ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Click

71 pointsposted 2 hours ago
by miohtama

46 Comments

exceptione

2 hours ago

  > Graphite belongs to the same category of commercial surveillance technology as Pegasus, the better-known spyware developed by NSO Group. Both are classified as mercenary spyware, meaning private companies develop and sell them to government intelligence and law enforcement agencies.
This buries the lede a bit. These companies play their part in trans-national organized crime networks, spanning countries like the USA, Russia and Israel. In Russia, it is often hard to delineate between organized crime and the FSB, because these networks overlap and they are often well established within the structures of the state. The same increasingly applies to the USA. ICE is becoming a paramilitary force, "immigration control" is clearly not its only purpose. I cannot unsee this from the massive purges in the military, rooting out the most competent leadership. The parallels with Russia can't be ignored.

saidnooneever

an hour ago

there are many if these companies and toolkits. too many to mention. more than 150 countries spend over 10M a year on _offensive_ cyber. generally making use of such toolkits if they lack inhouse capabilities, which is pretty much all of those countries because the people creating the capabilities will refuse to work for them, so they can sell their tools.

exceptione

27 minutes ago

Yup, but here is the rub: you and me can't buy the real stuff. You have to be a professional law breaker, which means you are in organized crime (don't forget the white collar guys), or you are working for Intelligence, in whatever capacity, in whatever oversight. The problem is that for offensive surveillance organizations the line between crime and work gets blurred quickly. That is why I am not too enthusiastic that our Dutch intelligence agency will receive offensive capabilities as well. Information is power, and you will soon end up with an organization that feels limited by oversight, but that also can easily accumulate means to evade such oversight. Bonus points if people from those kinds of organizations find their way in legislative branches or overseeing powers.

This has been a process of decades. Also surveillance, cybercrime and business do connect. If you look at the history of capital flows in the US, you will see a massive shift of capital from military has been redirected to the surveillance industry. If you would cut out surveillance from the USA economy, things would look quite different. The stock market is heavily skewed towards companies with this business model. As food for thought, think about what the GDP looks like without Apple, Google, Anthropic, OpenAI etc. To give an example of just one facet, Meta alone makes billions on crime each year [1] and will fight toot and nail anyone who dares to threaten their business model of addiction and privacy violation. To continue down this path against the interests of the public, these companies feel confident enough to try their hands at dangerous games [2], of which history teaches us that will always end in tears, because zero-sum is in the end a hunger game.

[1] https://www.reuters.com/investigations/meta-is-earning-fortu...

[2] https://abc45.com/news/nation-world/big-tech-ceos-attend-tru...

strictnein

13 minutes ago

> That is why I am not too enthusiastic that our Dutch intelligence agency will receive offensive capabilities as well

AIVD[0] has had world renowned offensive cyber capabilities for a long time now. They punch _way_ above their weight class, equalling and maybe surpassing the capabilities of countries like Russia, although Russia throws more people at it so they end up with a broader overall impact. It's actually really, really impressive what they've accomplished. You should be proud of it. For example of some of their good work: https://www.zdnet.com/article/dutch-spies-tipped-off-nsa-tha...

"When hackers operating next to Moscow’s Red Square launched an attack against the Democratic Party in 2015, someone was watching. And that someone, according to new reports, was the Dutch General Intelligence and Security Service (AIVD).

Netherlands newspaper de Volkskrant and the public broadcaster NOS reported on Thursday evening that AIVD hackers had penetrated the Russian operation back in the summer of 2014."

More here: https://www.washingtonpost.com/news/worldviews/wp/2018/01/26...

[0] https://english.aivd.nl/

saidnooneever

15 minutes ago

a lot of these companies sell to people with money. its just that ordinary folks cant afford million dollar contracts.

there are varying degrees ofc. not everyone is NSO group or such ex intelligence folks. many sell licenses to red teams and security service providers (and law enforcement in some cases).

private intelligence companies use such tooling to gather information on individuals for business and private customers too.

a lot of toolkits also allow to just add your own exploits via scripting etc. so you can get exploits in 1 place and tooling in another etc.

there are laws, but those are not everywhere, and its unclear whos dealin to who in a lot of cases

headsman771

an hour ago

What is ICE doing besides immigration control?

MSFT_Edging

an hour ago

They're suggesting[1] they'll be attempting arrests at polling locations, which due to the statistics on fraudulent votes(statistically microscopic), equates to interference and intimidation since we know ICE isn't beyond arresting US citizens to harass them. This will have a chilling effect on citizens who are remotely non-white, who may avoid voting in person due to the risks associated with interacting with the under-trained ICE forces.

Additionally, USPS's current plans[2] for purging mail-in votes will disenfranchise the other method of voting.

[1]https://www.democracydocket.com/news-alerts/dhs-chief-says-i...

[2]https://www.cbsnews.com/news/whistleblower-postal-service-ne...

strictnein

39 minutes ago

They're the leading agency in the US involved in stopping human trafficking and child exploitation. Unfortunately the good work they do is being overshadowed by the other nonsensical shit.

MrWiffles

an hour ago

Modern American version of the SS.

wang_li

an hour ago

I know you all are here getting ready for a circle jerk, however ICE stands for Immigration and Customs Enforcement. They monitor all goods and such coming and going from the country.

strictnein

42 minutes ago

They are also heavily involved in stopping human trafficking, preventing child exploitation, etc.

MisterTea

an hour ago

> In Russia, it is often hard to delineate between organized crime and the FSB, because these networks overlap and they are often well established within the structures of the state.

This already applies to the USA where Trump was very likely involved with the mob who were deeply embedded in the fabric of NYC. All of his NYC construction projects were pushed through and built by mobbed up companies. It's obvious he's in bed with anyone who will get him what he wants, criminal or not.

jason-phillips

an hour ago

> I cannot unsee this from the massive purges in the military, rooting out the most competent leadership.

Structural coherence issues aside, is this some sort of a joke, or just thinly veiled personal bias presented as fact?

chii

an hour ago

> ICE is becoming a paramilitary force

this is how the gestapo gets established.

miohtama

2 hours ago

Meanwhile in Serbia

https://citizenlab.ca/research/pegasus-spyware-infection-of-...

"In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware."

Zero clicks are cheap if NSO can afford to go after students.

strictnein

an hour ago

When a company sells a 0-click exploit like that, they don't sell the actual malware/exploit, they sell access to a service or product. The contract will likely have a certain number of attacks with additional infections having a set price of $XXk.

That is how companies like Crowdfense can pay up to $5 million for an exploit. The sell it to some service (or have the service themselves) and generate revenue off of that. The person who sells that exploit gets some of that revenue, they're not getting $5 million up front.

edoceo

2 hours ago

Seems a low price for no-click zero-day infections

miohtama

2 hours ago

They reuse the same zero-days across multiple countries and agencies; Israelis are very efficient at doing business.

edoceo

40 minutes ago

Ok, so they can amortize expense and scarcity. But if they are reusing exploits, why isn't WhatsApp or the phone OS patched? I'm confused how they can be known functional infections, used multiple times, and then not get checked by the vendors? Even not be thwarted by some incidental app-patch. WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix?

strictnein

22 minutes ago

A lot of these exploits don't survive an update, power cycling, etc. Some, if they're done well, may also clean up after themselves.

Doing digital forensics on a restrictive mobile device (like an iphone or decent android phone) is difficult.

> WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix?

Sure, but it's not a simple thing. That's why these exploits can go for millions. If it was easy to "fuzz and fix" these exploits would be worth nothing.

bobowzki

2 hours ago

My first thought too.

teravor

an hour ago

    > Researchers have confirmed Graphite attacks through WhatsApp and iMessage, although the complete method remains secret.

unsurprising that it's closed source software which is vulnerable like this. LLMs can now decompile binaries very efficiently so it's not even security by obscurity anymore.

you really have to screw up to not carefully trace the path of incoming messages to ensure they are processed safely.

josefritzishere

2 hours ago

So NSA Wiretapping is illegal but ICE is ok? This administration is so wantonly criminal.

mc32

2 hours ago

Wait, since when has the NSA stopped collecting data? That assumption is new to me.

tamimio

an hour ago

> The most dangerous infections require no mistake by the target. A zero-click attack works because phones automatically inspect incoming messages and files before displaying them.

It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!! I hope now you know why they keep phone numbers as a mean of identification, all the big tech and advancement in protocols and what not, yet you are still required to have a phone number as an ID “to fight spam, spoiler: it doesn’t”, or even as a 2FA, Canada for example is making a unified login portal to its all government services and the 2FA is only a phone number, how convenient!!

Phone number is the entry point for zero click, but also for tracking you even when your gps is disabled btw, phone modems has their own gnss and they send location to the towers all the time.

To prevent that, keep the phone number in another phone, not your main (keep your main with no sim card), preferably some dummy phone that you will only use when you need to otherwise it’s on airplane mode.

strictnein

25 minutes ago

> "It’s zero click but it needs an entry point, do we know the entry point? Yes of course! It’s the phone number!!"

Sort of, but not really. iMessage, Whatsapp, Signal, etc are the actual entry point. You can use some of those services without a phone number and having your phone number tied to a different device isn't going to protect you. If you had none of those on your phone most of these attacks wouldn't work.

> phone modems has their own gnss and they send location to the towers all the time

Cell modems don't have their "own gnss", nor would it be needed to track people. Cell signal triangulation is what the mobile networks utilize. It is mainly used to help provide location data to emergency services and is accurate enough with three or more towers. They can also do it with two, but then it's a less accurate positioning, with the user's location being in the overlap of the two cells.

empath75

2 hours ago

for people that don't understand how bad ICE is, here is a brief selection of _recent_ news about ICE, this isn't even like the product of an extensive search

Ice buys shock gloves https://www.pbs.org/newshour/nation/a-perfect-tool-for-abuse...

ICE doesn't pay hospital bills: https://www.sfchronicle.com/politics/article/ice-detainee-me...

DOJ blocked federal prosecution of ICE agent in shooting: https://www.propublica.org/article/doj-blocks-charges-ice-ag...

ICE doesn't vet candidates: https://www.nytimes.com/2026/09/03/us/ice-recruits-national-...

ICE agent with history of violent behavior shoots man in Maine: https://www.pbs.org/newshour/nation/ap-report-ice-officer-in...

ICE puts tracking devices on Haitians who were here legally: https://www.nbcnews.com/politics/immigration/haitians-ohio-l...

Haitian student commits suicide after being forced to wear tracking device https://www.nbcnews.com/news/us-news/springfield-ohio-haitia...

ICE Deports Milo Yiannopoulos, to settle some intra-MAGA feud: https://sfist.com/2026/08/28/milo-yiannopoulos-detained-by-i...

Like, that isn't like cherry-picking, it's a five minute scroll through one of my social media feeds.

They are a stain on the US and need to be abolished.

jMyles

an hour ago

Indeed. But when the rubber meets the road, even our community has trouble standing behind people taking direct action to disrupt ICE activities. eg: https://news.ycombinator.com/item?id=48727750

jmyeet

18 minutes ago

Tech in general (including HN) skews right wing. The era of the countercultural social rebel is long over. Now it's largely just people who have the bag defending the status quo and a whole bunch more people who think they'll one day be holding the bag so are defending the status quo. Tech companies are now fundamentally just defense contractors.

There are an awful lot of people who don't hate opression. They simply hate being oppressed. And those are two very different things.

This claim probably upsets a bunch of people who don't want to think of themselves as right wing. They'll point to rainbow flags in their bios at the same time they're the most NIMBY people in the Bay Area and they basically want homeless people to just die.

gadders

2 hours ago

[flagged]

detourdog

an hour ago

The illegal immigrants are not as scary as ICE.

peter422

an hour ago

I’m sure we could come up with a better system than paying extreme amounts of money to detain in terrible conditions non-violent people who were following the rules that were previously given to them.

jmyeet

2 hours ago

> ICE Deports Milo Yiannopoulos, to settle some intra-MAGA feud

This is probably the one valid thing they did. He's truly vile [1]. He's also illustrative of how most undocumented people aren't "sneaking across the border" as the media claims but are simply visa overstayers. Still, Laura Loomer shouldn't have the power to advance his deportation. The story goes that he was in removal proceedings and he didn't show up for his hearing before an immigration judge so was ordered deported in absentia and then ICE picked him up.

Milo Yiannopoulos is just not a hill I'm ever willing to die on.

[1]: https://www.theguardian.com/us-news/2026/aug/30/milo-yiannop...

kijashdkujdfhas

an hour ago

> Still, Laura Loomer shouldn't have the power to advance his deportation.

This is a really key point. Trump operates like a mafia boss. Being in the protected class is a privilege that is fully dependent on the perception of the boss and those close to him. "For my friends everything, for my enemies the law."

It's not a good way to run a country. Did we have perfectly applied rule of law before the Trump era? No, but Trump is bringing us to new extremes of legal inequality.

MSFT_Edging

an hour ago

The real terrifying aspect of this whole story has nothing to do with Milo Vs ICE.

It's the fact that these previously cartoonish figures on Twitter are now wielding some level of power.

People love to say "oh just get off those bad social medias", but that fails to recognize how there is now multiple social media sites exercising a high level of coercion and misinformation that is injecting the previously goofy "it's just online" into real life.

The white nationalism that has been boosted by Elon and co IS REAL. It will have lasting effects on every facet of our society. The people who used to be internet clowns are now deporting their enemies.

I can't emphasize this enough, this is BAD.

There is no one with any level of morals or ethics at the wheel. It makes too much money to tear apart society. You can bring up endless cliches, "mainstream media", "billionaires", "politics". But the fact is, news channels have spent endless hours covering Hassan(the twitch streamer) and avoiding actual news. Nearly every facet of society has been captured to manipulate us, and there is no good ending for any of this.

user

2 hours ago

[deleted]

readthenotes1

2 hours ago

Ehud Baraj, wasn't he a close confidante of Epstein?

tdeck

an hour ago

I assume you mean Ehud Barak? Surely not, or I would have heard about it in the US media for sure.

jason-phillips

an hour ago

This is your daily reminder that orange man bad

idiotsecant

2 hours ago

>Citizen Lab helped WhatsApp identify and block an active Graphite zero-click exploit in late 2024.

How to get murdered by a private equity firm in one easy step.

VladVladikoff

2 hours ago

They’ve been doing this for a while. And actually there’s a pretty great episode of darknet diaries that talks about how they were directly targeted by 8200 agents (taken out to dinner in New York IIRC). They were trying to find dirt on the guy.