CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • Use Cases

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

Ask AI about aVenture

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
The Secrets of a US Spyware King

From Wired

By Kim Zetter

October 1, 2026

The Secrets of a US Spyware King

The Secrets of a US Spyware King

Spyware maker Paragon Solutions has long positioned itself as the good guy in an industry seemingly filled with bad ones, vowing to never sell its mobile spyware to authoritarian regimes or ones with poor human rights records. It also promises to cut off any customer caught misusing its products against journalists, dissidents, or other non-legitimate targets.

Yet weeks after Paragon, then Israeli-owned, was acquired by the US equity firm AE Industrial Partners in December 2024 and merged with REDLattice—an American offensive cyber firm owned by AE that this week announced plans to go public—WhatsApp alleged that Paragon’s Graphite spyware was used to infect the phones of more than 60 individuals in more than 20 countries, including journalists and activists. Most of the targets were not identified, but the University of Toronto’s Citizen Lab named two journalists and two activists in Italy.

Italian authorities denied misuse. Paragon and its new US owners, despite their zero-tolerance policy for customer abuse of their software, initially declined to comment on the allegations, and reportedly was exploring potential legal action against WhatsApp after the company sent a cease-and-desist letter to Paragon. Within a week, however, Paragon had canceled the two contracts it had with Italy’s domestic and foreign intelligence agencies.

From the outside, it seemed Paragon must have conducted an investigation and verified the allegations before canceling the contracts. But Paragon and RedLattice’s new CEO, Andrew Boyd, now says in an exclusive and surprisingly candid interview with WIRED that the company simply “fired” Italy because it “just was not worth it, from a risk perspective, to maintain the relationship” following the allegations.

In other words, there was no Paragon investigation and no interest in conducting one to determine if the allegations were true—Italian government investigators concluded they were not. Paragon didn’t even follow up with WhatsApp or Citizen Lab to obtain details about the alleged abuse and determine if any contracts in the other countries named by WhatsApp should be canceled as well. More damning, according to critics, is what Boyd revealed next: Paragon has no technical way to know if customers misuse its software, because it can’t see who customers target or the data they extract from targeted devices. It can only learn about misuse if customers admit to it or third parties uncover it. He says WhatsApp and Citizen Lab did the company a great service when they exposed the alleged misuse last year.

Paragon also doesn’t have a “kill switch” to disable customers when misuse occurs. All they can do is halt customers’ 24-hour support and system “updates.” But Boyd says the updates, the nature of which he won’t specify, are frequent and essential to using the spyware, and without them the system is rendered ineffective in about 12 hours.

“Things start falling apart quite quickly,” he says.

Boyd’s comments mark the first time a Paragon executive has spoken in detail about the secretive company or its handling of the Italian affair. He agreed to speak with WIRED now because he says more public discussion is needed about the offensive cyber industry and what it means for a US company to operate responsibly in this space. Prior to the interview, REDLattice founder John Ayers wrote in an email that they were “not looking for a favorable write-up.”

“If the honest assessment is still damning, that's a conversation we're prepared to have,” he wrote.

But Boyd’s admissions reveal that despite priding itself on being better than competitors, Paragon/RedLattice has less oversight and accountability than its most significant one—NSO Group, the Pegasus spyware maker, which has been excoriated for selling its tool to Saudi Arabia and other countries with poor human rights records. According to NSO’s transparency reports, which the company began publishing in recent years in response to criticism, it sets up infrastructure and portals that customers use to infect targets and, like Paragon, can’t see who customers target or detect misuse. But it claims it does have a kill switch to disable a customer’s access to the spyware if allegations of misuse arise, and NSO says its systems keep “tamper-proof” logs to record user activity. Customers are contractually obligated to provide these to NSO if allegations of misuse occur or else face “immediate suspension.”​​

By contrast, Boyd says Paragon customers can enable logging on some systems if they opt to, but Paragon has no access to the logs, nor does it want access. Instead, he says, government oversight bodies can use the logs to investigate allegations of misuse among their agencies, as an Italian parliamentary committee did last year in the case of the Citizen Lab allegations. However, this raises the possibility that a government investigator could lie about misuse if they uncover it in logs.

Rather than see Paragon’s lack of access to logs as an accountability problem, however, Boyd describes it as a selling point: No one would buy their products if the company could see a customer’s sensitive targeting information or logs that contain it.

“There's a balancing act between privacy and security and being able to ensure that our customers are using these things correctly,” Boyd says. “And I think we've landed on the best balance.”

That balance is achieved mostly through careful vetting of customers, he says, and rejecting any country that might be prone to abusing the spyware.

John Scott-Railton, senior researcher at Citizen Lab, which has tracked government misuse of commercial spyware for years, calls the revelations astonishing and the lack of mandatory logging “reckless.”

“What Paragon is saying in several substantial ways means [it has] less oversight, less transparency, less contractual protection against abuses than NSO Group,” he says. “It’s exactly the opposite of the picture that Paragon has painted for itself for years. The CEO admitting that his customers won’t tolerate oversight is refreshing honesty: Accountability is bad for business. And it signals to lawmakers and regulators that the spyware industry cannot be trusted to self-regulate."

Scott-Railton also finds it ironic that Paragon relies on Citizen Lab and others to uncover customer misuse when Paragon actively works to hide its spyware on infected devices and prevent discovery—which inherently includes potential misuse.

“We only find a very, very, very small subset [of infections], and the total numbers are always larger,” Scott-Railton says. “These companies spend millions trying to hide from us.”

US senator Ron Wyden tells WIRED that surveillance tools that lack oversight and transparency are “inevitably abused.”

“It’s easy to claim your powerful hacking tool isn’t being misused if you go out of your way to ensure you don’t know how customers use it,” Wyden says. “The fact that Paragon refuses to audit use of its tool, or even attempt to match the work of a small team of researchers at the Citizen Lab is a massive red flag.”

Israeli Intelligence Roots

Paragon was launched in 2019 by Israeli Brigadier General Ehud Schneorson, former commander of the Israeli military’s signals intelligence group, Unit 8200. He cofounded it with three other 8200 veterans and former Israeli Prime Minister Ehud Barak. Two years later, the company reportedly had no customers but was developing Graphite and hoping to conquer the lucrative US market. But then the US government began cracking down on foreign spyware companies after NSO’s Pegasus and Candiru’s DevilsTongue tools were misused by their customers against government workers, journalists, dissidents, activists, and academics.

The US Commerce Department sanctioned both companies in 2021, and the Israeli government drastically cut the number of countries to which Israeli firms could sell spyware—from 102 countries to 37, excluding Saudi Arabia, the UAE, Morocco and Mexico. Over a year later, the Biden administration and Congress imposed guardrails making it difficult for the US government to purchase foreign-made commercial spyware if it posed a national security risk or could be misused by foreign governments.

By then, Paragon reportedly already had a contract with the Drug Enforcement Agency to combat drug traffickers outside the US, but otherwise could not “make any substantial headway” in the US, Boyd says. So the company began looking for a US buyer to overcome its foreign-ownership handicap. In December 2024, AE acquired it for $900 million. The result is a company that is now American on paper, but is still effectively Israeli. Paragon is a RedLattice company—though Paragon has no working website, and the RedLattice website currently doesn’t mention Paragon—but, according to Boyd, it retains its name and offices in Israel, where it has more than 600 employees. Any Paragon-built products still require licensing approval from the Israeli government to sell abroad, while RedLattice-made products sold to non-US customers are governed by US International Traffic in Arms Regulations.

Nonetheless, the US acquisition has served as an end-run around foreign-ownership guardrails. Once the AE deal closed, Boyd says, “everybody started talking” to them about Paragon products, and Paragon began looking to hire 150 new workers to handle its expected new business.

Ayers, the REDLattice founder, told WIRED in an email that prior to acquisition, REDLattice and AE spent more than two years in discussion with US and allied governments and “didn't move without their buy-in.” But asked whether the government pushed back on the acquisition, Boyd says there were no objections, and no one imposed conditions or governance requirements on them either.

“The US government in any form [was] never going to formally say … we approve this acquisition,” he says. “But they didn't have any discomfort with it. … If the [National Security Council] said, ‘this would be a colossally bad idea,’ we probably wouldn't have gone through with it.”

Less than a year after Paragon merged with REDLattice, NSO Group and Candiru copied their savvy acquisition move. A US investment group acquired controlling ownership of NSO and appointed David Friedman, former US ambassador to Israel under President Donald Trump, as executive chairman. Candiru was acquired by the US-based Integrity Partners. Now all three companies are vying for US contracts.

Boyd, who became CEO of RedLattice and Paragon eight months after the acquisition, gives the companies an edge in the US market. As a former military intelligence officer, State Department diplomat, and director of the CIA’s Center for Cyber Intelligence until retiring in 2023, he has many US government, military, and intelligence community connections to help secure contracts.

During the interview, Boyd was open with many of WIRED’s questions, but also inexplicably opaque with others. He wouldn’t even, for example, confirm that Graphite is the name of a product the company sells or say how many products the combined companies possess. He says only that before the acquisition, Paragon had fewer than five products and together they now have between five and 10. Some of these do “over-the-horizon” data collection (by hacking devices and systems remotely) while others require physical access to targeted devices. He bristles at calling the tools “spyware,” though. He considers them “defensive” tools since, broadly speaking, they help defend against national security and criminal threats. But in truth, they are designed for surveillance, espionage, and possibly even disruptive cyber operations.

Graphite, the only product ever publicly identified, extracts communications from chat applications, particularly encrypted messaging apps such as WhatsApp and Signal. This contrasts with NSO Group’s Pegasus, which can spy on all aspects of a mobile phone, including surreptitiously activating its microphone and camera to spy on targets. Reportedly, Graphite’s capabilities can be expanded through modules, though its full feature set is not publicly known.

WhatsApp and Citizen Lab have reported that Graphite uses a powerful zero-click zero-day exploit to infect phones without user awareness. Boyd won’t say if the companies hunt for zero-day vulnerabilities and develop their own exploits or purchase them from others, but says both Paragon and RedLattice have “substantial” research and development teams. RedLattice’s website says the company has more than 200 “vulnerability research experts.”

In addition to their products, Paragon and RedLattice build bespoke solutions for some customers, and some contracts provide customers with personnel who possess “appropriate clearances” to do a “variety” of tasks. Boyd won’t elaborate on the tasks but says his company doesn’t do offensive operations for customers; it just provides hardware and software. But after the Trump administration recently announced plans to contract with select private companies to conduct offensive cyber operations against cybercriminal groups, he says RedLattice will pursue these contracts.

Customer Vetting

Without the ability to monitor customer activity and detect misuse, Paragon relies on its governance model to prevent abuse. This involves customer vetting and contractual deterrence. Customers, and the countries in which they reside, are vetted by an internal risk committee that Boyd and other board members chair using various criteria to determine if a prospective country or customer might have a negative business or reputational impact on the company.

“We don't want our products to be involved in things that they weren't intended to be used for,” he says.

Boyd wouldn’t provide a full list of the country assessment criteria but mentioned several during the interview: political and government stability, human rights record, corruption-index ratings, strength of a country’s legal system, and whether a potential customer has a track record of adhering to its national laws. He says they lean more toward rejecting countries than approving them. They currently have between 20 and 30 countries on their approved list, and have more than 100 customers in 23 countries.

“I think there's some people that would argue that we're too conservative [about who we’ll sell to],” he says, but notes that “it's better to take a hit on revenue” than sell to countries that could prove detrimental in the long run. (Boyd says, for example, that canceling Italy’s two contracts cost the company “seven figures” in revenue. He would not specify the exact value, but Israeli media have estimated the contracts were worth “tens of millions of dollars.”) In the year since he became CEO, he says a “handful” of countries have been rejected as potential customers but won’t say which ones.

Paragon only sells to the US and select US allies (whether democratic or not) and only to national entities, not state and local governments and police forces. But being a US ally doesn’t guarantee a sale. They won’t sell to Saudi Arabia, even though it’s an ally. After the Saudi government reportedly used NSO’s Pegasus to spy on the fiancé and close associates of Washington Post opinion writer Jamal Khashoggi, who was murdered by Saudi government agents, the Israeli government reportedly asked Paragon to take over the Saudi Arabia contract from NSO Group, but Paragon reportedly refused. Boyd says they still won’t sell to Saudi Arabia, and also says the company has no commercial relationships with any country in the Middle East.

“I think there's very important national security reasons why [the US] would want a close relationship with the Saudis from a nation-state to nation-state level,” he says. But that “does not translate into … this private-sector company having a business relationship with them. … I don't need to get into the why’s, because you probably know the why’s.”

They also won’t sell to Venezuela, even with President Nicolas Maduro gone. “There's too much chaos,” Boyd says, “and it wouldn't fit our risk calculus for other variables.”

Yet the company reportedly signed a lucrative contract in Singapore in 2023 worth tens of millions of dollars. Though an electoral democracy, Singapore imposes significant restrictions on free speech, media independence, and human rights.

The customer vetting, Boyd says, “usually works 99 out of 100 times” to eliminate those who might misuse their tools – the assumption being that if they choose only reputable customers, the customers they choose will act only reputably. For the remaining 1 in 100, the customer contracts and zero-tolerance policy are meant to deter misuse. These prohibit using the tools against journalists, civil society members, opposition politicians, and anyone else who is not the target of a legitimate intelligence or criminal investigation. Also embedded in any system sold to non-US customers is a block that prevents targeting of any person in the US—that is, any number that requires the US +1 country code to dial. US law enforcement agencies who have a warrant can get the block disabled, he says.

What if a US customer let a non-approved country use Graphite to spy on targets? During the first Trump administration, the CIA reportedly purchased NSO Group's Pegasus to give to an East African country to use. Boyd insists they would know if this occurred.

“We know where the system is, because we [help customers] install it and train [them on it]…. And so we would know if it was not installed in the place where they intended it to be,” he insists.

Would they also know if a customer used the tool on their own infrastructure but to spy on behalf of another non-approved country? He says they would, because the majority of customers have similar intelligence, military, or law enforcement backgrounds to RedLattice and Paragon employees, and they have robust relationships with customers. They would have a “sixth sense” if something were “fishy” about a customer, he says.

Boyd insists that the fact that there has been only one allegation of misuse so far is evidence that the company’s vetting and governance model is effective. This, however, ignores the fact that the odds of someone uncovering misuse are low, especially because the company takes care to ensure its spyware won’t be easily detected on infected systems.

All of this, of course, leads to questions about US customers. Based on Paragon’s vetting criteria some might wonder how the current Trump administration would meet it. Given reports of corruption, disregard for the rule of law and Trump’s unveiled threats to use government power against political opponents, fears of misuse by US agencies are not irrational. Asked what the company would do if there were allegations of misuse by a US customer, Boyd said an inspector general or legislative committee would likely investigate the matter, and if they found concrete evidence of misuse, Congress or the company would likely take action.

A year after the acquisition, however, it’s unclear how much US sales have expanded. Shortly before the 2024 acquisition, Paragon signed a $2 million contract with Homeland Security Investigations, a division of US Immigration and Customs Enforcement, to help dismantle foreign terrorist operations and disrupt fentanyl traffickers, And RedLattice has had longstanding contracts with the US Air Force. But no other government contracts for the companies show up in a search of public databases, though classified contracts likely would not appear. Boyd won’t identify customers but indicates the company is particularly interested in Pentagon and CIA contracts.

“There are offices across the national security enterprise that don't even know they need our product yet,” he says. “And I consider that an unaddressed market.”

View original article on wired.com

Most Recent

China's Delivery Robots Are Learning to Tackle the Night Shift

Autonomous vehicle companies believe there's a huge market opportunity in delivering after dark, if the technical challenges can be overcome.

Oct 10, 2026

After 20+ major Japanese companies reported cyber attacks in recent weeks, Japan's NCSH chief says the country is in "a state of emergency in cyber space"

Dozens of targets including car rental operators, barbecue chains and rail group JR East disclose data leaks

Oct 10, 2026

Nvidia is in talks to acquire or invest more into US open-weights AI startup Reflection AI; the deal may be an acquihire to avoid antitrust scrutiny

Donald Trump's administration hopes the company will rival cheap Chinese alternatives such as DeepSeek

Oct 10, 2026

Shenzhen-based DJI and Insta360, accounting for 73% and 20% of global smart camera market in Q2, are vying for the top spot as GoPro's share drops to 3%

DJI and Insta360 engaged in ‘civil war’ to become world's top smart camera maker — The decline of action camera pioneer GoPro …

Oct 10, 2026

Similar Posts

Meta-Led Anti-Terrorism Group Faces Mass Resignation of Expert Advisers

Meta and other tech giants are pushing through structural changes at the Global Internet Forum to Counter Terrorism that outside researchers allege will weaken oversight of an already embattled consortium.

Sep 28, 2026

An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.

Sep 18, 2026

The UK's MI5 issues a rare espionage alert urging UK universities to cut ties with the China General Technology Research Institute, which funded AI research

China General Technology Research Institute has ‘very strong ties’ to Chinese intelligence, says UK agency in unusual espionage alert

Sep 30, 2026

OpenAI’s A.I. Went Rogue and Meddled With U.S. Government Websites - The New York Times

The company did not learn until recently that its technology had meddled with websites for the Education Department …

Sep 25, 2026