ELSEIF
Your brief EB
478 stories from 219 feeds 1271 clusters Refreshed 3 minutes ago next pull 10:42

TECH Signal 133

ICE awards $2 million contract for zero-click phone spyware Graphite

U.S. Immigration and Customs Enforcement has secured a $2 million contract to acquire Graphite, a zero-click spyware that can infiltrate phones via messaging apps without user interaction.

WHY IT MATTERS

Engineers must now consider that even end-to-end encrypted messaging apps can be read if a device is compromised by zero-click spyware. The ICE contract shows that U.S. law-enforcement agencies are procuring such tools, raising questions about oversight and the need for stronger device-level defenses.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Graphite is a zero-click spyware developed by Paragon Solutions that can infect a phone without the target clicking a link or opening an attachment.

02

Once installed, it can retrieve message content from encrypted apps such as WhatsApp and Signal by operating inside the device after the apps decrypt the data.

03

The $2 million ICE contract with Paragon highlights government interest in mercenary spyware and underscores the need for defenses against undisclosed message-parsing flaws.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

The U.S. Immigration and Customs Enforcement agency has entered a $2 million agreement with Paragon Solutions to obtain Graphite, a zero-click spyware tool. Previously, similar capabilities were publicly linked to NSO Group’s Pegasus. This contract marks the first known direct acquisition of such technology by a U.S. federal immigration agency. It shifts the surveillance landscape by giving ICE a commercial off-the-shelf option for covert phone access.

The $2 million figure covers the license, integration, and likely support for deploying Graphite across targeted devices. For software engineers, this means allocating resources to defend against zero-click infection vectors that bypass user interaction. Mitigations may involve updating operating system message parsers, applying vendor patches, and deploying runtime integrity checks. The financial outlay also signals a growing market for mercenary spyware that government buyers are willing to fund.

Graphite’s effectiveness depends on exploiting undisclosed flaws in how phones automatically inspect incoming messages and files. If device manufacturers patch those specific zero-click vulnerabilities, the spyware cannot install without user action. The tool also requires the target to receive a specially crafted message; air-gapped or heavily restricted devices may block the delivery vector. While end-to-end encryption protects data in transit, it does not prevent Graphite from reading decrypted messages inside the compromised device.

Because Graphite is designed primarily to harvest data from messaging applications rather than take full control of the phone, its impact is limited to accessible app data. Engineers should watch for unexpected access to app containers or abnormal data exfiltration from trusted messaging services. Public disclosures from Citizen Lab and WhatsApp warnings show that detection is possible when anomalous behavior is spotted. However, the secrecy surrounding the exact exploit chain makes long-term reliability uncertain for both attackers and defenders.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
military.com via Hacker News ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click Open ↗