A sophisticated spyware campaign leveraging a zero-click vulnerability in Apple’s iOS has targeted European journalists, marking a significant escalation in digital surveillance against press freedom.
Forensic analysis confirms Paragon’s Graphite mercenary spyware exploited CVE-2025-43200, a critical flaw patched in February 2025 but actively weaponized months earlier.
Apple iOS Zero-Click Vulnerability (CVE-2025-43200)
The attack exploited a logic flaw in iOS that allowed maliciously crafted photos or videos shared via iCloud Links to trigger remote code execution, without requiring user interaction.
Dubbed a “zero-click” exploit, it enabled Graphite spyware to infiltrate iPhones running iOS 18.2.1, leaving no visible traces of infection.
Key technical details:
- Attack Vector: A hidden iMessage account labeled ATTACKER1 delivered the exploit.
- Infrastructure: Compromised devices connected to server
46.183.184[.]91, hosted by EDIS Global, which matched Citizen Lab’s Fingerprint P1 identifier for Graphite. - Patch Timeline: Apple resolved the vulnerability in iOS 18.3.1 (February 10, 2025), but delayed public disclosure until June 11, 2025.
“The zero-click attack deployed here was mitigated as of iOS 18.3.1,” Citizen Lab noted, emphasizing the critical need for timely updates.
Targeted Journalists and News Organizations
Forensic evidence confirms two high-profile cases:
- Prominent European Journalist (anonymous):
- Compromised January–February 2025 via ATTACKER1.
- Device logs revealed sustained communication with Paragon’s server.
- Ciro Pellegrino (Head of Fanpage, it’s Naples newsroom):
- Targeted using the same ATTACKER1 account, linking both cases to a single Paragon operator.
A third journalist, Francesco Cancellato (Fanpage.it editor), received a WhatsApp notification about Graphite targeting in January 2025, though no infection was confirmed.
The pattern suggests a coordinated effort to undermine Fanpage.it’s investigative work.
Impact on Journalism:
- Graphite granted full access to messages, location data, the microphone, and the camera.
- Italian authorities acknowledged using Graphite for “national security” but denied targeting Cancellato, raising accountability concerns.
Risk Factors and Mitigation Strategies
The Graphite campaign highlights systemic vulnerabilities in mobile security.
Below are critical risk factors identified by researchers:
| Risk Factor | Description | Impact |
|---|---|---|
| Zero-click exploit | No user interaction required for infection | High |
| Targeted attacks on journalists | Specific focus on media professionals | Severe privacy breach |
| Undetectable infection | No visible indicators of compromise | Prolonged surveillance risk |
| Delayed patching | Older iOS versions remain vulnerable | Medium |
| Government spyware use | Lack of oversight for mercenary tools | Erosion of democratic safeguards |
Mitigation Recommendations:
- Immediate Updates: Install iOS 18.3.1 or later to patch CVE-2025-43200.
- Enable Lockdown Mode: Restrict non-essential device features to reduce attack surfaces.
- Threat Notifications: Heed warnings from Apple or WhatsApp and seek expert assistance.
The Graphite attacks underscore the dual threat of mercenary spyware and unregulated government surveillance.
While Apple’s patches mitigate immediate risks, the incident highlights urgent needs for transparency, accountability, and international regulations to protect journalists and civil society.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates