Home/Threat Actor/Cy4Gate
Threat Actor

Cy4Gate

cy4gate · italy · active since 2017-01

Cy4Gate S.r.l. (Rome, Italy.

Euronext Growth Milan: CY4G) is a publicly-listed Italian commercial surveillance vendor (PSOA) that develops and sells the Epeius mobile surveillance platform to government law enforcement and intelligence clients; Epeius provides comprehensive iOS and Android device surveillance capabilities including location tracking, microphone/camera activation, message interception (SMS, iMessage, WhatsApp), contact/calendar/call-record access, and screen capture; Google TAG / Project Zero (March 2023) documented exploit chains associated with the Italian commercial surveillance vendor ecosystem including Cy4Gate infrastructure.

examined in the European Parliament PEGA Committee inquiry (2022-2023) alongside NSO Group, Intellexa, and Paragon Solutions.

distinct from RCS Lab (the former Hacking Team successor entity) which is separately curated.

PSOA governance concern is documented misuse of lawful-interception-marketed tools against civil society, journalists, and political opposition consistent with the broader commercial spyware vendor ecosystem.

italy confidence: medium 9 aliases
Sigma rules23 YARA rules0 Live IOCs0 CVEs exploited2

Profile

Cy4Gate S.r.l. (Rome, Italy.

Euronext Growth Milan: CY4G) is an Italian private sector offensive actor (PSOA), a publicly- listed commercial surveillance vendor that develops, markets, and sells the Epeius mobile surveillance platform and related intelligence-collection tools exclusively to government law enforcement and intelligence clients under a lawful- interception / government-exclusive commercial model. Cy4Gate occupies a distinct position in the Italian commercial surveillance vendor ecosystem: unlike RCS Lab (the former Hacking Team successor entity, curated at hacking_team_memento_labs.yaml), Cy4Gate is a post-Hacking- Team-collapse market entrant (founded approximately 2016-2017) that emerged during the period of Italian surveillance-vendor market reconsolidation following the 2015 Hacking Team breach and subsequent reputational damage to the Italian surveillance industry. Cy4Gate is also notable as a publicly-listed PSOA, one of a small number of commercial surveillance vendors that operates with public market transparency obligations (unlike the privately-held NSO Group, Intellexa, or Paragon Solutions). The Epeius platform provides comprehensive mobile device surveillance capabilities across both iOS and Android platforms, including location tracking, microphone activation, camera activation, SMS/iMessage/WhatsApp message interception, contact list and calendar access, call record access, clipboard capture, and screen capture. The platform's capabilities are broadly comparable to those of other commercial mobile surveillance platforms (NSO Group Pegasus, curated at nso_group_pegasus.yaml; Intellexa Predator, curated at intellexa_predator.yaml.

Paragon Solutions Graphite, curated at paragon_solutions_graphite.yaml) while operating at a smaller documented deployment scale. Google TAG and Project Zero (March 2023) documented exploit chains used in the Italian commercial surveillance vendor ecosystem, including infrastructure and exploit delivery patterns associated with Cy4Gate's Epeius platform, providing the primary technical-attribution basis linking specific vulnerability exploitation to Epeius delivery. The European Parliament PEGA Committee inquiry (2022-2023) examined the Italian surveillance vendor ecosystem in which Cy4Gate operates, providing a governance-context backdrop for assessing the cluster's commercial operations. The PSOA governance significance of Cy4Gate, like all commercial surveillance vendors in this curated corpus, is that government clients nominally purchasing Epeius for lawful interception of criminal suspects have, in the broader PSOA ecosystem pattern, been documented to direct surveillance tools against journalists, human rights defenders, opposition politicians, and civil society members in contexts inconsistent with stated lawful-interception justifications. No publicly- available technical report has definitively attributed specific Epeius deployments against named civil society victims with the same evidentiary density as Citizen Lab's Pegasus forensic reports, Cy4Gate's public attribution footprint is thinner than NSO Group's but analytically significant in the Italian PSOA market context.

Aliases

9
cy4gatecy4gate s.r.l.cy4gate srlepeius_operatorsepeius spyware vendorrsd_operatorseuronext-growth-milan-cy4gitalian-psoa-cy4gatepsoa-cy4gate

Notable Campaigns

3
2023Google TAG Commercial Spyware Vendor Attribution, Cy4Gate Epeius Infrastructure (2023)
2022-2024Lookout Mobile Threat Intelligence, Epeius Mobile Surveillance Analysis
2022-2023European Parliament PEGA Committee, Surveillance Spyware Inquiry Context (2022-2023)

Attribution & Reporting

Attributed by
Citizen Lab (University of Toronto Munk School)Google TAG (Threat Analysis Group)Lookout SecurityMeta (Facebook) Security ResearchAmnesty International Tech LabAccessNowRecorded FutureESETEuropean Parliament PEGA Committee (Pegasus and equivalent surveillance spyware inquiry)Italian data protection authority (Garante)Reporters Without Borders
Key reporting
reportGoogle TAG / Project Zero: Italian Surveillance Vendor Exploit Analysis (March 2023)
reportLookout Security: Epeius / Cy4Gate Mobile Surveillance Analysis
reportEuropean Parliament PEGA Committee Final Report (May 2023), Italian surveillance vendor ecosystem context
reportCitizen Lab: Italian Surveillance Vendor Research (multiple years)
reportMeta (Facebook) Security: Commercial Surveillance Vendor Disruption Actions
reportMalpedia Actor Profile: Cy4Gate

Operational

State sponsor

Cy4Gate S.r.l. is an Italian private sector offensive actor (PSOA), a commercial surveillance vendor that develops, markets, and sells the Epeius mobile surveillance platform and related interception and intelligence-collection tools to government law enforcement and intelligence clients under a lawful-interception / government-exclusive commercial model. The company is headquartered in Rome, Italy, was founded approximately 2016-2017, and is publicly listed on the Euronext Growth Milan stock exchange (ticker CY4G). Cy4Gate's stated business model is government-exclusive lawful interception and intelligence collection, the company markets Epeius and its associated capabilities exclusively to government customers (law enforcement agencies, intelligence services, military intelligence) as a lawful interception tool for criminal investigations and national security operations.

The company operates within the broader Italian and European surveillance-technology commercial ecosystem that includes RCS Lab (a separate Italian PSOA curated at hacking_team_memento_labs.yaml, note: RCS Lab is the successor entity to Hacking Team, though some Italian surveillance market analysis conflates RCS Lab and Cy4Gate as adjacent vendors serving overlapping government client markets). Cy4Gate does not publicly disclose its client list or the jurisdictions in which Epeius has been deployed. Industry analysis (Citizen Lab, Google TAG, Lookout, Meta security team) has documented Epeius deployment and associated surveillance infrastructure in contexts raising human rights concerns consistent with misuse against journalists, activists, and political opponents, consistent with broader PSOA ecosystem patterns in which government surveillance tools nominally sold for lawful interception are documented as being used against civil society targets.

Motivations
commercial_surveillance_vendor, government_lawful_interception_tools_sales, mobile_device_surveillance_product_development, intelligence_collection_tool_commercialization, psoa_commercial_operations
Sectors
Regions

Detection Blind Spots

31 techniques
Across this actor’s 31 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)4/31 · 12%
Analytics (MITRE CAR)0/31 · 0%
Runtime / container (Falco)0/31 · 0%
File / malware (YARA)0/31 · 0%
Network (Suricata/Snort)3/31 · 9%
Vuln scan (Nuclei)0/31 · 0%

Atomic Test Plan

3 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin