
Intelligence agencies have to adapt to developments in the digital environment. Agencies need to have access to the digital world as it has become a place where population is eventually more active and younger generations are prone to communicate and interact in the digital environment.
As an example of the efforts that intelligence agencies have been doing to catch up with the targets they pursue, a medium size agency has been taken as example. It should be noted that, from Morocco to Scandinavia, all these agencies follow the same pattern.
A mix of self-developed and startup-developed tools is the way these agencies navigate these troubled waters. The main problem they face boils down to exposure that happens regularly due to the warring parties, malware creators and cyber security counterparts.
Much of the research has sifted through the hacked files of the Italian company Hacking Team, now defunct. These companies find it hard to survive after their tools are exposed publicly. The same happened to the NSO Group (Pegasus) that has been sold to other companies.
Here a summary in Spanish.
And the report in English.
The file examines evidence from leaked Hacking Team materials showing a documented procurement relationship between Spain’s CNI and Hacking Team from at least 2008 to 2011, with later contract administration in 2013. It argues that CNI purchased or evaluated offensive cyber capabilities including RCS upgrades, an exploit portal, macOS and iOS target modules, remote mobile infection tools, and Android-related maintenance and licenses. The strongest evidence is a €72,000 2010 package matching procurement documents and invoice records, while the broader ledger shows seven CNI offensive-security entries totaling €340,000. The document emphasizes that these records prove procurement intent and access to capabilities, not actual operational use against specific targets.
The report assesses that CNI’s interest evolved from exploit-driven delivery of remote-control implants toward broader, persistent, cross-platform device access, including mobile systems. It describes the available capabilities as including surveillance of communications, keystrokes, audio, screenshots, browsing history, location, organizer data, and remote-control functions, while repeatedly noting that no files reviewed contain target lists, deployment logs, collected intelligence, or proof of specific operations. The later section places Hacking Team tools in a broader alleged trajectory involving Careto and Pegasus, presenting them as successive generations of malware or spyware capability that reduced the need for user interaction and increased device control, though several claims are framed as suggestive rather than conclusively proven.

Leave a comment