Can Cyber Mercenaries and Human Rights Defenders Coexist?

Bill Marczak, Cooper Quintin, Eva Galperin

BSidesSF 2025 — Here Be Dragons · Day 1 · Main

Overview

The panel's opening answer — "no" — barely scratched the surface of a decade-long arms race between spyware vendors and the researchers chasing them. Cooper Quintin (EFF), Bill Marczak (Citizen Lab), and Eva Galperin (EFF) laid out why the commercial spyware industry is structurally incompatible with human rights, traced the industry's geographic drift from Europe to Israel and back to Cyprus and Spain, and closed with sharp commentary on who in Silicon Valley is helping fund the problem today. ---

Watch on YouTube

Visual summary for Can Cyber Mercenaries and Human Rights Defenders Coexist? by Bill Marczak, Cooper Quintin, Eva Galperin
Visual summary for Can Cyber Mercenaries and Human Rights Defenders Coexist? by Bill Marczak, Cooper Quintin, Eva Galperin

Key moments

  1. 9:59 "Turn-key tyranny": mercenaries sell spyware at $1-2M per government
  2. 14:00 FinFisher origins: first major commercial spyware sold to Bahrain and Ethiopia
  3. 17:59 Israel became spyware hub via Unit 8200 IDF alumni founding companies
  4. 24:00 Insight: mercenary industry enables OSINT via LinkedIn and trade shows
  5. 27:59 Western democracies Italy, Poland, Hungary caught using Paragon spyware
  6. 32:00 Key strategy: starve mercenaries of VC funding to shut them down
  7. 35:59 Prediction: Trump admin will enable domestic US cyber mercenary free-for-all
  8. 41:59 Critical definition: mercenaries require payment; hacktivists are categorically different

Can Cyber Mercenaries and Human Rights Defenders Coexist?

Speakers: Bill Marczak, Cooper Quintin, Eva Galperin

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: Watch the full talk

Reading time: ~8 minutes

TL;DR

The panel's opening answer — "no" — barely scratched the surface of a decade-long arms race between spyware vendors and the researchers chasing them. Cooper Quintin (EFF), Bill Marczak (Citizen Lab), and Eva Galperin (EFF) laid out why the commercial spyware industry is structurally incompatible with human rights, traced the industry's geographic drift from Europe to Israel and back to Cyprus and Spain, and closed with sharp commentary on who in Silicon Valley is helping fund the problem today.

Introduction

When three of the most prominent researchers tracking mercenary spyware share a stage, the conversation quickly cuts past diplomatic hedging. At BSidesSF 2025, Cooper Quintin, senior staff technologist at the Electronic Frontier Foundation and Citizen Lab fellow; Bill Marczak, senior researcher at the Citizen Lab at the University of Toronto's Monk School of Global Affairs; and Eva Galperin, EFF's director of cybersecurity — each with over a decade of experience hunting state-sponsored implants — spent an hour dismantling the premise that the commercial spyware industry can ever be adequately regulated.

The talk served as a companion to an earlier session on "tracking the world's dumbest cyber mercenaries," but this panel aimed higher, asking not just who is doing this, but whether the industry itself is salvageable from a human rights perspective. The resounding answer was no — with one important structural caveat that defenders might actually leverage.

The Origin and Architecture of the Mercenary Spyware Industry

▶ Watch: The origin of the industry (4:10)

Galperin traced the industry's genesis to a simple problem: governments want data living on devices they cannot lawfully or practically access. She outlined three paths to that data — asking for it with a court order, sending a subpoena to a platform like Google, or covertly installing an implant. Mercenary spyware exists to industrialize the third option.

"Turnkey tyranny," Galperin called it. A government that lacks a sophisticated offensive cyber program can purchase implant capabilities for as little as one to two million dollars — "authoritarian pocket change" — rather than attempting to recruit and retain a staff of highly specialized engineers in-house. The UAE-linked company Dark Matter illustrated the alternative: offering $400,000 to $450,000 per year to lure ex-NSA talent to Abu Dhabi, only to have some of them balk when the same tools were turned on American citizens.

The first wave of commercial spyware firms emerged from Europe — FinFisher's FinSpy, Hacking Team from Italy — followed by a migration to Israel, where IDF mandatory service and Unit 8200's advanced offensive hacking program created a ready supply of skilled engineers and a startup culture eager to monetize those skills. NSO Group became the most visible example. Paragon Solutions, Marczak noted, has since "eaten a lot of NSO Group's lunch and I think a lot of their former employees as well."

The Geographic Drift and the Plausible Deniability Problem

▶ Watch: Migration to Cyprus and Spain (18:30)

The panel described the current "hot new trend": companies leaving Israel because even the Israeli Ministry of Defense — the regulatory body that must authorize export of offensive cyber tools — has begun applying pressure. The new destinations are Cyprus and Spain, offering looser oversight while still largely drawing on Israeli talent.

This geographic arbitrage is compounded by a structural advantage the industry sells explicitly: plausible deniability. When a device is infected with Paragon malware, Marczak pointed out, the victim knows they have a Paragon infection — but they still cannot determine which government purchased the access. This shields state actors from direct attribution in a way that using their own homegrown tools would not.

Marczak also pushed back on the common framing of "good governments" and "bad governments" as a meaningful dividing line for sales decisions. The Italy cases illustrate the complexity: Paragon spyware was found on the phones of sea rescue activists working in the Mediterranean and a credentialed journalist, Francesco Cancellato. Italian law explicitly prohibits surveillance of accredited journalists, yet the government tacitly acknowledged the sea rescue targeting as "legally authorized preventative security measures" while remaining conspicuously silent on the journalist case.

"The spyware scandals are no longer confined to Bahrains and Ethiopias," Marczak said. Hungary, Spain, Poland, and now Italy — all considered western democracies — have appeared in the reports.

Scaling, Tracking, and the Arms Race

▶ Watch: How researchers track "invisible" spyware (22:00)

How do you track an adversary that advertises itself as "stealth and untraceable"? Marczak described the methodological toolkit: mobile device log analysis, internet scanning and measurement to map command-and-control infrastructure, and open-source intelligence gathered from the mundane realities of running a company. Spyware vendors must give sales demonstrations, which means standing up infrastructure. Operational security lapses — an improperly firewalled server, a demo domain left exposed — leave traces.

Beyond technical breadcrumbs, Quintin pointed to an ironic advantage researchers hold over fully state-run programs: mercenary companies are, by necessity, public-facing businesses. Their employees are on LinkedIn. They attend trade shows. They job-hop between firms, spreading institutional knowledge and creating attribution threads. "Maybe from that perspective for people who are doing threat hunting, it's actually better that they are working in industry," Quintin observed.

The arms race runs in both directions. Defenders — Apple, Google, app sandbox designers — continuously add mitigations. The spyware industry adapts, learns from every public report, and tightens operational security. NSO Group, for instance, has faced export restrictions from Israel's Ministry of Defense as a direct consequence of repeated research exposés, but the business has not collapsed.

Can Any Framework Constrain the Industry?

▶ Watch: The regulation debate (34:00)

Galperin gave what she called "the worst answer" — both yes and no. Her cynical read: bad actors will always find a cyber mercenary willing to sell to them, and when one company is shut down, another often rises with the same people and the same playbook. At the same time, the panel identified real levers.

Removing the industry component dramatically narrows the club of countries capable of conducting sophisticated device-level surveillance. Not every government can develop zero-click exploits internally, but every government can write a check. The Wassenaar Arrangement and the export control frameworks of individual states are imperfect but not meaningless — they impose friction.

The panel was considerably more enthusiastic about a different mechanism: starving companies of venture capital. Many of the firms repeatedly caught selling to authoritarian regimes are funded by US-based VCs. Quintin closed with an explicit call-out of Palantir and a broader indictment of the defense investment portfolio of firms like Andreessen Horowitz. "If we can starve these companies of venture capital," Galperin argued, "it will be much harder for them to exist."

For individuals and organizations that discover they have been targeted, the panel's advice was direct: contact EFF, Citizen Lab, Access Now, or Amnesty International — organizations that investigate even when the target is in a country where US law enforcement will not engage.

Notable Quotes

"You can have turnkey tyranny. It would be great. We'll charge you maybe a million dollars, maybe two million dollars — authoritarian pocket change."

— Eva Galperin, ▶ 8:45

"The spyware scandals are no longer confined to the Bahrains and the Ethiopias of the world. We're seeing more and more so-called western democracies."

— Bill Marczak, ▶ 26:10

"If there is one sort of hard line that former NSA employees sometimes have, it is: we don't spy on American citizens."

— Eva Galperin, ▶ 11:20

Key Takeaways

  • The commercial spyware industry exists specifically to give governments that cannot build their own offensive cyber programs access to device-level implant capabilities — at prices that make it economically attractive compared to building in-house.
  • Geographic migration from the UK and Germany to Israel to Cyprus and Spain is a regulatory arbitrage strategy, not a meaningful shift in the industry's character or clientele.
  • Plausible deniability is a feature that mercenary spyware deliberately sells: even confirmed Paragon infections do not reveal which government purchased the access.
  • Western democracies — including Hungary, Spain, Poland, and Italy — are no longer edge cases in spyware abuse reports; the good-government/bad-government sales distinction is not holding.
  • The most actionable lever for the security community may be scrutinizing the US venture capital funding that sustains these companies and directing victims toward nonprofit organizations like EFF, Citizen Lab, and Access Now for investigation and support.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Three of the most credible researchers tracking mercenary spyware on a single stage — this is the rare panel where the participants actually earned their reputations through years of documented fieldwork. The analysis of plausible deniability as a deliberate product feature, not a side effect, is the sharpest framing I've seen on this problem. The VC-starvation argument at the close is blunt and probably the most actionable thing said all day.

Heather Calloway (CISO) — MUST SEE

Commercial spyware is 'turnkey tyranny' available for authoritarian pocket change, it is being used against western democracies including Italy, Hungary, Spain, and Poland, and US venture capital is helping sustain the industry. Galperin, Marczak, and Quintin name the structural failure with precision: this industry exists because governments can buy what they cannot build, and the regulatory frameworks designed to constrain it are not working.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons