How Spyware Brokers and Resellers Are Quietly Fuelling a Global Surveillance Market

A recent Atlantic Council report highlights that spyware brokers and middlemen are central to the global commercial surveillance industry, bypassing export controls and aiding governments with limited tech capabilities in accessing powerful hacking tools despite sanctions.

Layla Haddad
Cyber Policy & Digital Risk Correspondent5 min read
Global spyware supply chain map showing the role of intermediaries, brokers and resellers in bypassing export controls and spreading commercial surveillance tools

Global spyware supply chain map showing the role of intermediaries, brokers and resellers in bypassing export controls and spreading commercial surveillance tools

Efforts to regulate the global spyware market are being systematically undermined by an expanding network of intermediaries — brokers, resellers, contractors and partners — that allow governments and private entities to circumvent transparency laws and export controls, according to a new report from policy think tank Atlantic Council.

The report, the latest entry in the Atlantic Council's Mythical Beasts series on the global spyware ecosystem, finds that these intermediaries have become central to the proliferation of commercial surveillance tools — making the market more costly, more opaque and significantly harder for researchers and policymakers to track and disrupt.

The Operational Backbone of Surveillance

Jen Roberts, associate director of the Cyber Statecraft Initiative at Atlantic Council and one of the report's authors, described the scale of the challenge.

"Intermediaries can drive down transparency efforts in the marketplace for offensive cyber capabilities like spyware by muddying supply chains and creating confusion for end buyers as to where a capability or component of a capability has come from. Intermediaries drive sales to countries regardless of size, but it is often countries that do not have robust technical capabilities in-house that seek them on the open market."

The researchers cited concrete examples of how this plays out in practice: a South African intermediary acting as a representative for Memento Labs to sell its Dante spyware to local markets, and a third-party firm reportedly facilitating Israeli company Passitora's sale of spyware to Bangladesh — despite the two countries having no diplomatic relations and Bangladesh having banned imports from Israel.

Collin Hogue-Spears, senior director of solution management at Black Duck, an application security firm, was direct about the structural purpose these entities serve.

"Their corporate structures exist specifically to make export controls irrelevant. The spyware market stopped being a vendor-to-government pipeline years ago. It has evolved into a modular supply chain where intermediaries fill every gap the buyer cannot fill alone: exploit engineering, operational training, deployment infrastructure, and most importantly, a legal paper trail that hides the origin."

Zero-Days and Commercial Surveillance Converge

The demand fuelling this ecosystem is substantial. Governments continue to seek spyware for law enforcement investigations, espionage and, in many documented cases, surveillance of political opponents, journalists and dissidents. In 2025, for the first time, more zero-day exploits were attributed to commercial surveillance vendors than to traditional state-sponsored groups, according to a March analysis by Google's Threat Intelligence Group — a milestone that illustrates how far the commercial market has matured.

Julian-Ferdinand Vögele, a principal threat researcher at Recorded Future, described the deliberate opacity at the heart of the model.

"Commercial spyware operates in the shadows by design. Brokers and resellers enable its spread by connecting vendors and buyers, bundling tools with support or training, and expanding into new markets, while adding opacity, obscuring relationships, and leveraging jurisdictions."

Meanwhile, recent moves by the US government — including reactivating previously cancelled contracts and removing sanctions against surveillance technology vendors — appear to have eased the path for some commercial spyware operators, raising further concerns among digital rights advocates.

Regulation Struggles to Keep Pace

International efforts to regulate the spyware market have intensified but remain incomplete. In February 2024, the United Kingdom and France launched the Pall Mall Process — a multilateral diplomatic initiative to address the proliferating market for commercial cyber intrusion tools. The process brought together 27 governments and technology companies including Google, Microsoft, Apple and Meta, with participants working toward a code of practice limiting the trade in commercial spyware and zero-day exploits. OECD AI Policy Observatory

Some vendors have attempted to leverage the regulatory moment to rehabilitate their public image. NSO Group, the Israeli company behind the notorious Pegasus spyware, has published transparency reports and claimed to establish a human rights compliance programme. However, critics remain deeply sceptical. Experts from The Citizen Lab and Access Now emphasise that despite NSO's claims, there is little evidence of tangible reform or accountability Datadog — and Amnesty International confirmed in February 2025 that Pegasus was used to target Serbian journalists, adding to a long record of documented abuses.

Roberts said resellers concern her the most among the intermediary categories the report examined. "We've observed them bypass policy regulations set forth to regulate this market, like export controls and trade bans," she said.

Transparency as the Starting Point

The Atlantic Council's report stops short of calling for an outright ban on commercial spyware — a step researchers acknowledge is unlikely to be politically viable — and instead recommends a series of near-term measures. These include countries adhering to Know Your Vendor requirements, introducing certification requirements for brokers and resellers, and improving registries that document which intermediaries are operating in the market.

The overarching principle, Roberts argued, is one of visibility. "Transparency initiatives are key to regulating intermediaries and also the spyware industry more broadly. It is difficult to ultimately regulate what one cannot observe."

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.