Spyware on Phones: Three Distinct Threats and How Each Gets Caught
Phone spyware is not one thing. It is three distinct categories of software, with three different install paths and three different detection problems. Treating them as one topic leads to advice that works for none of them.
- Categories tracked
- 3
- Journalists confirmed compromised (Graphite, 2025)
- 2
- Zero click exploit
- CVE-2025-43200
- Coalition Against Stalkerware founded
- 2019
Fake security tools
The first category disguises itself as protection. An app markets itself as an antivirus or cleaner tool, then behaves as malware once installed. This works because people who search for security tools are already worried their device is compromised, and are inclined to install quickly rather than scrutinise the developer.
The defence here is ordinary app hygiene: install security tools only from the device maker's own recommendations or from vendors you already know, and treat urgency in an app's marketing as a warning sign rather than a reason to skip verification.
Commercial stalkerware
The second category requires physical access to the target device, typically for the few minutes it takes to install an app directly from the developer's site rather than an app store, since these apps are usually banned from official stores. Once installed, they run hidden and forward messages, photos, call logs, and location to whoever installed them.
This is a recognised form of technology facilitated abuse. The Coalition Against Stalkerware, a partnership between anti domestic violence organisations and the IT security industry founded in November 2019, publishes guidance on checking a device without alerting the person who installed the software. That distinction matters: an abrupt uninstall can signal to an abuser that they have been detected, which is its own safety risk.
Mercenary spyware
The third category is built for governments and deployed through zero click exploits, meaning the target does not need to click a link or open a file. Detection by the phone's owner is close to impossible, because there is no phishing message to notice and often no performance symptom either.
The clearest documented case is Paragon's Graphite spyware. On 29 April 2025, Apple notified a group of iOS users that they had been targeted with advanced spyware. Citizen Lab's forensic analysis, published 12 June 2025, confirmed with high confidence that two journalists, a prominent European journalist who requested anonymity and Italian journalist Ciro Pellegrino, had been compromised by Graphite through an iMessage zero click attack. Apple confirmed the vulnerability was mitigated in iOS 18.3.1 and assigned it CVE-2025-43200. Paragon markets Graphite as a lawful intercept tool sold only to vetted government customers; Citizen Lab's finding shows that framing did not prevent it from being used against journalists.
What actually caught this campaign was not a scan the journalists ran themselves. It was Apple's threat notification programme, which is reserved for suspected state sponsored attacks and alerts affected users directly, followed by independent forensic confirmation from a research lab. Consumer antivirus software plays no role in this category.
What follows from this
The three categories need three different responses. Fake security tools are stopped by not installing untrusted apps under pressure. Commercial stalkerware is addressed through the physical access it requires and specialist support services rather than software alone. Mercenary spyware is addressed by taking manufacturer threat notifications seriously and, for people at elevated risk such as journalists, activists, and human rights defenders, treating any such notification as credible rather than as a false alarm.
No single app removes all three risks. The category determines the defence.
Sources
This guide is built on Citizen Lab's forensic confirmation of the 2025 Graphite spyware campaign against journalists, Apple's published threat notification support documentation, and the Coalition Against Stalkerware's public guidance on stalkerware detection and removal. Status current as of 6 August 2026.
Frequently Asked Questions
What are the main categories of spyware on phones?
Three distinct categories exist: fake security tools that bundle malware inside a supposed antivirus app, commercial stalkerware installed by someone with brief physical access to the device, and mercenary spyware deployed by state actors through zero click exploits that need no user interaction.
Can I detect mercenary spyware like Paragon Graphite myself?
Not reliably. Citizen Lab confirmed two journalists compromised by Graphite through forensic analysis after Apple’s own threat notification system flagged the accounts. Consumer antivirus tools did not detect the infections.
What should I do if I get an Apple or Google threat notification?
Treat it as credible. Apple’s threat notification programme is reserved for suspected state sponsored attacks and has a documented record of correctly flagging mercenary spyware cases, including the Paragon Graphite campaign against journalists in 2025.
Where can stalkerware victims get help?
The Coalition Against Stalkerware, founded in 2019, publishes detection and safe removal guidance written to avoid alerting the person who installed the software, which matters because removal can escalate risk in an abusive relationship.