{"id":4621,"date":"2025-06-13T10:05:39","date_gmt":"2025-06-13T10:05:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/13\/graphite-spyware-exploits-apple-ios-zero-click-vulnerability-to-attack-journalists\/"},"modified":"2025-06-13T10:05:39","modified_gmt":"2025-06-13T10:05:39","slug":"graphite-spyware-exploits-apple-ios-zero-click-vulnerability-to-attack-journalists","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/13\/graphite-spyware-exploits-apple-ios-zero-click-vulnerability-to-attack-journalists\/","title":{"rendered":"Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists"},"content":{"rendered":"<p>    Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The advanced Graphite mercenary spyware, developed by Paragon, targets journalists through a sophisticated zero-click vulnerability in Apple\u2019s iOS.<\/p>\n<p>At least three European journalists have been confirmed as targets, with two cases forensically verified.\u00a0The spyware exploited a zero-day vulnerability in iOS that allowed attackers to compromise devices without any user interaction.<\/p>\n<p>The attack leveraged a previously unknown vulnerability in iOS (CVE-2025-43200) that enabled the Graphite spyware to infiltrate devices through iMessage.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>iOS Zero-Click Vulnerability (CVE-2025-43200) Exploited<\/strong><\/h2>\n<p>Forensic analysis revealed that an iMessage account, referred to by researchers as \u201cATTACKER1,\u201d was used to deploy the <a href=\"https:\/\/cybersecuritynews.com\/iphones-zero-click-exploit\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-click exploit<\/a> against multiple targets.\u00a0<\/p>\n<p>The sophisticated nature of this attack meant victims had no way of detecting the infection, as it required no user interaction to execute.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiHF6hb6_1n-jsaNvE-6Q0dmPMUlVorrIwYnOt2PLHNJpjj_qvobx5dXv4K1l-ZPwzNJo_v6bcTAbngTHv37-UpTcTiOB7t6VBpY-9iFTgJVpkP_CtxIhMXPbWCgoB-fG0ShtH4DV24RPt_GRkmgYYTARt4QI41N6dnA3FGT9KbWDFv5gd0li0CW0U14PAf\/s16000\/iOS%2520Zero-Click%2520Vulnerability%2520%28CVE-2025-43200%29%2520Exploited.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Apple iOS infections<\/figcaption><\/figure>\n<\/div>\n<p>Technical analysis of the compromised devices showed connections to a server with IP address 46.183.184[.]91, which researchers have linked to Paragon\u2019s Graphite spyware infrastructure.<\/p>\n<p>The server was hosted on VPS provider EDIS Global and continued matching Citizen Lab\u2019s \u201cFingerprint P1\u201d identifier until at least April 12, 2025.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXedqrFmRBEsZ1LM8qe55iM_z9drApcxfvIWLP3HM75FNZvbnzcYJP7NbPzE8sxb_6k7sOmsKZayObwQaD64_W_WuDASoP4s5gdn_WiCjpz74Sj5Fz3ofzAUCITukSHSiZjSxxcr7Q?key=_b4c7BJrVnbj3rIGarAVQg\" alt=\"\"><\/figure>\n<\/div>\n<p>Notably, Apple has confirmed the vulnerability was patched in iOS 18.3.1, but devices running earlier versions remained vulnerable through early 2025.<\/p>\n<p>\u201cThe zero-click attack deployed here was mitigated as of iOS 18.3.1,\u201d notes the Citizen Lab report, highlighting the critical importance of keeping devices updated against such sophisticated threats.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Targeted Journalists and News Organizations<\/strong><\/h2>\n<p>Among the confirmed targets are a prominent European journalist who requested anonymity and Italian journalist Ciro Pellegrino, head of the Naples newsroom at Fanpage[.]it.\u00a0<\/p>\n<p>Both received notifications from Apple on April 29, 2025, alerting them to potential advanced spyware compromises. Subsequent forensic analysis confirmed the presence of Graphite spyware artifacts on their devices.<\/p>\n<p>Francesco Cancellato, another journalist at Fanpage[.]it, was similarly notified by WhatsApp about being targeted with <a href=\"https:\/\/cybersecuritynews.com\/whatsapp-zero-click-paragon-spyware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Paragon\u2019s spyware<\/a>.\u00a0<\/p>\n<p>The targeting of multiple journalists from the same news organization suggests a deliberate effort to compromise Fanpage.it\u2019s operations.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXf_OHM16sOW-j55BZLzLwvkdncaDMudDEpadxT1wqsPZDiVQ41oEW96j9em56CTsIol2NJraGsxTwt6-J160P5qxiYR4yHwIUtStAi5z3K-wT_mYZedMBevP1k6tLQJYoCcWM9x?key=_b4c7BJrVnbj3rIGarAVQg\" alt=\"\"><\/figure>\n<\/div>\n<p>Citizen Lab researchers <a href=\"https:\/\/citizenlab.ca\/2025\/06\/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a>, \u201cThe identification of a second journalist at Fanpage.it targeted with Paragon suggests an effort to target this news organization.\u201d<\/p>\n<p>The spyware could potentially access messages, location data, photos, and activate microphones and cameras without the victim\u2019s knowledge, posing severe privacy and security risks to the journalists\u2019 sources and work.<\/p>\n<p>The Italian government\u2019s parliamentary committee overseeing intelligence services (COPASIR) published a report on June 5, 2025, acknowledging the use of Paragon\u2019s Graphite spyware against certain individuals, but denied knowledge of who targeted Cancellato.\u00a0<\/p>\n<p>This has raised serious questions about oversight and accountability in the use of mercenary spyware.<\/p>\n<p>Paragon Solutions reportedly offered to assist in investigating the Cancellato case, an offer rejected by Italian authorities citing national security concerns.\u00a0<\/p>\n<p>The Department of Security Intelligence (DIS) stated that providing Paragon such access would damage Italy\u2019s reputation among international security services.<\/p>\n<p>This latest spyware campaign highlights the growing \u201cspyware crisis\u201d affecting journalists worldwide.\u00a0<\/p>\n<p>Researchers said that the lack of accountability available to these spyware targets highlights the extent to which journalists in Europe continue to be subjected to this highly invasive digital threat.<\/p>\n<p>It is recommended that individuals who receive spyware warnings from Apple, Meta, WhatsApp, or Google take them seriously and seek expert assistance from organizations like Access Now\u2019s Digital Security Helpline or Amnesty International\u2019s Security Lab.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong><strong>Automate threat response with ANY.RUN\u2019s TI Feeds\u2014Enrich alerts and block malicious IPs across all endpoints<\/strong>\u00a0-&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=free-vs-paid-ti-feeds&amp;utm_content=plans&amp;utm_term=100625\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Request full access<\/strong><\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apple-ios-zero-click-vulnerability\/\">Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apple-ios-zero-click-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists The advanced Graphite mercenary spyware, developed by Paragon, targets journalists through a sophisticated zero-click vulnerability in Apple\u2019s iOS. At least three European journalists have been confirmed as targets, with two cases forensically verified.\u00a0The spyware exploited a zero-day vulnerability in iOS that allowed attackers to compromise [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-4621","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4621"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4621"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4621\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}