Sign in

Bill Marczak

@billmarczak.org
12K followers 179 following 42 posts

senior researcher at @citizenlab.ca

PostsRepliesMedia
Reposted by Bill Marczak
Hong Kong Free Press HKFP @hongkongfp.com · 09/02/2026
Hong Kong pro-democracy media tycoon Jimmy Lai has been jailed for 20 years following his foreign collusion and sedition conviction. In full: buff.ly/6FeYWmm
buff.ly
Hong Kong pro-democracy media tycoon Jimmy Lai has been sentenced to [years] in jail following his conviction of foreign collusion and sedition charges.
Hong Kong pro-democracy media tycoon Jimmy Lai has been jailed for XX years following his foreign collusion and sedition conviction.
32724
Bill Marczak @billmarczak.org · 20/10/2025
The attack in question was reportedly in 2022, and while we can imagine there's a plausible way they might have figured this out (via analysis of published Operation Triangulation infrastructure from Kaspersky), there are (seemingly) unfortunately no IOCs available at this time
011
Bill Marczak @billmarczak.org · 20/10/2025
Now this is (perhaps) interesting, it seems like China's MSS believes that some CN Gov folks were targeted w/ a (presumably) zero-click exploit through a "foreign" messaging app. They attribute to US NSA (though no mention of why they attribute this way)
reuters.com
China accuses US of cyber breaches at national time centre
The ministry said it found evidence tracing stolen data and credentials as far back as 2022.
263
Bill Marczak @billmarczak.org · 16/10/2025
We were also able to identify a second (unpublished) iOS threat actor (not NSO) who likely used the same persistence exploit *code* (shared strings), and a third (unpublished) iOS threat actor who likely used the same telemetry-disablement *code* as both.
020
Bill Marczak @billmarczak.org · 16/10/2025
Not to spoil too much, but the underlying issue was a type confusion vulnerability in Foundation during NSKA deserialization of "StrideCalibrationDataBins" in locationd's "user.plist" file that it loads on start. Silently patched in 10.3.3.
100
Bill Marczak @billmarczak.org · 16/10/2025
Watch the video to learn about @droethlisberger.bsky.social's hard-core reverse engineering: he essentially wrote an emulator for a significant chunk of iOS 10 internals to reveal the exploit's secrets!
100
Bill Marczak @billmarczak.org · 16/10/2025
Of course, there's ~no capital-P persistence on iOS (i.e., you can't "just launch" your malicious binary on reboot), so the game is reinfect-on-reboot, either by pushing a remote exploit, or by causing the phone to pull/process an exploit on reboot.
100
Bill Marczak @billmarczak.org · 16/10/2025
The video of @droethlisberger.bsky.social and my @reconmtl.bsky.social 2025 talk, "A Trip to Ancient BABYLON", is now online! It's a fun story about a 2017-era iOS persistence exploit that we found in a Pegasus sample -- on VT (!!)
youtube.com
Recon 2025 - A Trip to Ancient BABYLON: Unearthing a 2017 Pegasus Persistence Exploit
YouTube video by Recon Conference
164
Reposted by Bill Marczak
eileen chengyin chow @chowleen.bsky.social · 27/09/2025
The South Korean Ministry of Defense has awarded medals of merit to 11 officers for disobeying direct orders of superiors during the martial law fiasco, orders that they deemed to be contrary to the constitution and endangerment to democracy. www.chosun.com/english/nati...
chosun.com
National Defense Ministry Honors 11 Soldiers for Refusing Illegal Orders
National Defense Ministry Honors 11 Soldiers for Refusing Illegal Orders Honored for rejecting illegal orders during martial law, Marine death probe
392197596106
Bill Marczak @billmarczak.org · 29/08/2025
Was a big mystery as to how/why CVE-2025-43300 came to be the only part of the chain that was patched on iOS. Now we know: it was actually a WhatsApp attack!
050
Bill Marczak @billmarczak.org · 29/08/2025
WhatsApp just announced they patched a very fun zero-click bug (CVE-2025-55177)! WhatsApp assesses that it was used partially in conjunction with the iOS RawCamera DNG vulnerability (CVE-2025-43300). www.whatsapp.com/security/adv...
1103
Bill Marczak @billmarczak.org · 29/06/2025
Excited to talk today at @reconmtl.bsky.social with @droethlisberger.bsky.social about a 2017 iOS persistence exploit used by NSO's Pegasus (and, interestingly, other threat actors too)! 10:00AM in the Grand Salon cfp.recon.cx/recon-2025/t...
0115
Bill Marczak @billmarczak.org · 20/06/2025
Remember when Meta published about an ITW FreeType OOB write vuln (CVE-2025-27363) in March? Turns out, Meta links this vuln to an exploit from spyware vendor Paragon www.securityweek.com/freetype-zer...
securityweek.com
FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks
WhatsApp told SecurityWeek that it linked the exploited FreeType vulnerability CVE-2025-27363 to a Paragon exploit.
099
Reposted by Bill Marczak
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 12/06/2025
Today we’re publishing new findings on Predator spyware, still active despite global sanctions, now with a new client and ties to a Czech entity. Here’s what we found 🧵 www.recordedfuture.com/research/pre...
recordedfuture.com
Predator Spyware Resurgence: Insikt Group Exposes New Global Infrastructure
Despite sanctions and global scrutiny, Predator spyware operations persist. Insikt Group reveals new infrastructure links in Mozambique, Africa, and Europe, highlighting ongoing threats to civil socie...
11912
Bill Marczak @billmarczak.org · 13/06/2025
This means if we see two devices targeted by the same Paragon attacker account (e.g., ATTACKER1), we can surmise that both targets were targeted by the _same_ Paragon customer/operator, as in this case.
020
Bill Marczak @billmarczak.org · 13/06/2025
Based on our understanding of typical mercenary spyware operations, a spyware company (e.g., Paragon) will register the attack accounts (e.g., ATTACKER1) and distribute credentials for a given account only to infrastructure exclusive to a single customer/operator.
120
Bill Marczak @billmarczak.org · 13/06/2025
We found the ATTACKER1 account present on the second journalist’s phone, i.e., the phone of Fanpage.it journalist Ciro Pellegrino. The steps of our attribution argument are outlined in our diagram:
120
Bill Marczak @billmarczak.org · 13/06/2025
Anyhoo, around the same time this same phone was making these requests, it was silently communicating with an iMessage account (which we redact as "ATTACKER1"). We conclude that ATTACKER1 deployed a sophisticated zero-click attack against the device. Apple (silently) mitigated it in iOS 18.3.1:
120
Bill Marczak @billmarczak.org · 13/06/2025
And there’s a clear chain of shared behavior leading from Fingerprint P1 back to other IPs that previously returned pages entitled "Paragon" and a TLS certificate with the terms "Graphite" and "installerserver".
130
Bill Marczak @billmarczak.org · 13/06/2025
Basically, one of the phones sent multiple requests to IP 46.183.184[.]91, an IP that we linked with high confidence to Paragon’s Graphite spyware infrastructure. We were able to make this link because 46.183.184[.]91 matched our Fingerprint P1 (seen here in Censys search syntax)
150
Bill Marczak @billmarczak.org · 13/06/2025
ICYMI, yesterday we released a report providing a first look at how we found traces of spyware on two journalists' iPhones, traces which we can attribute with high confidence to Paragon's Graphite spyware:
citizenlab.ca
Graphite Caught: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab
On April 29, 2025, a select group of iOS users were notified by Apple that they were targeted with advanced spyware. Among the group were two journalists who consented to the technical analysis of the...
24424
Reposted by Bill Marczak
Raph Levien @raphlinus.bsky.social · 19/03/2025
New blog post up on the Rust font loader now shipping in Chrome. I only had a small part in this personally but am proud of the team's work. developer.chrome.com/blog/memory-...
developer.chrome.com
Memory safety for web fonts  |  Blog  |  Chrome for Developers
Learn how and why the Chrome team has replaced FreeType with Skrifa.
310726
Bill Marczak @billmarczak.org · 19/03/2025
Check out our new @citizenlab.ca report today on Paragon! We got a tip from a collaborator, used it to map out Paragon's infrastructure, and shared with Meta. WhatsApp was able to capture & burn a zero-click, and sent out notifications to targets citizenlab.ca/2025/03/a-fi...
citizenlab.ca
Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations - The Citizen Lab
In our first investigation into Israel-based spyware company, Paragon Solutions, we begin to untangle multiple threads connected to the proliferation of Paragon's mercenary spyware operations across t...
0123
Bill Marczak @billmarczak.org · 28/02/2025
Nice work by Amnesty Security Lab & Google TAG patching three vulnerabilities in Android/Linux kernel USB device drivers that Cellebrite was using to unlock Android devices. Also, it's *scandalous* that Android doesn't have a USB restricted mode like iPhone... securitylab.amnesty.org/latest/2025/...
securitylab.amnesty.org
Cellebrite zero-day exploit used to target phone of Serbian student activist - Amnesty International Security Lab
Amnesty International’s Security Lab uncovers sophisticated Cellebrite zero-day exploit, impacting billions of Android devices.
0196
Bill Marczak @billmarczak.org · 10/02/2025
Update your iPhones.. again! iOS 18.3.1 out today with a fix for an ITW USB restricted mode bypass (via Accessibility) support.apple.com/en-us/122174
35634
Bill Marczak @billmarczak.org · 15/01/2025
President Yoon arrested for masterminding martial law plot
koreajoongangdaily.joins.com
President Yoon arrested for masterminding martial law plot
The Corruption Investigation Office for High-ranking Officials (CIO) on Wednesday arrested impeached President Yoon Suk Yeol, marking the first time a sitting president has been arrested in Korean his...
2222
Bill Marczak @billmarczak.org · 10/01/2025
Excellent @eff.org piece on how data brokers get ads-related data to sell (to spyware vendors, etc.) This is something that always mystified me, but after reading this I finally get it!
eff.org
Online Behavioral Ads Fuel the Surveillance Industry—Here’s How
Each time you see a targeted ad, your personal information is exposed to thousands of advertisers and data brokers through a process called “real-time bidding” (RTB). This process does more than deliv...
04121
Reposted by Bill Marczak
Vas Panagiotopoulos @vaspanagiotopoulos.com · 08/01/2025
NSO Group co-founder & owner Omri Lavie speaks about the recent US judge's WhatsApp ruling, the acquisition of competitor Paragon Solutions by AE Industrial Partners & the US-blacklisting of Pegasus spyware maker, amidst shifting 🇺🇸policy under Trump. 👇 vaspanagiotopoulos.substack.com/p/nso-group-...
vaspanagiotopoulos.substack.com
NSO Group owner: “We will appeal, justice was not served.”
NSO Group co-founder and majority owner Omri Lavie breaks silence amid legal battles and anticipated US policy shift under Trump.
184
Bill Marczak @billmarczak.org · 04/01/2025
Rinson Jose's uncle says Jose emailed his family, claiming to be back in Norway, and with a new job.
timesofindia.indiatimes.com
'Am fine': Kerala-born Norwegian contacts kin after pager blasts probe | India News - Times of India
India News: A Norwegian citizen from Kerala, Rinson Jose, has been cleared by Norwegian police of any involvement in the September 2024 pager blasts in Lebanon. J
010
Bill Marczak @billmarczak.org · 29/12/2024
The article:
nytimes.com
Behind the Dismantling of Hezbollah: Decades of Israeli Intelligence
A Times investigation shows how extensively Israel penetrated the Lebanese militia, closely tracking the group’s commanders and culminating in the assassination of its leader, Hassan Nasrallah.
040
Bill Marczak @billmarczak.org · 29/12/2024
One interesting detail about our guy Rinson Jose in the new NYTimes article on the pager operation: Israel pressured the US to let Jose flee (though unclear anyone would have stopped him). Still no word on to what extent Jose was aware of the operation.
131
Reposted by Bill Marczak
The Washington Post @washingtonpost.com · 22/12/2024
Tesla is deeply reliant on China, both for manufacturing and sales. But now that its CEO has an official role in the Trump administration, things could get tricky.
washingtonpost.com
China loves Elon Musk and his hustle — but Trump could complicate that
Tesla is deeply reliant on China, both for manufacturing and sales. But now that its CEO has an official role in the Trump administration, things could get tricky.
4328787
Reposted by Bill Marczak
Kirsten Han 韩俐颖 @kirstenhan.com · 23/12/2024
Happy holidays to me, I guess
54517
Bill Marczak @billmarczak.org · 23/12/2024
Still no detail on the supply chain for the non-exploding pager components (do we really believe Mossad has a facility to manufacture circuit boards, etc., for pagers?) and not much color on the roles of the various shell companies beyond BAC, whose purpose was said to have been to dupe Gold Apollo
020
Bill Marczak @billmarczak.org · 23/12/2024
Another interesting bit of color: when the guy who developed the exploding pager took it to the Mossad director, the director rejected it, thinking no one would buy it because it was too bulky/ugly. But, turns out, it was just barely good enough that Hezbollah didn't think to ask too many questions.
120
Bill Marczak @billmarczak.org · 23/12/2024
One slightly new detail: the Taiwanese saleswoman (whose name was published in Taiwanese media) was apparently selling (non-exploding) pagers to Hezbollah even before the Mossad (covertly) recruited her (!) Also, she gave Hezbollah the first batch of the (exploding) AR-924 pagers for free.
110
Bill Marczak @billmarczak.org · 23/12/2024
Not many new tangible facts in this CBS News report about the exploding pagers operation. But it was interesting to see that Mossad gave Lesley Stahl an AR-924 pager (or at least the outer casing) -- presumably minus the explosive battery.
cbsnews.com
How Israel's Mossad tricked Hezbollah into buying explosive pagers | 60 Minutes
Pagers exploded across Lebanon in September. Retired Mossad agents, key to the operation, tell 60 Minutes Israel's plot started years ago with getting Hezbollah terrorists to buy walkie-talkies.
181
Bill Marczak @billmarczak.org · 21/12/2024
Summary judgement for WhatsApp in the NSO "missed call hack" case! The judge found NSO did not meet discovery obligations (in part b/c they did not suitably produce code for their custom WhatsApp client used in the hacks). Thus, a number of key evidentiary questions were resolved in WhatsApp's favor
courtlistener.com
Order on Administrative Motion to Consider Whether Another Partys Material Should Be Sealed AND Order on Discovery Letter Brief AND Order on Discovery Letter Brief AND Order on Discovery Letter Brief ...
ORDER by Judge Hamilton re 397 Motion for Summary Judgment; 401 Motion for Summary Judgment; 406 Motion for Sanctions. (pjhlc3, COURT STAFF) (Filed on 12/20/2024) (Entered: 12/20/2024)
02011
Bill Marczak @billmarczak.org · 16/12/2024
Everything old is new again 🙂
040
Bill Marczak @billmarczak.org · 16/12/2024
Google Project Zero also out with an interesting report on a series of Android (Qualcomm DSP) privilege escalation exploits they managed to burn based on crash logs that Amnesty Tech recovered from devices that the Serbian police unlocked with Cellebrite's forensics product.
googleprojectzero.blogspot.com
The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit
Posted by Seth Jenkins, Google Project Zero This blog post provides a technical analysis of exploit artifacts provided to us by Google's Thr...
060
Bill Marczak @billmarczak.org · 16/12/2024
Pretty clever tactic by Serbian police - apparently they rolled their own very simple Android spyware (NoviSpy), then confiscated and unlocked phones (sometimes using Cellebrite's forensics product) and manually sideloaded the spyware APK onto the devices!
amnesty.org
Serbia: Authorities using spyware and Cellebrite forensic extraction tools to hack journalists and activists
Serbian authorities are using spyware and Cellebrite forensic extraction tools to hack journalists and activists in a surveillance campaign.
2188
Bill Marczak @billmarczak.org · 15/12/2024
Interesting! Though this is going to drive up BigQuery costs for Certificate Transparency queries 🙁 letsencrypt.org/2024/12/11/e...
letsencrypt.org
A Note from our Executive Director
This letter was originally published in our 2024 Annual Report. The past year at ISRG has been a great one and I couldn’t be more proud of our staff, community, funders, and other partners that made i...
021
Bill Marczak @billmarczak.org · 13/12/2024
Another interesting case of leveraging petty crime for OPSEC (perhaps unintentional this time tho?) Reminds me of how the Hacking Team hacker used a drug addict to buy Bitcoin gift cards to rent servers
040
Reposted by Bill Marczak
The Citizen Lab @citizenlab.ca · 05/12/2024
NEW REPORT: In a joint investigation with The First Department, we uncovered spyware covertly implanted on the phone of a Russian programmer following his release from Russian custody. citizenlab.ca/2024/12/devi...
citizenlab.ca
Something to Remember Us By: Device Confiscated by Russian Authorities Returned with Monokle-Type Spyware Installed - The Citizen Lab
In a joint investigation with The First Department, The Citizen Lab uncovered spyware covertly implanted on the phone of a Russian programmer following his release from Russian custody. The Monokle-li...
34725
Reposted by Bill Marczak
The Citizen Lab @citizenlab.ca · 02/12/2024
NEW REPORT: We investigate the rising trend of gender-based digital transnational repression by drawing on the lived experiences of 85 women human rights defenders living in exile across the globe. Read the full report: citizenlab.ca/2024/12/the-...
citizenlab.ca
No Escape: The Weaponization of Gender for the Purposes of Digital Transnational Repression - The Citizen Lab
Building upon our prior research and the contributions of other scholars to this field, the aim of this novel study is to understand the security risks and harms caused by digital transnational repres...
417298
Bill Marczak @billmarczak.org · 27/11/2024
Very cool! This will save threat hunters a lot of time.
072
Bill Marczak @billmarczak.org · 27/11/2024
smithsonianmag.com
The Curious Case of Charles Osborne, Who Hiccupped for 68 Years Straight
A 1922 accident sparked the Iowa man’s intractable hiccups, which suddenly subsided in 1990
220
Bill Marczak @billmarczak.org · 26/11/2024
Oh that's interesting, I never noticed that, but I see that even with LDM disabled, these USPS spam links aren't clickable. I wonder if that really applies to _all_ incoming iMessages from non-contacts you haven't interacted with or whether there's a more nuanced decision that the app makes there.
100
Bill Marczak @billmarczak.org · 26/11/2024
Is this because iMessage has detected it as spam or because you're using LDM?
100