Google's TAG publishes a report on commercial spyware, detailing ~40 vendors, and says global governments should take more aggressive steps to combat spyware
The commercial spyware industry continues to supply highly advanced surveillance capabilities despite efforts to better regulate it.
CyberScoopAJ Vicens
Context & Ripple Effects
Google's security team had already tied targeted campaigns against Android, iOS, and Chrome to commercial spyware activity, including highly targeted campaigns using multiple zero-days. This report broadens that case from individual incidents to a mapped vendor ecosystem.
It lands alongside a multinational and industry statement calling for stronger action, while earlier US proposals sought to restrict spyware sellers' access to government business. The significance is the shift from patching individual exploits toward treating the suppliers themselves as a policy target.
First-order effects
Google's report raises scrutiny of roughly 40 commercial-spyware vendors and gives governments a more concrete basis for enforcement or procurement restrictions.
Potential targets and platform operators gain additional public evidence that advanced surveillance tooling remains available despite existing regulatory efforts.
Second-order effects
Governments that have endorsed stronger action face pressure to convert broad commitments into coordinated rules, sanctions, export controls, or contracting limits; uneven implementation would leave vendors room to serve other markets.
If governments align procurement, export, and enforcement measures, commercial spyware could increasingly be treated as a cross-border security market requiring supplier-level oversight rather than solely incident response.
The durable constraint is attribution and jurisdiction: a large, internationally distributed vendor base can make national restrictions less effective unless participating states coordinate.
The trend: Commercial spyware is moving from a cyber-defense problem addressed exploit by exploit toward a coordinated governance challenge focused on the vendors and state customers behind it.
But first check out the full 50 page report pulling together years of work by on understanding and countering these threats. https://storage.googleapis.com/ ... Thanks @auroracath @billyleonard @_clem1 @maddiestone @az_matazz @t_gidwani @charley_snyder_ + others for the tireless …
These commercial surveillance vendors are also behind half of known 0-day exploits targeting Google products as well as Android ecosystem devices. [image]
The proliferation of spyware causes real world harm. We partnered with @Jigsaw to highlight the stories of three high-risk users who attested to the fear felt when these tools were used against them. [image]
Announcing the latest report from Threat Analysis Group documents the rise of commercial surveillance vendors and the industry that threatens free speech, the free press and the open internet https://blog.google/... Some highlights below. 🧵
.@SecBlinken is announcing a new visa restriction policy to address the misuse of commercial spyware. This action will promote accountability for individuals who target or enable the targeting of journalists, activists, dissidents, and marginalized communities.
To realize the promise of technology to promote democratic freedom + prosperity, it's important to set up guardrails to mitigate potential harm. In line with these goals, we are proud to announce a new visa restriction policy that will hold individuals who misuse commercial...
NEW: U.S. @StateDept announces new measures to target those involved in spyware abuses Visa restrictions will be levied on individuals involved in the misuse of commercial spyware 👇 https://www.state.gov/... [image]
Big news! 👏🏽 @POTUS administration has just issued a sanctions policy that would deny visas to individuals who misuse or facilitate the misuse of commercial spyware + their family members. ❌🕵️♂️📱 EU should follow suit! https://www.state.gov/...
2/ Linking mercenary spyware targeting to extrajudicial killings... @SecBlinken & @StateDept are not mincing words. Crystal clear: US sees the unchecked proliferation of commercial / mercenary spyware as a major problem for human rights AND 🇺🇸national security... [image]
.@SecBlinken announced a new visa restriction policy to promote accountability for individuals involved in the misuse of commercial spyware, including those who gain financially from such misuse. https://www.state.gov/...
6/ Timing: @StateDept visa ban announcement comes day before the #pallmallprocess conference hosted by 🇬🇧UK & 🇫🇷France.👇 Crystal clear that a growing # of countries are concerned about proliferation of #spyware et. al. & seeking paths forwards. https://twitter.com/...
NEW: @StateDept won't give visas to individuals involved in mercenary #spyware abuses. No 🇺🇸Disneyworld trip if you... ❌Abused commercial spyware ❌Got financial benefit from the misuse (e.g. your company sold it) This is targeted & will hurt 1/ https://www.state.gov/... [image]
The State Department says it will begin denying visas to people involved in abusing commercial spyware, people who financially benefit from that abuse, and family members of those people. https://www.state.gov/...
4/ Today's visa ban will be impactful because it follows the people. Prior efforts focused on spyware companies. Which is good. But spyware players play shell games w/corporate identities. Now, no matter what your company name is this week, you still can't go to Disneyworld.