2. Collective: demand real red lines
On the political side, we have to stop with the half-measures.
A few simple avenues:
- clearly ban certain uses (surveillance of protected categories, sales to non-democratic regimes, etc.);
- impose minimal transparency on public procurement of these tools;
- genuinely strengthen the checks and balances: oversight authorities, judges, parliamentary committees equipped with technical means.
We cannot, on one side, explain that these tools threaten democracy and, on the other, keep buying them in total secrecy.
3. Cultural: put technology back in its place
A last point, more political: we have to break out of this technocratic fascination that consists of believing there is a technical solution to everything.
The question is not only "can we spy on this phone within the bounds of the law?". It is also: "is it legitimate, proportionate, compatible with a free society?".
As long as this debate stays confiscated by a few experts, lawyers and techies, we will keep piling up tools in the name of security, all while widening the gap with liberties.
In closing
This ANSSI report has one merit: it finally puts down in black and white the scale of the threat to mobile phones and acknowledges the existence of a global private surveillance market.
It is now up to us to make something of it:
- by protecting ourselves better, individually;
- by applying pressure, collectively, to obtain clear red lines;
- by refusing this normalization of the exceptional that turns our smartphone into a State snooping device outsourced to private companies.
Sources
- Existence of a private surveillance market, LIOP, ADINT (Sherlock, Patternz, Alladin), ISPs, the Pall Mall Process and the compromises handled in France: ANSSI / CERT-FR, "Téléphones mobiles : état de la menace depuis 2015" (CERTFR-2025-CTI-012), 26 November 2025.
- The Graphite affair in Italy, around 90 people notified by WhatsApp on 31 January 2025 and Paragon's presumed customers: Citizen Lab, "A First Look at Paragon's Proliferating Spyware Operations", March 2025.
- First forensic confirmation of the zero-click Graphite infection on iOS (CVE-2025-43200, fixed in iOS 18.3.1) and journalists targeted: Citizen Lab, "Graphite Caught: First Forensic Confirmation of Paragon's iOS Mercenary Spyware", June 2025.
Frequently asked questions
What is an offensive cyber operations company (LIOP)?
These are private companies that emerged from the 2010s onward and that develop, package and sell turnkey spying tools to governments, to their intelligence services or to para-public bodies. ANSSI notes that they give access to these capabilities to States that do not master them in-house.
What is a zero-click attack?
It is a chain of zero-day vulnerabilities that infects a phone with no action from the target, no click and no file to open. The implants that are dropped are often non-persistent and leave few traces, which makes investigations much harder. Graphite, for instance, was confirmed on iOS via iMessage through the CVE-2025-43200 flaw, patched from iOS 18.3.1 onward.
What is ADINT?
ADINT (a contraction of advertising and intelligence) is intelligence derived from advertising: by posing as an advertiser in real-time ad auctions, you can profile and geolocate individuals. Products such as Sherlock, Patternz or Alladin, cited by ANSSI, reportedly go as far as compromising a phone by combining targeted ads with the exploitation of a vulnerability.
Do you have to be an important target to be affected?
No. You can be targeted indirectly: because you work in a strategic company, because you are close to an elected official or a journalist, or because your phone can serve as a pivot toward other systems.
Does the Pall Mall Process solve the problem?
Not really. This Franco-British initiative launched at the end of 2023 led, in April 2025, to a code of practice aimed at States. It is a code of good conduct, not a binding treaty: we keep the right to buy software weapons, we just ask others to be nice about it.
What individual reflexes should you adopt in the face of this threat?
Separate work and personal use, update, restart and clean your phone regularly, limit apps and permissions, delete or rotate your advertising identifier, and know how to react when in doubt by contacting CERT-FR or professionals rather than tinkering.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
