By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Graphite spyware used in Apple iOS zero-click attacks on journalists
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Graphite spyware used in Apple iOS zero-click attacks on journalists
Tech News

Graphite spyware used in Apple iOS zero-click attacks on journalists

By admin 4 Min Read
Share
SHARE

Forensic investigation has confirmed the use of Paragon’s Graphite spyware platform in zero-click attacks that targeted Apple iOS devices of at least two journalists in Europe.

Researchers at Citizen Lab say that the victims were a prominent European journalists who requested anonimity and Ciro Pellegrino, a journalist at Italian publication Fanpage.it.

“Our analysis finds forensic evidence confirming with high confidence that both a prominent European journalist (who requests anonymity), and Italian journalist Ciro Pellegrino, were targeted with Paragon’s Graphite mercenary spyware,” reports Citizen Lab.

The attacks occurred in early 2025, and Apple sent a notification to the two victims on April 29 informing that they had been targeted by “advanced spyware.”

The threat actor used Paragon’s Graphite spyware platform to target the victims’ iPhone devices running iOS 18.2.1 and exploit CVE-2025-43200, which was a zero-day vulnerability at the time.

Apple describes the flaw as “a logic issue that existed when processing a maliciously crafted photo or video shared via an iCloud Link.”

The vendor addressed the vulnerability in the next iOS release, 18.3.1, on February 10, by adding improved checks. However, the CVE identifier was added earlier today to the security bulletin .

BleepingComputer has reached out to Apple to clarify the date of fixing the vulnerability but have not received a response at publishing time.

According to Citizen Lab’s analysis, Graphite’s delivery vector was iMessage. The attacker used an account, generically labeled ‘ATTACKER1’  in the research, to send specially crafted messages that exploited CVE-2025-43200 for remote code execution.

This achieved the delivery of the spyware without any interaction from the target, in what is called a zero-click attack, and without producing any visible signs to alert the victim.

Once active, the spyware contacts a command-and-control (C2) server to receive further instructions. In the case confirmed by Citizen Lab, the infected phone connected to https://46.183.184[.]91, a VPS linked to Paragon’s infrastructure.

This IP address was hosted on EDIS Global and was active at least until April 12.

Attribution diagram
<strong>Attribution diagram</strong><br /><em>Source: CitizenLabs</em>

Although little trace was left on the devices, Citizen Lab was able to recover some logs that contained enough evidence to attribute the attacks to Paragon’s Graphite spyware with high confidence.

The same spyware family was “caught” earlier this year in another zero-click attack exploiting a zero-day vulnerability in WhatsApp that targeted other Italian victims.

Italian authorities have confirmed earlier this month multiple attacks against individuals in the country, including journalist Francesco Cancellato and activists Luca Casarini and Dr. Giuseppe “Beppe” Caccia. However, the parties responsible for those attacks are not publicly known at this time.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

You Might Also Like

Surplus Wind End Energy Poverty Alan Wylie of EnergyCloud

What Is a Preamp, and Do I Really Need One?

Your guide to complete visibility

How do you dispose of old batteries? Derry Cronin, Business Development Director of EHS International

CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

TAGGED: Graphite, Graphite Spyware, iMessage, iOS, Italy, spyware, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article The New England Patriots will unveil Tom Brady’s statue at their preseason game on August 8
Next Article New Graphite Design Software: A New Era for 2D Creativity Arrives
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Man Utd 1-1 Wolves: Gary Neville slams "bizarre" Ruben Amorim decision
Sports
Live – Channel Tunnel partially reopens but Eurostar still advises passengers to delay travel
Travel
Here’s The XRP Fractal That Says Price Is Headed To $27
Crypto
Surplus Wind End Energy Poverty Alan Wylie of EnergyCloud
Tech News
‘I opened her door and the wind caught me, and I went flying’: The U.S. Arctic air surge is sweeping northerners off their feet
Business
Nearly 25 Islamic State fighters killed or captured in Syria, US military says
World News
Citi edges closer to Russia exit, bracing for over €1bn hit
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Man Utd 1-1 Wolves: Gary Neville slams "bizarre" Ruben Amorim decision

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Man Utd 1-1 Wolves: Gary Neville slams "bizarre" Ruben Amorim decision
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?