Information Warfare Strategies (SRF-IWS): Spyware as Statecraft — How States Blackmail States

Read Time: 15 minutes

TL;DR

Commercial spyware collapsed the price of the oldest move in statecraft: know what the other side knows, and hold something over the people who decide. A mid-sized state can now rent zero-click capability that used to belong only to top-tier intelligence services, point it at another country’s prime minister, and turn the take — private messages, locations, contacts, negotiating positions, personal secrets — into leverage over a border, a vote, a recognition, a venue. This is the SRF-IWS entry on coercion by malware: how it works as a doctrine, and how a government defends against it. The public case study is the Pegasus affair in Spain — it is confirmed that the phones of Prime Minister Pedro Sánchez and Defence Minister Margarita Robles were infected with NSO Group’s Pegasus in 2021; it is alleged and under judicial investigation, and firmly denied by Rabat, that Morocco was behind it; and it is my analysis, not a proven fact, that the intrusion sits inside a broader pattern of Spanish concessions to Morocco. I keep those three tiers separate on purpose, because the mechanism matters more than the verdict — and the mechanism should terrify every government that still treats a minister’s personal phone as a personal matter. Method at the threat-vector level, defenses at the end.


Disclaimer, doubled — this one names names. This article is defense-oriented and kept at the threat-vector level. Where I state something as fact, it is publicly confirmed and sourced. Where attribution is contested, I say so and note the denial. Where I connect events into a pattern, I label it as my own reading, not a finding. Nothing here is an operational how-to; it is a doctrine-level analysis for the people who build and defend government security. As with the rest of the SRF-IWS series, the goal is Blue Team planning. I am a security practitioner, not a court; treat contested claims as contested.

There is a particular kind of intrusion that does not feel like hacking. No server is breached, no embassy is burgled, no document leaks. A phone — the one in a head of government’s pocket during every classified briefing — simply starts answering to someone else. It keeps ringing, keeps showing the right time, keeps looking exactly like it did yesterday. And somewhere outside the country, a case officer reads the prime minister’s messages before his own chief of staff does.

That is the weapon this post is about, and the uncomfortable part is that it is for rent.

What actually happened: the confirmed core

Let me start with what is not in dispute, because the rest only matters if the foundation is solid.

In May 2022, the Spanish government confirmed that the mobile phone of Prime Minister Pedro Sánchez had been infected with Pegasus, the spyware built by the Israeli firm NSO Group. The Minister for the Presidency, Félix Bolaños, told the press the intrusion was “illicit” and “external” — from outside Spanish state organs, with no judicial authorization. According to the government’s May 2022 account, Sánchez’s phone was compromised twice in May 2021, and Defence Minister Margarita Robles’ device once in June 2021, with a significant volume of data exfiltrated. Days later the director of Spain’s intelligence service, the CNI, was dismissed. The later judicial investigation would put the numbers higher still — reporting five infections of the prime minister’s phone across 2020–2021 and four of Robles’, with more than 2.5 GB of data pulled from Sánchez’s device alone.

Pegasus is the reason this is a story about statecraft and not about phishing. It is a zero-click weapon: at its peak it could compromise a fully patched iPhone with no tap, no link, no mistake by the target — a silent message that installs, executes, and deletes its own trace. Citizen Lab and Amnesty International’s Security Lab documented the technique; the same toolset surfaced in “CatalanGate,” where researchers found at least 65 people in Catalan political and civil-society circles targeted with Pegasus and Candiru between 2017 and 2020 — an operation Citizen Lab tied by circumstantial evidence to a “strong nexus” with Spanish state entities, while explicitly declining to attribute it conclusively.

So the confirmed core is this: the two most security-relevant phones in the Spanish state were owned, for a while, by an outside party. That is not an embarrassment. That is a national-security event.

Who did it: the contested part

Here I slow down, because this is where careful language is not optional.

The Spanish government did not, in 2022, name the author. Since then, the investigation at the Audiencia Nacional has — according to Spanish press reporting — increasingly pointed toward Morocco, and has drawn on judicial cooperation from France, where Pegasus targeting of officials was also alleged. Reporting in 2026 has gone further, tying the May 2021 migration surge at Ceuta — when thousands of people crossed into the Spanish enclave after Moroccan border control abruptly relaxed — to Moroccan retaliation against Spain, and framing the Pegasus operation as part of the same pressure campaign.

Morocco denies all of it. No court has issued a final attribution as I write this — and in January 2026 the investigating judge at the Audiencia Nacional shelved the probe, not for lack of a trail but for lack of cooperation, after Israel ignored five formal requests to help identify who operated the Pegasus licence. The case is suspended, not solved. That outcome is itself the thesis in miniature: this weapon works partly because attribution reliably stalls — the deniability is designed in, and the courts run out of road before the operator is ever named.

So the honest state of play is: the intrusion is confirmed; the author is alleged. I am going to write the rest of this analyzing the pattern — because the pattern is instructive regardless of which state, in the end, is proven to have held the remote. If it turns out not to be Morocco, every word about the mechanism still stands, pointed at whoever it was.

And the conflict is not a closed 2021 file — it is live as I write this. In late August 2026, a hacktivist group calling itself Jabaroot claimed to have leaked personal data on tens of thousands of alleged Moroccan security and intelligence personnel, framing the dump, in its own words, as a message aimed at Spain and tied to the 2026 Ceuta crisis — the largest migrant surge in the enclave’s history, when more than 60,000 people crossed into the Spanish city in a matter of days at the end of July, a breakdown widely reported to have come with a green light from the Moroccan side. The claim is unverified, I am deliberately not reproducing any of that data, and hack-and-leak doxxing is a different instrument from the silent phone implant this article is about. But it belongs here as context: the Spain–Morocco intelligence relationship is an open, two-way covert conflict, and spyware is one tool in a much larger kit. And as of 26 August the leaker has begun gesturing directly at this article’s subject — publicly dangling supposed Pegasus material tied to Sánchez — with no evidence yet that the data is real or in hand.

The mechanism: how a phone becomes leverage

Strip the geopolitics and coercion-by-spyware is a clean, repeatable chain. This is the SRF-IWS core, at doctrine level.

Target selection. You do not need the principal’s phone if you can have the people around it. Chiefs of staff, private secretaries, advisers, spouses, drivers, the journalist the minister trusts — the entourage is the soft edge of a hard target, and each one is a window onto the same room. The principal is the prize; the circle is the way in.

Delivery. Commercial spyware turned capability into a purchase order. Zero-click chains mean the operation does not depend on the target’s mistakes, only on the vendor’s inventory of exploits. A state that could never build this can now license it, aim it, and deny it — the plausible-deniability layer is part of the product.

Collection. Once resident, the implant is not a wiretap; it is the device. Messages before and after encryption, live microphone and camera, location history, contacts, calendars, photos, password vaults. Two distinct kinds of gold come out: kompromat — the private material that makes a person coerceable — and positional intelligence — what the other government actually thinks, fears, and will settle for.

Exploitation. This is where intelligence becomes coercion, and it runs on two rails. The first is blackmail: leverage over an individual, quiet pressure to act, to soften, to look away. The second is subtler and often more valuable: foreknowledge. A state that has read your prime minister’s phone does not have to win the negotiation — it already knows your red lines, your fallback, and the date you will fold. It sits down at the table having read the other side’s notes.

Effect. The output is not data. It is a decision that goes the other way: a border that opens or closes on cue, a vote withheld, a position reversed, a venue awarded. The malware is upstream of foreign policy.

srf_spyware_coercion_kill_chain

Figure 1. The doctrine as an attack tree. The chain is AND across all five phases — you need targeting and delivery and collection and exploitation and effect — with OR inside each, because any single target, route, or payoff will do. Break any one phase and the chain breaks, which is exactly where the defensive playbook aims.

My reading: from intrusion to concession

Now the part I am explicitly flagging as analysis, not fact.

Look at the Spanish timeline the way I look at an attack chain, and a pattern is hard to unsee. The Ceuta surge (May 2021) as raw pressure. The compromise of the prime minister’s phone (May 2021). And then, in March 2022, Spain’s abrupt reversal on Western Sahara — Sánchez backing Morocco’s autonomy plan and ending decades of studied neutrality, a shift that blindsided his own coalition and Algeria alike. Since then, a warming across migration cooperation and the shared 2030 World Cup, down to the pointed dispute over which country hosts the final.

I want to be precise about what I am and am not saying. I am not asserting that spyware caused those decisions; that is not proven and may never be. I am saying that this is exactly what the mechanism above would look like from the outside, and that a government which discovers its leader’s phone was owned during the run-up to a major concession owes its citizens a harder question than it has publicly asked. The value of the case is not a verdict. It is that it makes the doctrine concrete.

This is a category, not a one-off

It would be a mistake — and frankly a less honest article — to treat this as a Morocco story. Commercial spyware as an instrument of statecraft is now a global market, and Europe is both customer and casualty.

The European Parliament stood up an entire committee, PEGA, precisely because member states were caught using this class of tool against journalists, opposition figures, and each other. Poland used Pegasus against opposition politicians. Hungary against journalists. Greece’s “Predatorgate” put the Predator spyware (from the Intellexa/Cytrox alliance) at the center of a scandal reaching the prime minister’s own circle. Beyond Europe, Mexico was among NSO’s largest clients and turned the tool on journalists and activists; the toolset appeared around associates of murdered journalist Jamal Khashoggi; targets surfaced in Jordan, the Gulf, and beyond. The through-line is not one villain. It is that a capability which used to require a Fort Meade now requires a contract, and the guardrails are mostly aspirational.

That is the real warning in the Spain case: not that one neighbor may have crossed a line, but that the line is cheap to cross and almost everyone with a budget is standing near it.

The defensive playbook

None of this is a counsel of despair. It is a counsel of treating the principal’s phone as the contested national-security terrain it now is. Here is what I would put in front of any government protection detail or CISO of state.

Harden the principal’s devices as if they are already targeted — because they are. Locked-down, minimally-provisioned handsets; Apple’s Lockdown Mode (or the platform equivalent) for high-risk principals; aggressive device rotation; and — critically — no personal phone in classified spaces. The convenience device is the attack surface.

Defend the circle, not just the crown. The entourage is the way in. Aides, family, and close staff need the same briefing, the same hardened devices, and the same discipline as the principal. A protection program that stops at one person is theater.

Assume the phone is hostile and design comms around that. Segregate sensitive discussion onto controlled, ephemeral, ideally air-gapped channels. The rule for anything that would be leverage in a foreign capital: it does not happen on a device you carry through an airport.

Instrument for detection. Zero-click implants are quiet, not invisible. Routine forensic acquisition of high-risk devices (the kind of methodology behind Amnesty’s Mobile Verification Toolkit), mobile threat defense, and a standing relationship with a lab that can do real forensics turn “we’ll never know” into “we caught it in the logs.”

Treat a confirmed head-of-state infection as an incident, not an embarrassment. The worst response to owning up that the PM’s phone was compromised is to bury it to avoid the domestic politics. Attribution, consequences, and public accounting are themselves deterrents; silence is an invitation to do it again.

Make it a policy and procurement problem, too. National controls and EU-level regulation on commercial spyware, export controls on the vendors, and hard limits on your own services’ use of these tools — because a state that normalizes buying this capability has no standing to complain when it is used against its own cabinet. The PEGA committee wrote the recommendations; the gap is enforcement.

So what

For most of history, reading another government’s mind required a spy in the room, a mole in the ministry, or a break-in at the embassy — expensive, slow, and dangerous. Commercial spyware turned all of that into a licensing agreement and a phone number. The consequence is that sovereignty now runs through a consumer device: a state that can read your prime minister’s phone does not need to out-argue you, out-maneuver you, or out-wait you. It already knows how you will argue, where you will maneuver, and how long you will wait.

srf_spyware_coercion_convergence

Figure 2. The same thing as a straight line: a sponsoring state acquires deniable capability, compromises the phone, collects everything, converts the take into leverage, and cashes it as a concession. The “weaknesses” it rides — zero-click delivery, rentable spyware-as-a-service, a personal device carried into classified rooms — are structural properties, not software bugs, which is why there is no patch, only a posture.

The Spain–Pegasus affair is the clearest public window we have into that world — a confirmed intrusion, a contested author, and a pattern that should make any government look hard at the device in its leader’s pocket. Whether or not the courts ever name the hand on the remote, the lesson does not wait for the verdict: the phone is not personal, the entourage is the perimeter, and a leader’s private life is now a national attack surface.

Treat it that way before someone else does.

Stay paranoid. Harden the principal. Assume the phone is listening.

Further Reading:

Questions or feedback? Reach out via:

Need help defending principals and sensitive staff against mobile/spyware threats? VULNEX offers:

  • Mobile threat and spyware exposure assessments (executive / principal device hardening)
  • Counterintelligence-aware security programs for high-risk organizations
  • Incident response and mobile forensics for suspected zero-click compromise
  • Security awareness and OPSEC for leadership and their circle

Contact: info@vulnex.com

This entry was posted in AI, Economics, Security, Technology and tagged , , , , , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.