20 ms·
ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click
- SomeonesAccount 13d agogreat article, very detailed
- josefritzishere 13d agoSo NSA Wiretapping is illegal but ICE is ok? This administration is so wantonly criminal.
- mc32 13d agoWait, since when has the NSA stopped collecting data? That assumption is new to me.
- SauciestGNU 13d agoIt is statutorily unlawful for NSA and foreign-facing intelligence agencies to target Americans for spying except for in certain specific conditions. This law has long been ignored, but it is on the books.
- mc32 13d agoIt’s orthogonal. Whether legal or not you know they have the data. I think most people were glad authorities were using flock and cell tower data to backtrack and arrest folks involved in the Jan riots. They didn’t push back then cuz they didn’t have the vision to see that it would just grow bigger and get used more commonly almost quotidian. And it will by this admin and by the opposing admins. They all love having data at their disposal. Heck, Congress did nothing about being spied on by our intelligence services.
- edoceo 13d agoSeems a low price for no-click zero-day infections
- bobowzki 13d agoMy first thought too.
- miohtama 13d agoThey reuse the same zero-days across multiple countries and agencies; Israelis are very efficient at doing business.
- edoceo 13d agoOk, so they can amortize expense and scarcity. But if they are reusing exploits, why isn't WhatsApp or the phone OS patched? I'm confused how they can be known functional infections, used multiple times, and then not get checked by the vendors? Even not be thwarted by some incidental app-patch. WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix?
- strictnein 13d agoA lot of these exploits don't survive an update, power cycling, etc. Some, if they're done well, may also clean up after themselves. Doing digital forensics on a restrictive mobile device (like an iphone or decent android phone) is difficult. > WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix? Sure, but it's not a simple thing. That's why these exploits can go for millions. If it was easy to "fuzz and fix" these exploits would be worth nothing.
- idiotsecant 13d ago>Citizen Lab helped WhatsApp identify and block an active Graphite zero-click exploit in late 2024. How to get murdered by a private equity firm in one easy step.
- VladVladikoff 13d agoThey’ve been doing this for a while. And actually there’s a pretty great episode of darknet diaries that talks about how they were directly targeted by 8200 agents (taken out to dinner in New York IIRC). They were trying to find dirt on the guy.
- idiotsecant 13d agoI think the days of nation-corps openly initiating tolerated if not fully legal 'police actions' against people sufficiently disruptive to quarterly results is probably in our not too distant future. A couple generations, at most.
- empath75 13d agofor people that don't understand how bad ICE is, here is a brief selection of _recent_ news about ICE, this isn't even like the product of an extensive search Ice buys shock gloves https://www.pbs.org/newshour/nation/a-perfect-tool-for-abuse-why-experts-are-concerned-about-ices-17-million-electric-shock-gloves-contract https://www.pbs.org/newshour/nation/a-perfect-tool-for-abuse... ICE doesn't pay hospital bills: https://www.sfchronicle.com/politics/article/ice-detainee-medical-care-22384190.php https://www.sfchronicle.com/politics/article/ice-detainee-me... DOJ blocked federal prosecution of ICE agent in shooting: https://www.propublica.org/article/doj-blocks-charges-ice-agent-minneapolis-julio-cesar-sosa-celis https://www.propublica.org/article/doj-blocks-charges-ice-ag... ICE doesn't vet candidates: https://www.nytimes.com/2026/09/03/us/ice-recruits-national-security-risk-whistleblower.html https://www.nytimes.com/2026/09/03/us/ice-recruits-national-... ICE agent with history of violent behavior shoots man in Maine: https://www.pbs.org/newshour/nation/ap-report-ice-officer-in-maine-shooting-has-history-of-violent-behavior-family-and-records-say https://www.pbs.org/newshour/nation/ap-report-ice-officer-in... ICE puts tracking devices on Haitians who were here legally: https://www.nbcnews.com/politics/immigration/haitians-ohio-lost-protected-status-get-ankle-monitors-instead-ice-det-rcna591989 https://www.nbcnews.com/politics/immigration/haitians-ohio-l... Haitian student commits suicide after being forced to wear tracking device https://www.nbcnews.com/news/us-news/springfield-ohio-haitian-student-dies-suicide-ice-mandates-ankle-monit-rcna595552 https://www.nbcnews.com/news/us-news/springfield-ohio-haitia... ICE Deports Milo Yiannopoulos, to settle some intra-MAGA feud: https://sfist.com/2026/08/28/milo-yiannopoulos-detained-by-ice-in-new-orleans-apparently-because-of-laura-loomer-feud/ https://sfist.com/2026/08/28/milo-yiannopoulos-detained-by-i... Like, that isn't like cherry-picking, it's a five minute scroll through one of my social media feeds. They are a stain on the US and need to be abolished.
- gadders 13d ago[flagged]
- catlover76 13d ago[dead]
- 13d ago
- deleted 13d ago[deleted]
- miohtama 13d agoMeanwhile in Serbia https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/ https://citizenlab.ca/research/pegasus-spyware-infection-of-... "In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware." Zero clicks are cheap if NSO can afford to go after students.
- strictnein 13d agoWhen a company sells a 0-click exploit like that, they don't sell the actual malware/exploit, they sell access to a service or product. The contract will likely have a certain number of attacks with additional infections having a set price of $XXk. That is how companies like Crowdfense can pay up to $5 million for an exploit. The sell it to some service (or have the service themselves) and generate revenue off of that. The person who sells that exploit gets some of that revenue, they're not getting $5 million up front.
- readthenotes1 13d agoEhud Baraj, wasn't he a close confidante of Epstein?
- tdeck 13d agoI assume you mean Ehud Barak? Surely not, or I would have heard about it in the US media for sure.
- readthenotes1 9d agoThe media in the US doesn't cover all the Epstein associates for some reason. But he is. For example: https://www.aljazeera.com/news/2026/2/13/former-israeli-pm-barak-responds-to-criticism-over-close-epstein-links https://www.aljazeera.com/news/2026/2/13/former-israeli-pm-b...
- exceptione 13d ago> Graphite belongs to the same category of commercial surveillance technology as Pegasus, the better-known spyware developed by NSO Group. Both are classified as mercenary spyware, meaning private companies develop and sell them to government intelligence and law enforcement agencies. This buries the lede a bit. These companies play their part in trans-national organized crime networks, spanning countries like the USA, Russia and Israel. In Russia, it is often hard to delineate between organized crime and the FSB, because these networks overlap and they are often well established within the structures of the state. The same increasingly applies to the USA. ICE is becoming a paramilitary force, "immigration control" is clearly not its only purpose. I cannot unsee this from the massive purges in the military, rooting out the most competent leadership. The parallels with Russia can't be ignored.
- headsman771 13d agoWhat is ICE doing besides immigration control?
- saidnooneever 13d agocausing misery
- MrWiffles 13d agoModern American version of the SS.
- wang_li 13d agoI know you all are here getting ready for a circle jerk, however ICE stands for Immigration and Customs Enforcement. They monitor all goods and such coming and going from the country.
- strictnein 13d agoThey are also heavily involved in stopping human trafficking, preventing child exploitation, etc.
- 13d ago
- ChrisArchitect 13d agoDoes this article have any information in it from 2026? or is it just a sloppy rehash of information from a year ago. May 2026: DHS says ICE has 'no relationship' with spyware maker Paragon Solutions https://www.npr.org/2026/05/22/nx-s1-5831577/dhs-ice-spyware-paragon https://www.npr.org/2026/05/22/nx-s1-5831577/dhs-ice-spyware...
- jason-phillips 13d ago[flagged]
- teravor 13d ago> Researchers have confirmed Graphite attacks through WhatsApp and iMessage, although the complete method remains secret. unsurprising that it's closed source software which is vulnerable like this. LLMs can now decompile binaries very efficiently so it's not even security by obscurity anymore. you really have to screw up to not carefully trace the path of incoming messages to ensure they are processed safely.
- tamimio 13d ago> The most dangerous infections require no mistake by the target. A zero-click attack works because phones automatically inspect incoming messages and files before displaying them. It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!! I hope now you know why they keep phone numbers as a mean of identification, all the big tech and advancement in protocols and what not, yet you are still required to have a phone number as an ID “to fight spam, spoiler: it doesn’t”, or even as a 2FA, Canada for example is making a unified login portal to its all government services and the 2FA is only a phone number, how convenient!! Phone number is the entry point for zero click, but also for tracking you even when your gps is disabled btw, phone modems has their own gnss and they send location to the towers all the time. To prevent that, keep the phone number in another phone, not your main (keep your main with no sim card), preferably some dummy phone that you will only use when you need to otherwise it’s on airplane mode.
- strictnein 13d ago> "It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!!" Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You can use some of those services without a phone number and having your phone number tied to a different device isn't going to protect you. If you had none of those on your phone most of these attacks wouldn't work. > phone modems has their own gnss and they send location to the towers all the time Cell modems don't have their "own gnss", nor would it be needed to track people. Cell signal triangulation is what the mobile networks utilize. It is mainly used to help provide location data to emergency services and is accurate enough with three or more towers. They can also do it with two, but then it's a less accurate positioning, with the user's location being in the overlap of the two cells.
- tamimio 13d ago> Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You are missing the point, the phone number is what links your identity in real life with the digital one, say you have WhatsApp and only was registered with an email, that email is hard or impossible to link it to you compared to a phone number. This is not about a vulnerability on an app but the points where it’s easy to send something remotely on someone’s phone to have click or zero click attack, knowing it’s them and it’s their phone. > Cell modems don't have their "own gnss", nor would it be needed to track people. Nope, the triangulation method is the old school way, aka old cell phones, new phones send the exact location from the gnss, and cell modems have built in gnss, just grab a quectel and send an AT command after connecting the antennas and you will get precise location, I personally used it in some projects before. Read more about the gnss sent by your phone here, which apple is trying to stop in recent phones. https://an.dywa.ng/carrier-gnss.html https://an.dywa.ng/carrier-gnss.html