The architecture of control has shifted. In the twentieth century, authoritarianism was visible, defined by physical borders, uniformed secret police, and the clanking of prison bars. Today, the machinery of repression is silent, invisible, and boundless.
This is the Invisible Panopticon, a system where the surveillance infrastructure is not built from concrete and steel, but from lines of code and exploited network protocols. Between 2020 and 2025, a lucrative industry of commercial surveillance vendors (CSVs) has effectively privatized the power of the state intelligence agency, selling military grade espionage tools to any government willing to pay the price. The result is a global crisis of digital authoritarianism that recognizes no jurisdiction and respects no privacy.
The Mercenary Marketplace
The defining feature of this era is the commodification of intrusion. Gone are the days when only superpowers possessed the capability to compromise encrypted communications. A 2024 report by Google’s Threat Analysis Group revealed a startling statistic: commercial spyware vendors were responsible for 50% of all known zero day exploits targeting Google products that year.
These companies, often operating from Europe or Israel with complex corporate structures to evade accountability, have democratized oppression.
Data from the 2021 Pegasus Project provided the first glimpse into this abyss, identifying over 50,000 phone numbers selected as potential targets. The list included 180 journalists across 20 countries, shattering the illusion that the press could operate safely in democratic or semi democratic states. By 2023, the scope had widened.
The “Predator Files” investigation exposed how the Intellexa alliance targeted at least 50 social media accounts belonging to 27 individuals and 23 institutions, reaching as high as the European Parliament and United Nations officials.
From State Sponsored to Mercenary
The terminology itself is evolving to match the threat. For years, technology giants referred to these actors as “state sponsored.” However, in April 2024, Apple updated its threat notification policy across 92 countries, replacing the term with “mercenary spyware attacks.”
This linguistic shift is significant. It acknowledges that the threat is no longer just about national policy but about a transactional market where repression is a service bought and sold. Since 2021, Apple has notified users in over 150 nations that they have been targeted by these sophisticated digital weapons.
Key Statistic: In 2024 alone, Apple sent threat notifications to users in 92 countries, warning them of mercenary spyware attacks targeting their iPhones.
The Zero Click Reality
The technical sophistication of these tools renders traditional cybersecurity advice obsolete. The most dangerous capability is the “zero click” exploit. Unlike phishing attacks that require a user to click a suspicious link, zero click infections occur without any interaction from the victim. A phone can be compromised simply by receiving a WhatsApp call that the user never answers, or by processing an invisible image file sent via iMessage.
Once infected, the device becomes a spy in the pocket. The spyware grants the attacker total access: encrypted messages, photos, location history, and even the ability to turn on the microphone and camera to record ambient conversations. In March 2025, reports from Citizen Lab highlighted new campaigns targeting the World Uyghur Congress, utilizing malware delivery methods that were highly customized to specific cultural contexts, proving that these tools are becoming more targeted and harder to detect.
The Chilling Effect
The psychological impact of this surveillance is profound. When dissidents, lawyers, and reporters know that their most private moments can be scrutinized by the state, they engage in self censorship. Sources go silent. Investigations are abandoned. The Invisible Panopticon creates a prison of the mind, where the fear of observation is as effective as the observation itself. The financial barrier to entry is high but falling relative to the value of the intelligence gained; earlier data suggested costs as high as 650,000 USD to target just ten devices, yet governments continue to pay millions for these capabilities because the control it offers is absolute.
As we examine the period from 2020 to 2025, it becomes clear that we are not merely witnessing a technological upgrade but a fundamental restructuring of power. The Telecom Spyware Network is not a glitch in the modern internet; it is a feature, designed and maintained by a shadow industry that profits from the silence of dissent.
II. The Evolution of Eavesdropping: From analog wiretaps to zero click exploits
The history of state surveillance is a timeline of escalating intimacy. In the analog era, intercepting a conversation required physical proximity or access to copper lines. Agents needed to clip wires in basement junction boxes or sit in unmarked vans listening to static filled frequencies. The barrier to entry was high, and the scale was limited by manpower. Today, that physical tether has been severed. The modern surveillance architecture resides entirely in code, allowing state actors to silently compromise devices from across the globe without ever triggering a notification.
The Silent Network: SS7 and Diameter
Before the rise of mercenary spyware, the digital surveillance frontier was defined by network vulnerabilities. The Signaling System 7 (SS7) protocol, the global standard that routes calls and text messages between networks, was built in the 1970s without authentication mechanisms. By 2020, security researchers had repeatedly demonstrated how intelligence agencies exploited this flaw to track geolocation and intercept two factor authentication codes. The successor protocol, Diameter, retained similar weaknesses. These network level attacks allowed governments to monitor dissidents without touching the target device, merely by querying the cellular network infrastructure.
The Mercenary Spyware Marketplace (2020–2025)
The industry shifted dramatically with the privatization of offensive cyber capabilities. Companies like NSO Group and the Intellexa Alliance commoditized advanced espionage tools, selling them to government clients under the guise of crime prevention. Real data from the past five years reveals a starkly different usage pattern.
In 2021, the Pegasus Project exposed the industrial scale of this targeting, but the years following showed no decline in activity. By early 2024, investigations by Access Now and Citizen Lab confirmed that at least 35 journalists, lawyers, and human rights activists in Jordan had their phones hacked with Pegasus spyware. The breadth of these attacks illustrated a terrifying reality: the tools of cyberwarfare were now being used for domestic political repression.
The market also saw the rise of the Intellexa Alliance, the consortium behind the Predator spyware. Unlike NSO, which faced intense scrutiny, Intellexa operated in the shadows until 2023. The “Predator Files” investigation revealed their tools were used to target European politicians and civil society members. In response to this proliferation, the United States Treasury Department sanctioned the Intellexa consortium and its leadership in March 2024, marking the first time the US government levied sanctions against a commercial spyware entity for enabling human rights abuses.
The Apex of Intrusion: Zero Click Exploits
The most significant technical leap in this period was the transition from “one click” to “zero click” infection vectors. Early versions of spyware required a user to make a mistake, such as clicking a malicious link in a text message. Modern exploits have eliminated this variable entirely.
A zero click attack requires no interaction from the victim. The spyware silently executes code merely by receiving a specially crafted message or image file. In September 2023, Citizen Lab discovered “BLASTPASS,” a zero click exploit chain capable of compromising iPhones running the latest iOS version. The attack leveraged a vulnerability in PassKit (Apple Pay) to deliver the payload via iMessage. The user saw nothing. The device simply became infected.
Google Threat Analysis Group (TAG) provided concrete data on this trend in their February 2024 report. Their researchers attributed 50% of all known zero day exploits discovered in 2023 directly to commercial spyware vendors. This statistic confirms that private companies are now driving the discovery of critical vulnerabilities at a rate rivaling major state intelligence agencies. These vendors stockpile unknown security flaws, ensuring their government clients can bypass even the most secure commercial encryption.
Automated Repression
The trajectory from 2020 to 2025 shows a clear pattern. Surveillance has moved from a targeted, labor intensive process to an automated, invisible service. Dissidents in India, Poland, Spain, and Mexico have found their devices turned into digital witnesses against them. The spyware does not just capture calls; it exfiltrates the entire digital life of the target, including encrypted chats, photos, location history, and passwords. As encryption standards improved to protect privacy, the surveillance industry pivoted to endpoint compromise, rendering the encryption irrelevant by reading the data before it is ever sent.
III. The Marketplace of Shadows: Profiling NSO Group, Candiru, and the Mercenary Spyware Industry
By Investigative Desk | January 2026
The global surveillance industry operates in a dark obscurity, a realm where digital weapons are bought and sold with terrifying ease. Between 2020 and 2025, this marketplace shifted from a niche sector for law enforcement into a sprawling mercenary network targeting dissidents, journalists, and democracy itself. At the center of this web sit three entities that define the modern era of cyber warfare: NSO Group, Candiru, and the Intellexa Consortium.
The Titan Under Siege: NSO Group
For years, the Israeli firm NSO Group stood as the undisputed leader of the spyware world. Its flagship product, Pegasus, promised governments absolute access to mobile devices. However, July 2021 marked a turning point. The Pegasus Project, a collaboration coordinated by Forbidden Stories, leaked a list containing 50,000 phone numbers selected as potential targets. The data revealed a grim reality: the tools claimed to fight terrorism were being used to track human rights lawyers, reporters, and heads of state.
The fallout was swift. In November 2021, the United States Department of Commerce added NSO Group to its Entity List, effectively blacklisting the company from American technology. This designation shattered the veneer of legitimacy the firm had cultivated. By late 2023, NSO released a transparency report admitting it had rejected over 300 million dollars in sales due to human rights concerns, a figure that highlighted the sheer scale of demand for illicit surveillance. Despite financial pressure, the threat remained. In March 2024, a US court ordered the firm to surrender source code for Pegasus, further exposing its inner workings.
The Ghost in the Machine: Candiru
While NSO courted publicity, Candiru preferred total invisibility. Based in Tel Aviv, this secretive firm sold spyware exclusively to governments, operating under the radar until July 2021. That summer, researchers from Citizen Lab and Microsoft exposed its operations, identifying it as the actor “Sourgum.”
Candiru specialized in infiltrating Windows systems and browsers using “zero click” exploits, attacks that require no interaction from the victim. The investigation uncovered over 100 victims worldwide, including activists in Spain, Hungary, and Indonesia. The malware, known as DevilsTongue, could steal files and log keystrokes with impunity. Like its rival, Candiru was placed on the US Entity List in November 2021. Yet, the firm illustrated the resilience of this industry. When one door closed, another opened, with corporate structures shifting to obscure ownership and evade sanctions.
The Hydra Rises: Intellexa and Predator
As NSO and Candiru faced headwinds, a new player aggressively captured market share. The Intellexa Consortium, founded by Tal Dilian, marketed the Predator spyware as a potent alternative. Unlike the centralized Israeli firms, Intellexa operated as a diffuse network with entities in Greece, Ireland, and North Macedonia.
The “Predator Files” investigation in October 2023 revealed the staggering reach of this alliance. Documents showed Intellexa products in at least 25 countries. The targets were not merely criminals but high level political figures, including European Parliament President Roberta Metsola and Taiwanese President Tsai Ing Wen. Predator often used “one click” attacks, tricking victims with links sent via SMS or WhatsApp.
The American government responded with unprecedented force. In July 2023, the US placed Intellexa and its developer Cytrox on the trade blacklist. Then, in March 2024, the US Treasury Department escalated the fight by sanctioning specific individuals within the consortium, including Dilian and corporate leader Sara Hamou. This marked the first time US sanctions targeted the people behind the spyware companies, not just the corporate entities.
A Persistent Threat
From 2020 to 2025, the mercenary spyware industry demonstrated a terrifying capacity for survival. When NSO stumbled, Intellexa rose. When exploits were patched, new “zero day” vulnerabilities were found. The marketplace of shadows remains open for business, selling the power to silence dissent to the highest bidder.
“`html
IV. Infrastructure Vulnerabilities: How SS7 and Diameter protocols are weaponized globally
The global telecommunications architecture relies on a foundation of trust that has become its most dangerous liability. At the core of every mobile connection lie two signaling protocols: Signaling System No. 7 (SS7) for 2G and 3G networks, and Diameter for 4G LTE and 5G networks. Designed decades ago to route calls and ensure roaming interoperability between carriers, these systems were built without authentication mechanisms. They assume that any request received from another network node is legitimate. Between 2020 and 2025, this assumption was systematically dismantled by private surveillance firms and state actors who transformed these routing protocols into global tracking weapons.
The SS7 Legacy: A License to Spy
SS7 functions as the central nervous system for older networks, handling call setup and text message delivery. Its vulnerability lies in its openness. An attacker with access to an SS7 gateway can send commands to a home network pretending to be a roaming partner. The network, programmed to trust these signals, obediently hands over sensitive data.
In December 2020, researchers at Citizen Lab exposed the scale of this market. They identified a surveillance vendor known as Circles, an affiliate of NSO Group, which sold access to SS7 exploits to twenty five countries. Unlike spyware that requires a user to click a link, SS7 attacks operate silently in the background. The attacker needs only a phone number. By executing commands such as AnyTimeInterrogation or SendRoutingInfo, surveillance operators can force the network to reveal the Cell Global Identity of the target device. This data point pinpoints the user to a specific cell tower sector, effectively tracking their movements in real time. The Citizen Lab report linked these deployments to nations with poor human rights records, including those known for targeting political rivals and journalists.
Diameter: The Insecure Successor
The transition to 4G and 5G did not solve the problem. The Diameter protocol replaced SS7 but inherited its fundamental flaw: the inability to verify the origin of a message across interconnects. While Diameter supports encryption standards like IPsec, many operators disable them to maintain compatibility with legacy equipment. This negligence leaves the door open for exploitation.
Data from 2024 and 2025 highlights the persistence of these threats. A report by telecom security firm Enea in July 2025 detailed a sophisticated “bypass attack” employed by a surveillance vendor likely based in the Middle East. This actor used manipulated encoding within signaling messages to slip past standard firewalls. The attack allowed them to query subscriber location data without triggering alarms. Enea statistics from late 2024 indicated that probing attacks targeting these signaling layers surged, with nearly 75 percent of global mobile networks experiencing reconnaissance attempts. These probes are often precursors to targeted surveillance, testing the network defenses to see which commands will be accepted.
The Salt Typhoon Breach
The vulnerability of telecom infrastructure extends beyond leased access to direct network penetration. In late 2024, a sophisticated campaign attributed to Chinese state backed hackers, dubbed “Salt Typhoon,” compromised major broadband providers in the United States. The attackers breached the lawful intercept systems embedded within the carrier networks. These systems are legally mandated backdoors designed for law enforcement use. By gaining administrative access, the intruders could monitor call logs, unencrypted texts, and location data of high profile political figures. This incident demonstrated that even without exploiting protocol flaws, the infrastructure itself remains a fragile repository of sensitive metadata.
The Human Consequence
The weaponization of these protocols has tangible consequences for dissidents. In Southeast Asia, activists fleeing authoritarian regimes have been tracked across borders using these “silent” network queries. Because the attack occurs at the carrier level, the victim sees no suspicious activity on their device. Encrypted apps like Signal or WhatsApp cannot protect against this, as the metadata of location and connection is generated by the network, not the application. The commodification of these exploits has created a reality where privacy is impossible as long as a device is connected to a cellular tower.
“`
V. The Anatomy of an Attack: Breakdown of infection vectors via SMS, WhatsApp, and iMessage
The evolution of digital surveillance from 2020 to 2025 reveals a disturbing shift in how spyware infiltrates mobile devices. While early iterations relied on user error or deception, modern campaigns utilize sophisticated exploits that require no victim interaction. This transition from social engineering to invisible intrusion represents the most significant escalation in cyber espionage. The following analysis breaks down the primary infection vectors used by state clients to target dissidents, journalists, and opposition leaders across the globe.
The SMS Vector: Deception and Social Engineering
Despite the rise of encrypted messaging, the humble text message remains a primary delivery mechanism for spyware like Predator and older versions of Pegasus. This method, often termed “smishing,” relies on creating a sense of urgency or curiosity. During 2023 investigations by Amnesty International, forensic teams discovered that the “Predator” spyware infrastructure aggressively targeted civil society members in the European Union, the United States, and Asia. Attackers sent personalized messages containing malicious links that masqueraded as news articles or social media posts.
In a confirmed case from early 2025, two journalists from the Balkan Investigative Reporting Network in Serbia received text messages baiting them with details about a local protest movement. The messages contained links to a cloned media website. Once the target tapped the link, the browser directed them to an exploit server. This “single click” method installs the payload within seconds, granting the attacker full remote control over the microphone, camera, and file system. While this vector requires user error, it remains effective because it exploits human psychology rather than software vulnerabilities.
The WhatsApp Vector: Exploiting the Buffer
WhatsApp serves as a critical communication tool for activists due to its encryption, yet it has been frequently weaponized by NSO Group and other vendors. The attack surface here often involves the complex code responsible for processing voice calls and media files. Between 2019 and 2020, NSO Group utilized a vector known internally as “Eden.” This exploit manipulated the memory buffer during a voice call establishment phase.
Legal documents released in late 2024 and resulting in a May 2025 verdict against NSO Group revealed that the “Eden” vector functioned without the victim answering the call. The spyware altered the data packets sent to the device, triggering a buffer overflow that allowed remote code execution. Following the closure of this loophole, attackers shifted to a vector named “Erised,” which remained active through May 2020. These attacks are particularly insidious because they leave little trace visible to the user; the call log entry can be retroactively deleted by the malware, leaving the victim unaware that their device was ever contacted.
The iMessage Vector: The Zero Click Frontier
The most advanced tier of infection targets Apple iMessage. This vector is prized because it allows for “zero click” infection, where the phone is compromised with absolutely no interaction from the owner. The device does not need to be unlocked, and the user receives no notification.
In September 2023, Citizen Lab uncovered the “BLASTPASS” exploit chain (CVE 2023 41064 and CVE 2023 41061). This attack method involved attackers sending a malicious PassKit image, typically used for digital wallet passes, via iMessage. The exploit successfully bypassed the “BlastDoor” security sandbox, a feature Apple specifically designed to filter untrusted data. The malicious image triggered a vulnerability in the image processing library, executing code immediately upon receipt. This specific campaign targeted civil society organizations in Washington DC, demonstrating that even fully patched devices running the latest operating software were vulnerable. Similarly, the “FORCEDENTRY” exploit observed in 2021 used malicious PDF files disguised as GIFs to crash the image rendering process and inject the spyware.
Technical Breakdown of the Infection Chain
Regardless of the delivery method, the infection process follows a consistent architectural pattern observable in forensic analysis:
- Delivery: The weaponized data packet arrives via SMS link, WhatsApp call packet, or iMessage attachment.
- Exploit: The code triggers a vulnerability (such as a buffer overflow or integer overflow) to crash the legitimate process and gain root privileges.
- Payload: The kernel installs the spyware agent (Pegasus or Predator) into the volatile memory of the device.
- Persistence: The malware establishes communication with a Command and Control server to exfiltrate passwords, photos, and location data. In many modern versions, the spyware resides only in temporary memory to vanish if the device reboots, complicating forensic detection.
The data from 2020 to 2025 underscores a terrifying reality: for a well funded attacker, no device is impenetrable, and the distance between privacy and total surveillance is measured in mere lines of code.
VI. Client States: Mapping the geopolitical flow of surveillance technology
The global trade in commercial spyware has fundamentally altered the balance of power between governments and their citizens. From 2020 to 2025, the market shifted from a niche industry into a sprawling diplomatic currency. Technologies once reserved for superpowers are now available to any nation with the budget to pay. This democratization of espionage has created a network of client states where digital repression is imported as easily as any other commodity.
The Supply Chain: From Tel Aviv to Skopje
The architecture of this trade relies on a complex web of corporate entities designed to obscure ownership and evade export controls. While Israel remains a primary hub for innovation, the operational center of gravity has drifted toward Europe. The “Intellexa Alliance,” a consortium of companies including Cytrox and WiSpear, exemplified this trend. By establishing legal footholds in Greece, Ireland, and North Macedonia, these vendors bypassed strict Israeli oversight to sell their Predator spyware to regimes across the Global South.
Data from the 2023 Predator Files investigation revealed that European jurisdiction served as a convenient backdoor for exports. Documents showed that licenses issued by Greek authorities allowed the sale of sophisticated surveillance tools to Madagascar and Sudan. This regulatory arbitrage enabled the technology to flow unchecked until the United States intervened with sanctions in late 2023 and 2024.
Case Study: The Persistent Surveillance of Mexico
Mexico stands as the premier example of a client state where spyware has become a permanent fixture of governance. Despite promises by the administration of President López Obrador to cease digital espionage, forensic analysis by Citizen Lab in 2023 confirmed that human rights defenders and journalists remained active targets. The usage of Pegasus persisted well beyond the initial scandals of 2017.
New evidence surfacing in 2024 indicated that elements within the Mexican military, specifically the Secretariat of National Defense, continued to operate these systems independently of civilian oversight. The targets included investigators looking into military abuses, proving that the tools purchased for cartels were weaponized against political accountability. The Mexican case demonstrates that once these capabilities enter a national security apparatus, they are almost impossible to extract.
The New Frontier: Southeast Asia and Africa
The client map expanded significantly between 2021 and 2025. In Southeast Asia, Thailand and Indonesia emerged as major importers. The “GeckoSpy” report from July 2022 confirmed that at least 30 Thai activists involved in pro democracy protests were infected with Pegasus. The timeline of infections perfectly matched periods of intense political unrest, suggesting a direct correlation between surveillance acquisition and domestic crackdown efforts.
Indonesia provided a glimpse into the opacity of the procurement process. An Amnesty International report from May 2024 detailed a labyrinth of shell companies in Singapore and Malaysia used to funnel surveillance tech to Indonesian police and intelligence agencies. This complex purchasing structure allowed the government to acquire tools from multiple vendors, including NSO Group and FinFisher, without public scrutiny.
In Africa, the Predator spyware took root in nations previously untouched by advanced cyber espionage. A March 2024 analysis by Recorded Future identified active Predator infrastructure in Angola, Botswana, and the Democratic Republic of the Congo. The addition of Botswana to this list signaled a disturbing trend: even stable democracies were beginning to procure mercenary spyware for unspecified national security purposes.
The Regulatory Counterattack
The proliferation of these tools eventually triggered a forceful response from Washington. The Biden administration utilized the Entity List as a primary weapon to disrupt the supply chain. In November 2021, NSO Group and Candiru were designated for acting contrary to US national security. This pressure escalated in July 2023 with the designation of Intellexa and Cytrox.
The sanctions reached a peak in March 2024, when the US Treasury imposed financial blocks on Intellexa founder Tal Dilian and his associates. This marked the first time individual executives were personally targeted for their role in the spyware trade. Despite these measures, the demand from client states remains robust. Vendors simply rebrand, restructure, or move their headquarters to jurisdictions with looser regulations, ensuring that the geopolitical flow of surveillance technology continues to outpace the laws designed to contain it.
“`html
VII. Target Profile A: The silencing of investigative journalists and media entities
The image of the government censor seizing printing presses is a relic of the past. In the modern era, the silencing of the press requires no physical force, no padlocks, and no public spectacle. It occurs in the silent, invisible domain of the smartphone. From 2020 to 2025, a digital siege was laid against investigative reporters worldwide. The weapon was military grade spyware, and the target was the very infrastructure of truth.
The Mexican Military Complex (2019 to 2024)
Mexico has long been the deadliest country for reporters outside of a war zone. Yet, parallel to the physical violence, a sophisticated digital apparatus emerged. Despite promises from the executive branch to end illegal surveillance, the “Ejército EspÃa” or “Spy Army” investigation revealed a different reality. In 2023, documents leaked by the Guacamaya collective exposed a secret military unit dedicated to surveillance.
This unit targeted Raymundo Ramos, a human rights defender, and journalists at El Universal. The military intercepted private encrypted conversations regarding extrajudicial executions in Nuevo Laredo. The data showed that the armed forces were not merely monitoring threats but were actively spying on reporters who investigated military abuses. By 2024, the evidence was irrefutable: the state security apparatus had turned its most potent cyberweapons inward.
El Salvador: The Total Surveillance of El Faro
In Central America, the attack on the free press reached a saturation point unseen in other regions. El Faro, the foremost investigative outlet in El Salvador, became the subject of one of the most intense spyware campaigns on record. Between July 2020 and November 2021, the devices of 22 staff members were infected with Pegasus. This accounted for more than half of the entire newsroom.
The intrusion was relentless. Oscar Martinez, the chief editor, had his device compromised at least 42 times. The timing of these infections was precise, often occurring exactly when reporters were investigating government negotiations with the MS 13 gang. This was not random data collection. It was a strategic operation designed to map sources, uncover whistleblowers, and intimidate the editorial board into silence.
“We are not just losing our privacy; we are losing our ability to protect our sources. When they enter our phones, they enter the minds of our newsroom.”
The Predator Scandal in Europe
The illusion that the European Union was a sanctuary for digital privacy shattered with the “Predatorgate” scandal in Greece. Unlike the Pegasus software which is often sold solely to governments, the Predator spyware ecosystem revealed a murky web of commercial entities. In 2022, financial journalist Thanasis Koukakis discovered his phone had been infected after he reported on banking scandals.
The scandal implicated the National Intelligence Service and led to the resignation of the nephew of the Prime Minister. By late 2024, courts began to dismantle the legal attacks against these reporters, but the damage was done. The surveillance had exposed the fragility of source protection in the heart of Europe. Reporters in Greece, Hungary, and Serbia found themselves working under the assumption that their devices were acting as double agents for the state.
Global Proliferation: India, Jordan, and Beyond
The threat landscape continued to expand through 2025. In India, the Editors Guild and global watchdogs flagged the repeated targeting of journalists critical of the ruling party. Following the Pegasus Project revelations of 2021, which identified over 40 reporters as potential targets, new waves of attacks occurred. In October 2023, Apple issued threat notifications to multiple Indian journalists, including Anand Mangnale of the OCCRP, warning them of attacks sponsored by the state.
Similarly, in Jordan, a forensic investigation in early 2024 confirmed the hacking of over 30 individuals, half of whom were journalists. The software was used to intercept calls and location data during periods of civil unrest. Even in 2025, reports surfaced of Serbian journalists being targeted by advanced spyware, proving that the market for these tools remains robust despite international attempts at regulation.
The Chilling Effect
The ultimate goal of this surveillance is not always to arrest or kill. It is to create a climate of fear. When a journalist knows that their phone can turn on its microphone at any moment, they stop meeting sensitive sources. They stop discussing sensitive leads. They engage in censorship by the self. The data from 2020 to 2025 depicts a grim trajectory: the privatization of espionage has made the silencing of dissent cheaper, easier, and harder to trace than ever before.
“`
VIII. Target Profile B: The suppression of political dissidents and activists
January 2026 Analysis
The digital perimeter of modern activism has collapsed. Between 2020 and 2025, the justification for military grade spyware shifted perceptibly from strictly counterterrorism to the political suppression of civil society. Data collected during this five year window reveals a systematic dismantling of privacy for those opposing government policy, with forensic evidence emerging from Southeast Asia, Latin America, and Europe. The tools are no longer reserved for hunting extremists; they are now the primary weapon against the organizer, the lawyer, and the critic.
The Anatomy of the Thai Crackdown
The most illustrative case of this doctrinal shift occurred in Thailand during the democracy protests that began in 2020. A forensic investigation known as GeckoSpy, released by Citizen Lab and local groups in 2022, confirmed that Pegasus spyware infected at least 30 individuals involved in the movement. These were not insurgents but university students, lawyers, and academics.
Prominent figures such as Arnon Nampa and Panusaya Sithijirawattanakul were targeted repeatedly. The infections correlated precisely with key protest dates and fundraising activities. The attackers sought more than just location data; they gained access to encrypted chats, turning the devices of leadership figures into listening posts to map the entire network of dissent. This was not surveillance for public safety but intelligence gathering for political dismantling.
Mexico and the Myth of Reform
In Latin America, the pattern persisted despite executive promises to end the practice. While the Mexican government claimed in 2019 that it had ceased spying on civilians, forensic analysis in 2023 proved otherwise. The target was the Miguel AgustÃn Pro Juárez Human Rights Center, known as Centro Prodh.
Smartphones belonging to staff members were infected with Pegasus while they investigated military abuses. Documents leaked in the Guacamaya hack later confirmed that the army, specifically the Secretariat of National Defense, was the operator behind this surveillance. In one instance, the military used intercepted conversations to obstruct an investigation into extrajudicial executions in Nuevo Laredo. The spyware served as a tool for obstruction of justice, shielding state actors from accountability by compromising the very people charged with oversight.
The European Contagion
The assumption that such tactics were confined to authoritarian regimes dissolved between 2022 and 2024. In Greece, the Predatorgate scandal exposed the use of Predator spyware against opposition politicians and journalists like Thanasis Koukakis. The initial defense, that these were legal wiretaps or private actions, crumbled under scrutiny. The Intellexa alliance, which marketed Predator, operated from Athens with apparent regulatory impunity for years.
By 2024, the scope widened further. Access Now and Citizen Lab revealed that seven Russian and Belarusian journalists and activists living in exile across Europe were targeted with Pegasus. These individuals, seeking safety within the European Union, carried devices that were turned into beacons for their persecutors back home. The borderless nature of digital surveillance means that physical exile no longer guarantees safety.
The 2025 Escalation
The trend continued to accelerate through 2025. An investigation into the “Intellexa Leaks” late that year provided damning evidence of the global trade in these weapons. Amnesty International confirmed in late 2025 that Predator was used to hack a human rights lawyer in Pakistan, specifically in the Balochistan region. This attack demonstrated that despite global outcry and blacklists, the proliferation of mercenary spyware remained robust.
“The chilling effect is the point. When an activist knows their phone is a witness against them, they stop calling sources. They stop organizing. The silence that follows is the true metric of success for these regimes.”
The data from this period paints a unified picture. The “Target Profile B” is no longer an anomaly or an error in targeting. It is a feature. Governments purchase these tools with the specific intent of neutralizing political opposition. By 2025, the distinction between a criminal suspect and a political rival had effectively vanished in the eyes of the surveillance state.
“`html
IX. Collateral Damage: The surveillance of lawyers, family members, and bystanders
When the screen of a smartphone goes dark, the eyes watching from the other side do not blink. For years, the narrative regarding commercial spyware focused on the primary targets: the dissident, the reporter, the politician. But data emerging between 2020 and 2025 reveals a far more insidious reality. The digital dragnet has widened. It now ensnares the intimate circles of those targets, turning wives into unwitting informants and lawyers into transparent vessels for privileged information.
The Family as a Vector
The case of Ahmed Eltantawy, a challenger for the presidency in Egypt, illustrates the ruthless logic of modern surveillance. In 2023, Citizen Lab discovered that his phone was targeted with Predator spyware. Yet the assault did not stop at his own device. Authorities arrested twelve members of his family and supporters. The message was clear: your political ambition will cost your loved ones their freedom.
This tactic of leverage is not unique. Hanan Elatr, wife of the murdered journalist Jamal Khashoggi, fought a legal battle that stretched well into 2025. Her lawsuit against the NSO Group alleged that agents manually placed Pegasus software on her phones while she was detained in the UAE in 2018. The infection of her device was not just about tracking her movements; it was a means to monitor her husband before his death. In May 2025, a United States court ruling in Khashoggi v. NSO Group marked a historic moment, allowing claims to proceed and highlighting how family members are treated as mere extensions of the target.
The Death of Attorney Client Privilege
Perhaps the most erosion of democratic norms is the targeting of legal counsel. In a functioning justice system, the conversation between a lawyer and their client is sacred. In the world of mercenary spyware, it is a goldmine.
In Poland, the lawyer Roman Giertych was hacked at least eighteen times in late 2019, but the forensic confirmation arrived later, shaking the Polish legal community during the investigations of 2022 and 2023. Giertych was not a criminal; he represented Donald Tusk and other opposition figures. By infecting his phone, the operators gained a seat at the table of the legal defense strategy for the political opposition. The breach was total. Every document, every confidential whisper, every strategy note was visible to his adversaries.
A similar violation occurred in the United Kingdom. Baroness Fiona Shackleton, a prominent barrister, was notified that her phone had been targeted with Pegasus while she advised Princess Haya of Jordan during a divorce dispute with the ruler of Dubai. The surveillance of a member of the House of Lords on British soil signaled that no legal shield is strong enough to repel military grade code.
The Bystander Effect
The infection spreads through contact lists, turning bystanders into collateral casualties. In Greece, the “Predatorgate” scandal of 2022 and 2023 exposed a list of ninety two targets. Among them was Artemis Seaford, a manager at Meta. She was not a politician or a radical activist. She was simply a citizen whose professional network overlapped with the interests of the state. Her privacy was stripped away not because of what she did, but because of whom she knew.
“The technology does not distinguish between the guilty and the innocent, or the target and the witness. It simply consumes data. Everyone in the digital radius of a dissident is now fair game.”
In El Salvador, the infection of thirty five journalists at El Faro created a ripple effect. Sources ceased to speak. Family members feared that a call to their son or daughter would alert the police to their location. The phone of the journalist, once a tool for truth, became a radioactive object that endangered anyone it touched.
The data from this half decade paints a grim picture. The state does not need to hack everyone. It only needs to hack the central nodes—the lawyers, the spouses, the children—to illuminate the entire network. Privacy is no longer an individual right; it is a collective vulnerability.
“`
X. Digital Forensics: Methodologies used by Citizen Lab and Amnesty Tech to uncover infections
The discovery of sophisticated spyware on a mobile device is rarely accidental. It is the result of rigorous, obsessive digital forensics. Between 2020 and 2025, research groups like The Citizen Lab and Amnesty Tech revolutionized how civil society detects government backed surveillance. Their methodologies shifted from simple malware scanning to complex forensic architecture analysis, often relying on the very logs intended to help Apple engineers debug software crashes.
The Anatomy of a Crash: Citizen Lab
For researchers at The Citizen Lab, the most valuable evidence often lies in what the phone does when it fails. Modern mercenary spyware, such as NSO Group’s Pegasus, relies on “zero click” exploits. These attacks require no interaction from the victim. To succeed, the spyware must force a legitimate system process to execute malicious code. Occasionally, this process becomes unstable and crashes.
In the 2023 investigation known as BLASTPASS, researchers analyzed the iPhone of a Washington DC based civil society employee. They discovered a recurring crash in the PassKit framework, which handles digital wallet passes. The forensic timeline revealed that the attacker had sent a malicious image via iMessage, forcing the BlastDoor security sandbox to fail. By analyzing the sysdiagnose logs—massive archives of system behavior—Citizen Lab pinpointed the exact moment the exploit triggered. They traced the infection to a specific buffer overflow vulnerability (later patched as CVE 2023 41064), confirming that the device was compromised without the user ever touching it.
Similarly, in investigations involving Paragon’s Graphite spyware in early 2025, analysts looked for anomalies in network traffic logs. They identified a device communicating with a specific IP address (46.183.184.91) immediately after receiving a silent push notification. This correlation allowed them to fingerprint the spyware’s distinct communication protocol, effectively burning the infrastructure used by the attacker.
Automating Detection: Amnesty Tech and MVT
While Citizen Lab often focuses on deep dives into novel exploits, Amnesty Tech democratized the forensic process with the release of the Mobile Verification Toolkit (MVT) in 2021. This open source modular tool allows technologists to parse massive iTunes backups and Android system dumps to hunt for known indicators of compromise (IOCs).
MVT operates by dissecting the internal databases of an iPhone, specifically DataUsage.sqlite and netusage.sqlite. These files record exactly which process used the internet and when. A legitimate process like Safari should browse the web; a system service named com.apple.coretelephony should not be uploading megabytes of data to an unknown server. Amnesty researchers used this method to uncover the Predator spyware in 2023. By cross referencing process names with a list of known malicious domains, they could flag infections even after the spyware had deleted its primary files.
The “Predator Files” investigation further refined this approach. Amnesty discovered that Intellexa’s spyware was often injected via HTTP redirects. When a target visited a benign website using mobile data, a piece of hardware installed at the ISP level would silently redirect the connection to a malicious server. MVT was updated to parse Safari browsing history and identify these split second redirects, providing irrefutable proof of network injection attacks targeting politicians and journalists across Greece and Egypt.
The Artifacts of Silence
The battle has now moved to “forensic evasion.” Spyware vendors effectively wipe their tracks, deleting files and scrubbing logs. However, they cannot easily erase the scars left on the operating system. Forensics teams now look for the absence of data or “impossible” artifacts. For instance, the presence of a GIF file that is actually a PDF containing a JBIG2 stream—a technique used in the FORCEDENTRY exploit—remains a smoking gun. These artifacts, buried deep within the file system, prove that despite the billions of dollars spent on secrecy, the digital traces of surveillance are impossible to completely erase.
XI. Telco Complicity: The role of internet service providers and carrier cooperation
The architecture of global telecommunications has evolved from a neutral conduit of information into a primary vector for state sponsored espionage. Between 2020 and 2025, investigations revealed a disturbing trend where Internet Service Providers (ISPs) and mobile carriers did not merely comply with legal warrants but actively facilitated the delivery of military grade spyware. This complicity ranges from the exploitation of legacy signaling protocols to the direct injection of malicious code into user traffic.
Network Injection and Middlebox Attacks
The most aggressive form of telco complicity involves “middlebox” attacks, where hardware installed within the ISP network manipulates traffic in real time. In September 2023, The Citizen Lab and Google’s Threat Analysis Group exposed a campaign targeting Egyptian presidential hopeful Ahmed Eltantawy. The investigation revealed that his mobile connection via Vodafone Egypt was tampered with using deep packet inspection technology.
Technical analysis identified a Sandvine PacketLogic device located physically within the telecom infrastructure. When Eltantawy visited websites using the insecure HTTP protocol, this middlebox intercepted the request and injected a redirect to a malicious domain. This redirect delivered the Predator spyware, a surveillance tool developed by the Intellexa alliance. This method, known as a network injection, requires the tacit or explicit cooperation of the network operator to place and maintain the injection equipment. It transforms the ISP from a service provider into a weaponized delivery system.
The Active Role of ISPs in Spyware Deployment
While some carriers are unwitting victims of compromised infrastructure, others have played a participatory role. In 2022, Google researchers detailed a campaign involving RCS Labs, an Italian surveillance vendor. In identified cases across Italy and Kazakhstan, the targets had their mobile data connectivity deliberately disabled by their ISP. To restore service, the victims were prompted to install a malicious application disguised as a legitimate carrier support tool. This social engineering tactic relied entirely on the ability of the ISP to manipulate service access at the network level, forcing the target into a vulnerability window where they were desperate for connectivity.
Legacy Protocols as Global Backdoors
Beyond direct injection, the global telecom network remains riddled with vulnerabilities in the Signaling System 7 (SS7) and Diameter protocols. These decades old frameworks allow networks to route calls and texts globally but lack robust authentication. Throughout 2024 and 2025, security researchers documented a resurgence in SS7 exploits used to track the physical location of dissidents and intercept two factor authentication codes.
In July 2025, a report highlighted a surveillance vendor exploiting a new SS7 bypass technique to track phones across borders, circumventing firewalls that operators had supposedly hardened. Despite the US Federal Communications Commission (FCC) demanding stricter oversight in 2024, the interconnected nature of the global telecom grid means that a single vulnerable or complicit carrier in one jurisdiction can jeopardize users worldwide. Intelligence agencies and private surveillance firms continue to lease access to these network entry points, treating global cellular infrastructure as a vast tracking grid.
The Greek Wiretap Scandal
The intersection of legal interception and illegal spyware became undeniable during the “Predatorgate” scandal in Greece. Uncovered in 2022, the affair showed how the National Intelligence Service (EYP) monitored journalist Thanasis Koukakis and opposition leader Nikos Androulakis. Investigations by the Hellenic Authority for Communication Security and Privacy (ADAE) in 2023 probed telecommunication records to verify if “legal” wiretaps coincided with Predator spyware infections. The scandal exposed a dual use strategy: traditional wiretaps via telecom providers were used alongside mercenary spyware to ensure total compromise, with the lines between lawful state surveillance and extralegal hacking completely blurred.
These incidents demonstrate that the telecom sector is no longer a passive bystander. Whether through negligence in securing SS7 nodes, the sale of middlebox access to intelligence agencies, or direct assistance in deploying malware, telcos have become integral components of the modern spyware supply chain.
XII. The Legal Void: Analyzing loopholes in international export controls and dual use technologies
The global trade in weapons grade surveillance technology thrives in the shadows of international law. While nuclear materials and fighter jets are subject to rigid tracking, the sale of spyware like Pegasus and Predator operates within a regulatory gray zone. Between 2020 and 2025, this legal void allowed mercenary spyware vendors to exploit systemic loopholes, moving their digital weaponry across borders with the ease of a software update.
The Failure of Voluntary Regimes
For decades, the Wassenaar Arrangement served as the primary instrument for controlling conventional arms and technologies with civilian and military applications. Yet, throughout the early 2020s, this voluntary framework proved toothless against the modern spyware industry. As a nonbinding agreement, Wassenaar relies on member states to implement their own restrictions. The result was a patchwork of enforcement where profit consistently outweighed human rights.
The paralysis of the arrangement became absolute following geopolitical fractures in 2022. With decision making requiring consensus among all 42 members, including Russia, the body could not update its control lists to keep pace with evolving cyberweapons. This stagnation allowed vendors to categorize invasive intrusion software under innocuous labels like “network analysis tools” or “traffic management systems,” bypassing scrutiny entirely.
The EU Regulation 2021/821: A Paper Tiger
Europe attempted to close these gaps with the Recast Dual Use Regulation (EU) 2021/821, which entered into force in September 2021. The updated law introduced a “catch all” clause (Article 5) intended to stop exports where there is a risk of use in human rights violations. In practice, however, the regulation failed to halt the proliferation of surveillance tools from European soil.
The “Predator Files” investigation in 2023 exposed the depth of this failure. Despite the new rules, the Greek Ministry of Foreign Affairs admitted to issuing two export licenses for the Predator spyware to Madagascar, a nation with a documented history of cracking down on dissent. Furthermore, investigations revealed that Intellexa, the consortium behind Predator, freely transferred assets and technology between jurisdictions. When regulatory pressure mounted in Cyprus, the operations shifted to Greece. When Greece came under scrutiny following the 2022 wiretapping scandal, the corporate structure adapted again, utilizing entities in Ireland, Hungary, and North Macedonia to maintain the flow of sales.
The Corporate Shell Game
The case of the Intellexa Alliance illustrates the sophistication of modern export evasion. Between 2020 and 2024, the consortium utilized a labyrinth of corporate entities to obscure the origin and destination of its spyware. By physically locating headquarters in EU states with lax enforcement while registering financial entities in tax havens like the British Virgin Islands, vendors created a jurisdictional fog that regulators could not penetrate.
Real data from the period highlights the scale of this evasion. In July 2023, the United States Department of Commerce added Intellexa and Cytrox to its Entity List, effectively banning them from receiving American technology. Yet, the companies continued to operate by sourcing components from non American vendors. It was not until March 2024 that the US Treasury escalated the situation by imposing direct financial sanctions on the individuals behind the consortium, including Tal Dilian and Sara Hamou. Even then, the legal battle remained fluid; in December 2025, the US Treasury delisted three executives after they demonstrated separation from the consortium, a move that critics argued softened the deterrent effect.
The Reactive Nature of State Controls
Israel, home to NSO Group, also adjusted its export policies during this window, but only under intense diplomatic pressure. Following the Pegasus Project revelations in 2021, the Israeli Ministry of Defense slashed its list of approved export destinations from 102 countries to just 37. While this ostensibly removed authoritarian regimes like Saudi Arabia and the UAE from the green list, the measure was largely reactive. By the time the restrictions were in place, the technology had already been sold, installed, and integrated into the security apparatus of the excluded nations.
The data from 2020 to 2025 paints a clear picture: the legal frameworks designed to control dual use technologies are obsolete. They target physical goods in a digital world and rely on voluntary compliance in an industry defined by secrecy. As long as jurisdiction shopping remains viable and export licenses are treated as trade secrets rather than public records, the legal void will continue to shelter the architects of the surveillance state.
“`html
XIII. The Chilling Effect: Psychological impacts and censorship of self in civil society
The most enduring damage inflicted by the telecom spyware network is not the data stolen, but the silence it leaves behind. Between 2020 and 2025, the proliferation of military grade surveillance tools like Pegasus and Predator constructed a digital panopticon, trapping journalists, activists, and dissidents in an invisible prison. This psychological containment produces a phenomenon known as the “chilling effect,” where the mere possibility of observation compels individuals to suppress their own speech and behavior. The target is no longer just the device; it is the mind of the user.
The Architecture of Anxiety
The revelation of the Pegasus Project in 2021 exposed over 50,000 potential targets, shattering the illusion of privacy for civil society globally. For those targeted, the psychological toll was immediate and profound. Victims describe a state of hypervigilance, a condition where the brain remains constantly alert to invisible threats. A 2023 report by the Citizen Lab highlighted the experiences of targeted activists who reported symptoms consistent with Post Traumatic Stress Disorder (PTSD), including paranoia, insomnia, and chronic anxiety.
This “always on” surveillance creates a unique form of psychological torture. Unlike physical incarceration, where the boundaries are visible, digital surveillance is boundless. Activists in countries such as El Salvador and Poland reported feeling like they were living in a “Truman Show,” where their most intimate moments were potential fodder for blackmail or public shaming. The knowledge that a microphone or camera could be activated remotely, with zero click or interaction, dissolves the sanctuary of private life. This violation extends to families and friends, causing targets to isolate themselves to protect their loved ones, furthering their psychological distress.
Silence as Survival
The primary objective of these tools is often not to prosecute, but to incapacitate through fear. This leads to profound censorship of the self. By 2024, surveys of journalists in high risk zones revealed a disturbing trend: many were abandoning sensitive investigations not because of direct threats, but because they could not guarantee the safety of their sources. The risk had become too great.
In Thailand, pro democracy protesters targeted during the 2020 and 2021 demonstrations adopted extreme measures, often leaving their devices at home or reverting to analog communication. Yet, this regression limits their ability to organize effectively in a digital world. Similarly, in Jordan, human rights defenders hacked with Pegasus ceased using digital platforms for sensitive work, effectively neutering their advocacy. The spyware does not need to be active to work; the memory of the infection is enough to enforce silence.
The 2024 Apple Notifications: A Global Warning
The scope of this psychological warfare widened significantly in 2024. In April and again in July of that year, Apple sent threat notifications to users in over ninety countries, warning them of attacks by “mercenary spyware.” The shift in terminology from “sponsored by the state” to “mercenary” followed intense diplomatic pressure, yet the impact remained the same. In India, opposition politicians and journalists received these alerts during a critical election year, casting a pall over the democratic process. The notifications served as a stark reminder that the eyes of the state were wide open.
These alerts triggered fresh waves of anxiety. Recipients in Armenia and Serbia reported a sense of helplessness, knowing that despite the advanced security of their devices, they remained vulnerable to tools costing millions of dollars. The psychological message was clear: no one is safe, and no encryption is absolute.
The Normalization of Intrusion
By 2025, the shock of surveillance had given way to a dangerous normalization. The expectation of being watched has become a baseline reality for civil society in authoritarian and illiberal regimes. This acceptance is the final stage of the chilling effect. When dissidents assume their phones are compromised, they limit their discourse to what is acceptable to the state. The vibrant, chaotic, and necessary noise of democracy is replaced by a curated silence.
The damage is measurable in the stories not written, the protests not organized, and the corruption left unexposed. The telecom spyware network has successfully monetized fear, selling not just access to data, but the power to control the psychological landscape of opposition. As the industry evolves, the battle for human rights has moved from the streets to the psyche, where the fight is against the urge to stay silent.
“““html
XIV. Countermeasures and Evasion: Technical defenses, “Lockdown Mode,” and burner culture
The surveillance industry operates on a premise of asymmetry. Companies like NSO Group and Intellexa hoard millions of dollars in “zero day” vulnerabilities, while dissidents often rely on consumer electronics designed for convenience rather than defense. However, the period between 2020 and 2025 marked a significant shift. Targets began adopting sophisticated evasion strategies, forcing spyware vendors to work harder for every infection. This escalation has created a digital arms race where the cost of privacy is now measured in extreme inconvenience and technical isolation.
The Apple Response: Lockdown Mode
The most mainstream technical defense emerged in September 2022 with the release of iOS 16 and a feature Apple called “Lockdown Mode.” This setting was not a marketing gimmick but a structural reduction of the attack surface available to hackers. By disabling complex web technologies like Just In Time (JIT) compilation and blocking incoming invitations from unknown sources, Apple aimed to neutralize the “zero click” vectors preferred by mercenary spyware.
Real world data confirms its efficacy. In April 2023, Citizen Lab analyzed the phones of civil society members in Mexico who were targeted with Pegasus. The researchers discovered that Lockdown Mode had successfully blocked an NSO Group exploit known as “PwnYourHome.” This attack targeted the HomeKit functionality to compromise devices without user interaction. For the first time, investigators saw forensic evidence of a commercial exploit failing against a stock consumer protection feature. The user received a notification that an attempt was blocked, turning a silent infection into a noisy failure for the attacker.
Beyond the Mainstream: Custom Operating Systems
For individuals facing threats from state actors, standard retail software is often insufficient. Between 2023 and 2025, investigative journalists and political targets increasingly turned to GrapheneOS. This hardened operating system, installed on Google Pixel hardware, removes all Google services by default. It implements aggressive memory corruption mitigation and sandboxing that exceeds standard Android protections.
By stripping away the tracking mechanisms inherent in commercial mobile ecosystems, GrapheneOS users reduce their visibility to data brokers and government dragnets alike. The trade is functionality; users often cannot use banking apps or push notifications, forcing them to check encrypted messengers manually. This “pull” rather than “push” communication style renders metadata analysis more difficult for surveillance teams trying to map a target’s social graph in real time.
The Fallacy of Burner Culture
Popular media often depicts the “burner phone” as a silver bullet for anonymity. In reality, modern telecommunications networks make true anonymity nearly impossible with this method. During the 2024 investigative cycle, security researchers noted that “burners” were frequently compromised not by spyware, but by metadata triangulation.
If a dissident purchases a prepaid phone but carries it alongside their primary device, telecom operators can link the two identities through location co-occurrence algorithms. Furthermore, the physical purchase of these devices is often captured on CCTV or linked to a credit card transaction. Advanced persistent threat (APT) groups simply wait for the new SIM card to register on the network, then cross reference its location history with known patterns. Unless the user maintains strict physical separation—never turning the burner on at home or near their primary phone—the device offers zero protection against a competent intelligence agency.
Physical Isolation and Faraday Defense
With software exploits becoming more expensive to deploy, some targets have reverted to physics based defenses. The use of Faraday bags, which block all wireless signals, became standard operational procedure for activists attending sensitive meetings in 2025. These sleeves prevent a compromised device from transmitting audio or location data even if malware is active. However, this defense only works while the device is bagged. Once removed for use, the “store and forward” capabilities of modern spyware allow it to upload cached recordings immediately upon network reconnection.
The ultimate countermeasure remains the most difficult: total disconnection. “Air gapped” workflows, where sensitive documents are viewed only on computers that never touch the internet, have returned to newsrooms and NGO offices. While effective, this approach creates a bottleneck that slows down the very work these groups try to accomplish, proving that the chilling effect of surveillance works even when the spyware fails.
“““html
XV. Conclusion: The future of privacy in the age of AI surveillance and 5G
The era of analog wiretaps and simple phone tracking is rapidly fading into history. As we move through 2025, the convergence of fifth generation telecommunications and artificial intelligence has birthed a new paradigm of control. This is no longer merely about interception but about prediction. The synthesis of these technologies constructs a digital panopticon where privacy is not just violated but rendered structurally impossible for those labeled as dissidents.
The deployment of 5G infrastructure serves as the physical backbone for this new surveillance architecture. While marketed to consumers as a leap in download speeds, the true utility for intelligence agencies lies in precision. Unlike its predecessors, 5G allows for device localization with sub meter accuracy. The introduction of network slicing, a feature intended to create virtual networks for specific industries, has introduced novel vulnerabilities. Research from 2024 indicates that isolation breaches in these slices can allow surveillance tools to bypass standard security protocols, granting operators invisible access to data streams that were previously segregated.
Once this data is harvested, it is fed into systems powered by artificial intelligence. The market for these predictive tools is exploding. Data indicates that the global sector for AI in predictive policing is projected to reach approximately 5.8 billion dollars in 2025. This capital flow suggests a massive shift from reactive investigation to proactive suppression. Algorithms now analyze vast datasets of location history, financial transactions, and social connections to identify potential leaders of protest movements before they even draft a manifesto. The objective is to dismantle opposition networks while they are still in their infancy.
The commercial marketplace for these tools has evolved from a monopoly held by a few giants into a fragmented ecosystem of mercenaries. A significant report by Google in early 2024 revealed that private spyware vendors were responsible for nearly half of all zero day exploits discovered in their products since 2014. This democratization of cyber weapons means that smaller nations and local police forces now possess capabilities once reserved for superpowers. The targeting of Ahmed Eltantawy in 2023 using Predator spyware illustrates this reach. Despite not being a terrorist or a criminal, his phone was persistently infected by a tool sold by the Intellexa alliance, a conglomerate that the United States government placed on a blacklist in July 2023.
Legislative efforts to curb this tide have proven largely symbolic. The Executive Order signed by President Biden in March 2023 attempted to restrict the use of commercial spyware by federal agencies, yet it left gaping loopholes for national security exceptions. Similarly, the European Parliament PEGA committee concluded its investigation in May 2023 with strong condemnations but failed to enforce a total ban. The industry simply adapts. When NSO Group faced scrutiny, competitors like Intellexa and smaller, agile firms filled the void, rebranding their products to evade export controls.
We face a future where the device in our pocket is a permanent informant. The integration of AI does not just record what we say; it interprets what we mean and predicts what we will do next. For dissidents, journalists, and activists, the margin for error has vanished. The fight for privacy in this decade is not about keeping secrets; it is about preserving the very possibility of human autonomy against a network that never sleeps and never forgets.
“`Here are 10 real news references and investigative reports covering the ecosystem of telecom vulnerabilities (such as SS7 exploits) and commercial spyware (like Pegasus and Predator) used by governments to track dissidents.
The Telecom Spyware Network: Tracking Government Surveillance of Dissidents
The following references cover the intersection of commercial spyware vendors (NSO Group, Intellexa), telecom network vulnerabilities (SS7/Diameter), and their use against journalists, activists, and political opposition.
The Guardian (The Pegasus Project):
“Huge data leak shatters lie that spyware is used only to catch criminals” (July 18, 2021).
Investigative report revealing how NSO Group’s Pegasus spyware was used to target human rights activists, journalists, and lawyers worldwide.
The Citizen Lab:
“Running in Circles: Uncovering the Clients of Cyberespionage Firm Circles” (December 1, 2020).
A technical report exposing how governments use “Circles” technology to exploit the global telecom SS7 network to track location and intercept calls without hacking the phone itself.
The Washington Post:
“Private Israeli spyware used to hack cellphones of journalists, activists worldwide” (July 19, 2021).
Part of the Pegasus Project, detailing the forensic evidence of military-grade spyware found on the smartphones of dissidents.
The New Yorker:
“How Democracies Spy on Their Citizens” (April 18, 2022).
Ronan Farrow investigates “CatalanGate,” where over 60 verified targets in the Catalan independence movement were infected with spyware.
The New York Times:
“How the Global Spyware Industry Spiraled Out of Control” (December 8, 2022).
An extensive look at how the spyware industry expanded from counter-terrorism tools to a weapon used by authoritarian and democratic regimes alike against political opposition.
Reuters:
“Exclusive: Senior EU officials were targeted with Israeli spyware” (April 11, 2022).
Report detailing how even top European Commission officials were targeted using NSO Group software, highlighting the reach of the surveillance network.
The Guardian:
“Saudi Arabia exploits US mobile networks to track its citizens” (November 26, 2019).
An investigation into how foreign powers exploit vulnerabilities in the signaling system (SS7) of telecom operators to track dissidents across borders.
Wired:
“Inside the ‘Predator’ Spyware That Is Taking Over Europe” (October 5, 2023).
Coverage of the “Predator Files,” exposing the Intellexa alliance and how alternative spyware vendors are filling the gap left by NSO Group to surveil European journalists.
BBC News:
“Apple sues NSO Group for attacking iPhones” (November 24, 2021).
News report on Apple’s legal action against the spyware maker and their subsequent move to notify victims of state-sponsored attacks.
Amnesty International:
“Massive data leak reveals Israeli NSO Group’s spyware used to target activists, journalists, and political leaders globally” (July 18, 2021).
The primary NGO report accompanying the media investigation, detailing the human rights implications of unchecked telecom surveillance.
“`


































