Graphite is a spyware and espionage implant name used in two distinct malware contexts. The more widely recognized usage refers to Paragon Solutions’ mercenary mobile spyware platform, which has been linked to highly targeted surveillance of journalists, civil society members, and other selected individuals. Graphite has been associated with zero-click exploitation of Apple devices through Messages and iMessage attack chains, including exploitation mitigated in iOS 18.3.1 and tracked as CVE-2025-43200. Public reporting and forensic investigations have tied Graphite activity to compromises of iPhones and Android devices, with capabilities consistent with full-device surveillance, including access to communications and other sensitive device data. Government customers in multiple countries have been publicly associated with deployments of this platform, and investigations have connected it to targeting in Europe and to WhatsApp notifications sent to affected users. The platform is generally characterized as mercenary spyware sold to government agencies for covert surveillance operations.
A separate malware family also known as Graphite has been documented in Windows espionage operations linked with low-to-moderate confidence to APT28. In that usage, Graphite is a DLL implant deployed in a multi-stage intrusion chain delivered through spearphishing documents exploiting CVE-2021-40444. The implant uses Microsoft Graph API and OneDrive as command-and-control infrastructure, gathers host reconnaissance data, polls cloud-hosted tasking, uploads encrypted results, and can execute shellcode in memory. Reported follow-on activity included deployment of Empire stagers and persistence via COM hijacking. This Windows Graphite variant was used against government and defense-related targets in Western Asia and Eastern Europe and reflects a tradecraft pattern of abusing legitimate cloud services to reduce detection.
Because the Paragon spyware platform is the dominant contemporary reference associated with the name, Graphite is most commonly understood as a mercenary mobile spyware capability, while defenders should remain aware of the separate APT28-linked Windows implant that shares the same name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Another investigation into Paragon’s Graphite spyware found evidence of a sophisticated iMessage-based zero-click attack against an iPhone. Citizen Lab reported that Apple subsequently confirmed the attack had been mitigated in iOS 18.3.1 and assigned it CVE-2025-43200. | In one 2025 investigation, Citizen Lab forensically examined iPhones belonging to journalists who had received Apple’s notifications and found evidence consistent with Paragon’s Graphite spyware.
The infection chain starts with the execution of an Excel downloader, most likely sent to the victim via email, which exploits an MSHTML remote code execution vulnerability (CVE-2021-40444) to execute a malicious executable in memory. | The attack uses a follow-up piece of malware called Graphite because it uses Microsoft’s Graph API to leverage OneDrive as a command and control server.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2022-09-23 ⋅ Cluster25 ⋅ In the footsteps of the Fancy Bear: PowerPoint mouse-over event abused to deliver Graphite implants
Zraniteľnosť bola podľa analýzy The Citizen Lab zneužitá na inštaláciu špionážneho softvéru Graphite od spoločnosti Paragon. Kompromitované mali byť mobilné zariadenia viacerých novinárov v Európe.
Associated Malware & Tools graphon ... Graphican GoGra remsec_strider BirdyClient Grager graphite
“...only a few exceptions, such as the Graphite malware documented by Trellix in 2021...”
33 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Techniques ... Resource Development T1583.001 Acquire Infrastructure: Domains Attackers purchased domains to be used as a command and control. wordkeyvpload[.]net wordkeyvpload[.]org
COPASIR said it verified that to use Paragon’s spyware, an operator has to log in with a username and password, and each deployment of the spyware leaves detailed logs.
WhatsApp discovered and mitigated an active Paragon zero-click exploit... We found clear indications that spyware had been loaded into WhatsApp, as well as other apps on their devices.
In 2023, Citizen Lab documented BLASTPASS, an NSO Group Pegasus exploit chain that targeted iPhones through maliciously crafted iMessage content and was capable of compromising devices without victim interaction.
Multiple entries describe APT28/Pawn Storm/Sofacy campaigns using lure documents, themed emails, and phishing schemes, e.g., “APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme”, “New Spear Phishing Campaign Pretends to be EFF”, and “distribution of emails with 'instructions' on 'updating the operating system'”.
Examples include “PowerPoint mouse-over event abused to deliver Graphite implants”, “BREXIT-themed lure document that delivers ZEKAPAB malware”, “fake NATO training docs to breach govt networks”, and repeated references to lure documents delivering Zebrocy or Seduploader.
logs on the device indicated that it made a series of requests to a server that, during the same time period, matched our published Fingerprint P1.
This led to the installation of a second-stage downloader, followed by Graphite and a secondary payload—PowerShell Empire.
A typical high-end mobile exploit chain might begin with a memory-safety or logic flaw in a remotely reachable parser or service. If the vulnerable component processes attacker-controlled data automatically, exploitation may require no visible interaction from the victim.
The Citizen Lab reported “a growing ecosystem of spyware capability” among Ontario police services, after identifying server infrastructure that indicated potential use of Paragon Solutions’ Graphite spyware by the Ontario Provincial Police.
Paragon appears to silently load their spyware into the device’s existing legitimate apps and processes, which serve as the spyware’s unwitting hosts.
The Citizen Lab reported “a growing ecosystem of spyware capability” among Ontario police services, after identifying server infrastructure that indicated potential use of Paragon Solutions’ Graphite spyware by the Ontario Provincial Police.
due to the fact that Android has limited logs, as well as “efforts by Paragon to delete traces of the infection,” it may be impossible to confirm that.
COPASIR said it verified that to use Paragon’s spyware, an operator has to log in with a username and password, and each deployment of the spyware leaves detailed logs.
The researchers analyzed the unnamed journalist’s devices and found that one of them was infected with Graphite, based on forensic evidence showing that the spyware communicated with a server that the researchers had previously established with “high confidence” was part of Paragon’s infrastructure.
The infrastructure appears to be consistent with a dedicated command and control infrastructure (“Tier 1”)... Pivoting to Tier 2: Paragon and Customer Endpoints... we suspected that they might be run directly from Paragon and customer premises.
Analysis of the BirdyClient malware (Trojan.BirdyClient) revealed that its main functionality is to connect to the Microsoft Graph API and use Microsoft OneDrive as a C&C server mechanism to upload and download files from it.
We named this malware Graphite due to the use of the Microsoft Graph API to use OneDrive as command and control... MITRE ATT&CK Techniques ... T1102.002 Web Service: Bidirectional Communication
MITRE ATT&CK Techniques ... Command and Control T1104 Multi-Stage Channels Adversaries created multiple stages to obfuscate the command-and-control channel and to make detection more difficult. Use of different Empire stagers
Repeated malware-delivery chains such as Zebrocy loaders, Seduploader, Downdelph, Cannon, and Graphite imply staged retrieval of additional payloads after initial compromise.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial mercenary spyware linked to targeted iPhone surveillance; discussed as a previously identified spyware family found on devices of Apple-notified users and associated with sophisticated iMessage-based zero-click attacks.
Implant delivered via abused PowerPoint mouse-over events in a Fancy Bear/APT28 campaign.
An APT28-associated tool identified through shared binary characteristics and code packaging habits linked to PixyNetLoader investigations.
Commercial spyware attributed to Paragon Solutions; the content describes potential use by Ontario Provincial Police based on identified server infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.