# Atlantic Council maps NSO, ENFER, DarkMatter

Published: 2021-03-01 · Severity: low · Sectors: media, government-national, technology, non-profit
Canonical: https://vorant.io/reports/854b4a07-221a-5523-9e13-559298952ed0/atlantic-council-maps-nso-enfer-darkmatter

> A policy report profiles NSO Group, ENFER, and DarkMatter as case studies in the unregulated 'Access-as-a-Service' offensive cyber industry and proposes counter-proliferation measures.

This Atlantic Council report is a policy analysis rather than an incident advisory, examining how commercial 'Access-as-a-Service' (AaaS) firms proliferate offensive cyber capabilities (OCC) to state clients who could not otherwise develop such tools independently. The authors frame OCC development around five pillars—vulnerability research, malware development, command-and-control infrastructure, operational management, and training—and use three vendors as case studies: Israel's NSO Group (maker of the Pegasus surveillance platform, linked via Citizen Lab research to targeting of journalists, activists, and dissidents including Ahmed Mansoor, Al Jazeera staff, and a Catalan independence leader), the Russian contractor 'ENFER' (allegedly operating under FSB direction), and the UAE's DarkMatter (which grew out of Project Raven, a US-Emirati intelligence collaboration).

The report does not describe new active exploitation or a live campaign; instead it argues that existing export-control regimes like the Wassenaar Arrangement only address a narrow slice of OCC proliferation and recommends 'know your vendor' laws, expanded selective disclosure, contracting preferences, post-employment reporting requirements, and technical restrictions like geofencing to curb AaaS firms whose products have been tied to human rights abuses and national security risks. It cites Google Project Zero data attributing 14 of 72 identified in-the-wild zero-days to private firms (Lench IT Solutions/FinFisher, Exodus Intelligence, NSO Group, Hacking Team) and references the Microsoft/Google-backed amicus brief in the WhatsApp v. NSO Group litigation as evidence of growing industry pushback against unregulated spyware sales.

From a threat-intelligence perspective, the value of this report is contextual: it names specific AaaS vendors and their state-customer relationships, which should inform vendor-risk and third-party threat modeling, but it reports no new technical indicators, exploited CVEs, or ongoing operations for defenders to act on directly.

## Mentioned in this report

- Threat actors: DarkMatter Group, ENFER, NSO Group
- Malware: Pegasus
- Campaigns: Project Raven

Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/report/countering-cyber-proliferation-zeroing-in-on-access-as-a-service

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/854b4a07-221a-5523-9e13-559298952ed0/atlantic-council-maps-nso-enfer-darkmatter.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
