There is a legal, commercially available industry that sells surveillance software to governments. The software is designed to silently compromise target devices, exfiltrate communications, activate cameras and microphones, and track location - all without the target's knowledge. The customers are law enforcement and intelligence agencies. The targets include criminals, terrorists, and - documented extensively - journalists, opposition politicians, lawyers, human rights workers, and dissidents. The industry operates in a legal gray zone that has resisted regulation for two decades.
FinFisher / FinSpy
FinFisher (also marketed as FinSpy) was developed by the UK-German company Gamma Group. It was first publicly exposed in 2011 when Citizen Lab researchers, analyzing malware samples, identified it as commercial surveillance software sold to governments. The initial discovery came from Bahrain, where FinFisher was being used to target opposition activists who had participated in the Arab Spring.
FinFisher's capabilities included keystroke logging, email and chat interception, webcam and microphone activation, file exfiltration, and location tracking. It targeted Windows, macOS, Linux, iOS, Android, and BlackBerry. The software was delivered through multiple vectors: spear-phishing emails, infected USB drives, and in some documented cases, through network interception - attackers sitting between the target and a legitimate software download and injecting the FinFisher installer into the download stream.
A breach of Gamma Group's internal systems in 2014 (conducted by a researcher calling themselves Phineas Fisher - no relation to FinFisher) released 40GB of internal documentation, source code, and customer data. The leaked files confirmed FinFisher sales to over 30 countries, including Bahrain, Ethiopia, Vietnam, UAE, and others. They also revealed that Gamma Group's staff maintained systems for clients in these countries and provided technical support for ongoing surveillance operations.
Hacking Team
Hacking Team was an Italian company that sold "Remote Control System" (RCS), marketed as "Da Vinci" - a surveillance platform with similar capabilities to FinFisher. Like Gamma Group, Hacking Team sold to governments globally, including Morocco, Sudan, Ethiopia, Bahrain, and others.
In July 2015, Hacking Team suffered a catastrophic breach. An attacker - again, Phineas Fisher - compromised Hacking Team's internal systems and released approximately 400GB of data including email archives, source code, customer lists, and internal documentation. The release was published via a Twitter account that had been hacked from Hacking Team's own Twitter.
The leaked data confirmed Hacking Team had customers in Sudan despite UN arms embargoes, had provided system access to Saudi Arabia during periods of well-documented political repression, and had maintained relationships with customers in multiple countries formally considered "not officially supported" in internal documentation - suggesting the company's stated customer vetting was effectively performative.
The leaked source code was analyzed immediately by the security research community. Zero-days for Flash, Windows kernel, and other platforms were identified in the code and disclosed to vendors. The Windows kernel zero-day (CVE-2015-2387) was subsequently used in other malware campaigns. The Hacking Team breach was operationally beneficial to the security community in forcing the disclosure and patching of previously unknown vulnerabilities - while simultaneously damaging the company and its clients.
NSO Group and Pegasus
NSO Group is an Israeli company that produces Pegasus - the most technically sophisticated commercial spyware publicly documented. NSO Group markets exclusively to governments and insists on a vetting process for customers. Pegasus has been documented using zero-click exploits - attacks that compromise a device without any interaction from the target. The target receives no phishing email, clicks no link, opens no attachment. Their phone simply becomes an NSO surveillance device.
The zero-click vulnerabilities Pegasus has used include FORCEDENTRY (CVE-2021-30860) - a vulnerability in Apple's image rendering that allowed Pegasus to compromise iPhones by sending a specially crafted PDF in a text message, processed before the message was even opened. Apple patched FORCEDENTRY in September 2021 after Citizen Lab discovered and reported it.
Pegasus was documented targeting journalists covering the Khashoggi assassination, opposition politicians in multiple countries, lawyers, and human rights workers. An investigation by a consortium of 17 media outlets - the Pegasus Project - in 2021 analyzed a leaked list of 50,000 phone numbers that had been selected as potential targets by NSO customers. The numbers included journalists at major international outlets, heads of state, cabinet ministers, and business executives.
The Regulatory Gap
Commercial spyware companies operate under export control regimes that were designed for physical weapons. Software that exists entirely as code, sold through licensing agreements, to government intelligence and law enforcement agencies, occupies a category that export controls handle poorly. The Wassenaar Arrangement, a multilateral export control regime, added "intrusion software" to its control list in 2013 - but implementation across member states was inconsistent, and the controls primarily affected security researchers' ability to share vulnerability information rather than commercial spyware sales.
The fundamental problem is that the same capability - silent device compromise and exfiltration - is both a legitimate law enforcement tool for investigating serious crime and a mechanism for suppressing journalism and political opposition. There is no technical difference between a lawful wiretap of a drug dealer's communications and the surveillance of a dissident's encrypted messages. The difference is legal authorization and the rule of law context in which the tool is deployed - neither of which is assessable from the technology itself.
Citizen Lab, Amnesty International's Security Lab, and Access Now's Digital Security Helpline have collectively documented commercial spyware use against civil society targets in dozens of countries over more than a decade. The pattern is consistent across products and vendors: the "lawful intercept" framing is accurate for some uses and provides cover for others. The commercial surveillance industry exists in the gap between these two realities.