Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Italian Adviser Targeted By Paragon Spyware

November 11, 2025
Reading Time: 4 mins read
in Incidents
Chinese Breach Exposes Cyber Weapons

Francesco Nicodemo, a prominent political communications strategist who previously served as the Democratic Party’s communications director, has been identified as a new target in the expanding Paragon spyware surveillance campaign. This revelation underscores a concerning escalation in the scope of highly sophisticated digital espionage operations targeting political figures and their associated networks in Italy. Nicodemo, who currently leads the communications agency Lievito, first discovered the security breach on January 31, 2025, after receiving a suspicious WhatsApp message while traveling abroad in Vienna.

The scope of the potential data exposure is significant, as Nicodemo’s agency was instrumental in managing thirteen election campaigns throughout 2024, including key successful center-left victories in the regions of Perugia, Liguria, and Umbria. Furthermore, the compromised device potentially exposed sensitive communications with Democratic Party parliamentarians, election candidates, and senior party officials. The spyware infection proved highly persistent, remaining active on Nicodemo’s Android device even after he had switched to an iPhone, with the compromised hardware sitting unused at his residence.

Fanpage security researchers were able to identify the specific attack pattern only after cross-referencing it with similar incidents involving other high-value targets, including journalists and activists. The timing of the surveillance, coinciding directly with several high-profile regional elections, has raised serious questions about the possibility of espionage intentionally targeting opposition political strategies and critical internal communications. This deliberate targeting suggests an interest in disrupting or preempting political activities at a crucial time in the electoral cycle.

The confirmation of the breach was solidified after John Scott Railton from Citizen Lab, a globally recognized cybersecurity watchdog organization, contacted Nicodemo multiple times via international calls. Railton emphasized the extreme severity and precision of the attack, noting that only a small, highly select number of Italian targets were chosen for this specific, advanced espionage operation. This selection criterion highlights the perceived strategic value of Nicodemo’s communications network and his agency’s political role.

The Paragon Graphite spyware utilizes a highly sophisticated, multi-stage infection process that is typically initiated through a deceptive WhatsApp message seemingly originating from legitimate WhatsApp Support infrastructure. Crucially, unlike traditional phishing attacks that require a user to interact with a malicious link, this advanced variant can establish persistence through “zero-click” exploitation techniques, meaning the user does not need to take any action. The malware is designed to leverage vulnerabilities in messaging protocols to covertly deploy surveillance modules capable of extracting critical data, including messages, call logs, and precise location data, from both active and inactive devices. Security experts have additionally noted that the spyware maintains operational capability even when the target device is powered down, suggesting the employment of advanced firmware-level compromise techniques that are able to effectively bypass standard operating system security controls.

Reference:

  • Italian Adviser Becomes Latest Target In Expanding Paragon Graphite Spyware Case
Tags: cyber incidentsCyber Incidents 2025Cyber threatsNovember 2025
ADVERTISEMENT

Related Posts

Chinese Breach Exposes Cyber Weapons

Manassas Schools Close After Cyberattack

November 11, 2025
Chinese Breach Exposes Cyber Weapons

Chinese Breach Exposes Cyber Weapons

November 11, 2025
Hackers Steal Sonicwall Cloud Backups

Oracle EBS Hack Hits Nearly 30 Victims

November 10, 2025
Hackers Steal Sonicwall Cloud Backups

China Hackers Target US Nonprofit

November 10, 2025
Hackers Steal Sonicwall Cloud Backups

Hackers Steal Sonicwall Cloud Backups

November 10, 2025
US Budget Office Hit By Cyberattack

US Budget Office Hit By Cyberattack

November 7, 2025

Latest Alerts

Glassworm Found In Three VS Code Addons

Triofox Flaw Lets Hackers Install Remote

Delayed Payloads Hit Nuget Packages

Samsung Flaw Used To Install Landfall

ClickFix Phishing Targets Hotel Systems

Lost iPhone Beware Fake Text Claims

Subscribe to our newsletter

    Latest Incidents

    Italian Adviser Targeted By Paragon Spyware

    Manassas Schools Close After Cyberattack

    Chinese Breach Exposes Cyber Weapons

    Oracle EBS Hack Hits Nearly 30 Victims

    China Hackers Target US Nonprofit

    Hackers Steal Sonicwall Cloud Backups

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial