Skip to content

Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case

Cybersecuritynews • November 10, 2025

Francesco Nicodemo, a prominent political communications strategist and former Democratic Party communications director, has been identified as a new target in the expanding Paragon spyware surveillance campaign.

The revelation marks a concerning escalation in the scope of sophisticated digital espionage operations targeting political figures in Italy.

Nicodemo, who currently leads the communications agency Lievito, discovered the breach on January 31, 2025, when he received a suspicious WhatsApp message while traveling in Vienna.

The agency has managed thirteen election campaigns throughout 2024, including successful center-left victories in Perugia, Liguria, and Umbria.

The spyware infection remained active on Nicodemo’s Android device even after he switched to an iPhone, with the compromised phone sitting unused at his residence.

Fanpage security researchers identified the attack pattern after cross-referencing similar incidents involving journalists and activists.

The timing of the surveillance coincided with several high-profile regional elections, raising questions potential espionage targeting opposition political strategies and communications.

John Scott Railton from Citizen Lab, a cybersecurity watchdog organization, contacted Nicodemo multiple times through international calls before confirming the breach.

The researcher emphasized the severity of the attack, noting that only a small number of Italian targets were selected for this particular espionage operation.

The compromised device potentially exposed sensitive communications with Democratic Party parliamentarians, election candidates, and senior party officials.

The Paragon Graphite spyware utilizes a sophisticated multi-stage infection process that begins with a deceptive WhatsApp message appearing to originate from legitimate WhatsApp Support infrastructure.

Unlike traditional phishing attacks that require user interaction with malicious links, this spyware variant can establish persistence through zero-click exploitation techniques.

The malware leverages vulnerabilities in messaging protocols to deploy surveillance modules capable of extracting messages, call logs, and location data from both active and inactive devices.

Security experts note that the spyware maintains operational capability even when the target device is powered down, suggesting advanced firmware-level compromise techniques that bypass standard operating system security controls.

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Zoom has issued multiple security bulletins detailing patches for several vulnerabilities affecting its Workplace applications.…

SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing…

Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet's Triofox…

CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited…

A sophisticated wave of ransomware attacks targeting UK organizations has emerged in 2025, exploiting vulnerabilities…

Cybercriminals are increasingly targeting websites to inject malicious links and boost their engine optimization…

Extracted Entities

Attack Types (2)

Companies (1)

Countries (1)

Malware (1)

Platforms (3)