VORANT. Threat Intelligence Sign in Get the full feed

Report exposes NSO, ENFER, DarkMatter access brokers

low threat government-nationaldefensemediatechnologytelecommunications

Atlantic Council report profiles NSO Group, ENFER, and DarkMatter as commercial Access-as-a-Service firms proliferating offensive cyber capabilities to states, and proposes counterproliferation policy.

This Atlantic Council report examines the 'Access-as-a-Service' (AaaS) industry, in which private firms sell offensive cyber capabilities—vulnerability research, malware, command-and-control infrastructure, operational management, and training—to government clients, primarily intelligence and security services. The authors argue that this commercial market, operating in semi-regulated jurisdictions, has become a major vector for the proliferation of offensive cyber capabilities (OCC) that existing export-control regimes like the Wassenaar Arrangement fail to adequately address.

Three case studies anchor the analysis: NSO Group (Israel), whose Pegasus spyware has been linked by Citizen Lab research to surveillance of journalists, activists, and dissidents, including the 2020 Al Jazeera staff hacks attributed to UAE- and Saudi-linked operators (dubbed SNEAKY KESTREL and MONARCHY); ENFER, an alleged contractor to the Russian FSB/MoD operating at the boundary of criminal and state-sanctioned markets; and DarkMatter, a UAE firm that grew out of Project Raven and recruited former US intelligence personnel to build independent offensive capability for Emirati intelligence services. The report notes that fourteen of the seventy-two publicly attributed in-the-wild zero-day exploits tracked since 2014 originated from private commercial vendors (including NSO Group, Hacking Team, FinFisher/Gamma Group, and Exodus Intelligence) rather than states.

The report is a policy analysis rather than a technical incident report, closing with recommendations for governments to 'understand, shape, and limit' AaaS proliferation—via know-your-vendor laws, expanded selective disclosure, contracting preferences, post-employment reporting requirements for intelligence personnel, and technical restrictions such as geofencing. No active exploitation, specific CVEs, or new malware campaigns are detailed; the piece is informational/policy-oriented in nature.

Mentioned in this report

Threat actors DarkMatterENFERNSO Group
Malware Pegasus

Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/report/countering-cyber-proliferation-zeroing-in-on-access-as-a-service

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free