The Secrets of the US Spyware King
Spyware maker Paragon Solutions admits to lacking oversight and a kill switch for its espionage tool.
Summary
Paragon Solutions, a spyware maker recently acquired by AE Industrial Partners and merged with REDLattice, is facing allegations that its Graphite spyware was used to target journalists and activists. Despite promises of a zero-tolerance policy for misuse, CEO Andrew Boyd revealed that Paragon lacks the technical capability to monitor customer activity or a 'kill switch' to disable the software remotely. The company canceled contracts with Italian intelligence agencies not based on an investigation, but due to the 'risk perspective' of maintaining the relationship after allegations surfaced.
Full text
CommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storySpyware maker Paragon Solutions has long positioned itself as the good guy in an industry seemingly filled with bad ones, vowing to never sell its mobile spyware to authoritarian regimes or ones with poor human rights records. It also promises to cut off any customer caught misusing its products against journalists, dissidents, or other non-legitimate targets.Yet weeks after Paragon, then Israeli-owned, was acquired by the US equity firm AE Industrial Partners in December 2024 and merged with REDLattice—an American offensive cyber firm owned by AE that this week announced plans to go public—WhatsApp alleged that Paragon’s Graphite spyware was used to infect the phones of more than 60 individuals in more than 20 countries, including journalists and activists. Most of the targets were not identified, but the University of Toronto’s Citizen Lab named two journalists and two activists in Italy.Italian authorities denied misuse. Paragon and its new US owners, despite their zero-tolerance policy for customer abuse of their software, initially declined to comment on the allegations, and reportedly was exploring potential legal action against WhatsApp after the company sent a cease-and-desist letter to Paragon. Within a week, however, Paragon had canceled the two contracts it had with Italy’s domestic and foreign intelligence agencies.From the outside, it seemed Paragon must have conducted an investigation and verified the allegations before canceling the contracts. But Paragon and RedLattice’s new CEO, Andrew Boyd, now says in an exclusive and surprisingly candid interview with WIRED that the company simply “fired” Italy because it “just was not worth it, from a risk perspective, to maintain the relationship” following the allegations.In other words, there was no Paragon investigation and no interest in conducting one to determine if the allegations were true—Italian government investigators concluded they were not. Paragon didn’t even follow up with WhatsApp or Citizen Lab to obtain details about the alleged abuse and determine if any contracts in the other countries named by WhatsApp should be canceled as well. More damning, according to critics, is what Boyd revealed next: Paragon has no technical way to know if customers misuse its software, because it can’t see who customers target or the data they extract from targeted devices. It can only learn about misuse if customers admit to it or third parties uncover it. He says WhatsApp and Citizen Lab did the company a great service when they exposed the alleged misuse last year.Paragon also doesn’t have a “kill switch” to disable customers when misuse occurs. All they can do is halt customers’ 24-hour support and system “updates.” But Boyd says the updates, the nature of which he won’t specify, are frequent and essential to using the spyware, and without them the system is rendered ineffective in about 12 hours.“Things start falling apart quite quickly,” he says.Boyd’s comments mark the first time a Paragon executive has spoken in detail about the secretive company or its handling of the Italian affair. He agreed to speak with WIRED now because he says more public discussion is needed about the offensive cyber industry and what it means for a US company to operate responsibly in this space. Prior to the interview, REDLattice founder John Ayers wrote in an email that they were “not looking for a favorable write-up.”“If the honest assessment is still damning, that's a conversation we're prepared to have,” he wrote.But Boyd’s admissions reveal that despite priding itself on being better than competitors, Paragon/RedLattice has less oversight and accountability than its most significant one—NSO Group, the Pegasus spyware maker, which has been excoriated for selling its tool to Saudi Arabia and other countries with poor human rights records. According to NSO’s transparency reports, which the company began publishing in recent years in response to criticism, it sets up infrastructure and portals that customers use to infect targets and, like Paragon, can’t see who customers target or detect misuse. But it claims it does have a kill switch to disable a customer’s access to the spyware if allegations of misuse arise, and NSO says its systems keep “tamper-proof” logs to record user activity. Customers are contractually obligated to provide these to NSO if allegations of misuse occur or else face “immediate suspension.”By contrast, Boyd says Paragon customers can enable logging on some systems if they opt to, but Paragon has no access to the logs, nor does it want access. Instead, he says, government oversight bodies can use the logs to investigate allegations of misuse among their agencies, as an Italian parliamentary committee did last year in the case of the Citizen Lab allegations. However, this raises the possibility that a government investigator could lie about misuse if they uncover it in logs.Rather than see Paragon’s lack of access to logs as an accountability problem, however, Boyd describes it as a selling point: No one would buy their products if the company could see a customer’s sensitive targeting information or logs that contain it.“There's a balancing act between privacy and security and being able to ensure that our customers are using these things correctly,” Boyd says. “And I think we've landed on the best balance.”That balance is achieved mostly through careful vetting of customers, he says, and rejecting any country that might be prone to abusing the spyware.John Scott-Railton, senior researcher at Citizen Lab, which has tracked government misuse of commercial spyware for years, calls the revelations astonishing and the lack of mandatory logging “reckless.”“What Paragon is saying in several substantial ways means [it has] less oversight, less transparency, less contractual protection against abuses than NSO Group,” he says. “It’s exactly the opposite of the picture that Paragon has painted for itself for years. The CEO admitting that his customers won’t tolerate oversight is refreshing honesty: Accountability is bad for business. And it signals to lawmakers and regulators that the spyware industry cannot be trusted to self-regulate."Scott-Railton also finds it ironic that Paragon relies on Citizen Lab and others to uncover customer misuse when Paragon actively works to hide its spyware on infected devices and prevent discovery—which inherently includes potential misuse.“We only find a very, very, very small subset [of infections], and the total numbers are always larger,” Scott-Railton says. “These companies spend millions trying to hide from us.”US senator Ron Wyden tells WIRED that surveillance tools that lack oversight and transparency are “inevitably abused.”“It’s easy to claim your powerful hacking tool isn’t being misused if you go out of your way to ensure you don’t know how customers use it,” Wyden says. “The fact that Paragon refuses to audit use of its tool, or even attempt to match the work of a small team of researchers at the Citizen Lab is a massive red flag.”Israeli Intelligence RootsParagon was launched in 2019 by Israeli Brigadier General Ehud Schneorson, former commander of the Israeli military’s signals intelligence group, Unit 8200. He cofounded it with three other 8200 veterans and former Israeli Prime Minister Ehud Barak. Two years later, the company reportedly had no customers but was developing Graphite and hoping to conquer the lucrative US market. But then the US government began cracking down on foreign spyware companies after NSO’s Pegasus and Candiru’s DevilsTongue tools were misused by their customers against government workers, journalists, dissidents, activists, and academics.The US Commerce Department sanctioned both companies in 2021, and the Israeli government drastically cut the number of countries to which Israeli firms could sell spyware—from 102 countries to 37, excluding Saudi
Indicators of Compromise
- malware — Graphite