Home/Threat Actor/Mollitiam Industries
Threat Actor

Mollitiam Industries

mollitiam_tykelab · spain · active since 2018-01

Mollitiam Industries S.L. / Tykelab S.L. is a Spanish commercial surveillance vendor (PSOA) that develops the Invisible Man and Real Fighter Android mobile surveillance platforms for government law enforcement and intelligence clients.

the company was publicly disclosed by Spanish newspaper EL PAIS (February 2022) via leaked product catalogues documenting comprehensive Android surveillance capabilities (location, microphone, camera, multi-platform message interception, anti-forensics icon suppression); Citizen Lab subsequently documented the Mollitiam-to-Tykelab corporate restructuring and command-and-control infrastructure fingerprints.

examined by the European Parliament PEGA Committee (2022-2023) in the context of Spanish surveillance vendor ecosystem governance.

thin public technical documentation relative to NSO Group / Intellexa / Paragon PSOA peers; curated for European PSOA market completeness alongside Variston (variston_heliconia.yaml) and Cy4Gate (cy4gate.yaml).

spain confidence: medium 11 aliases
Sigma rules14 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Mollitiam Industries S.L. / Tykelab S.L. is a Spanish private sector offensive actor (PSOA), a commercial mobile surveillance vendor that develops and markets the Invisible Man and Real Fighter Android surveillance platforms to government law enforcement and intelligence clients. The company came to public attention through an investigative disclosure by the Spanish newspaper EL PAIS (February 2022), one of the first public exposures of a Spanish-origin commercial surveillance vendor operating in the government-exclusive lawful-interception market. Mollitiam occupies a smaller market position in the commercial surveillance vendor ecosystem than major PSOA peers (NSO Group Pegasus, Intellexa Predator, Paragon Graphite) but represents a documented European PSOA market participant with reported government client operations. The company's Invisible Man platform marketed capabilities including comprehensive Android device surveillance (location tracking, microphone activation, camera activation, multi-platform message interception, SMS, WhatsApp, Telegram, Signal, iMessage), anti-forensics features (icon suppression, self-deletion, low-battery-footprint design), and claimed iOS surveillance capability. The company has not publicly disclosed its client list or deployment jurisdictions.

the geographic marketing targets documented in leaked product catalogues include Latin American and Middle Eastern government agencies in addition to European law enforcement clients. The corporate continuity between Mollitiam Industries S.L. and Tykelab S.L.

, documented in Citizen Lab's technical analysis following the EL PAIS disclosure, suggests a corporate restructuring or rebranding consistent with the PSOA industry pattern of regulatory-pressure-driven entity reorganization (similar to Hacking Team
  • RCS Lab and Cytrox / Intellexa corporate evolutions documented elsewhere in this corpus). The exact nature and completeness of the Mollitiam-to-Tykelab corporate transition remains partially opaque in public reporting. This actor entry is curated as a "thin-documentation" entry relative to flagship PSOA entries in this corpus, the public technical disclosure record for Mollitiam / Tykelab is significantly less dense than for NSO Group, Intellexa, Paragon Solutions, Cy4Gate, or RCS Lab. The entry is structurally significant for PSOA ecosystem completeness (providing coverage of the Spanish commercial surveillance market alongside Variston, curated at variston_heliconia.yaml) and governance analysis (European PSOA regulatory framework context) rather than for deep technical tradecraft analysis. Analysts requiring technical depth on Spanish PSOA tradecraft should prioritize the Variston / Heliconia entry (variston_heliconia.yaml) and for overall PSOA ecosystem context the NSO Group (nso_group_pegasus.yaml), Intellexa (intellexa_predator.yaml), and Cy4Gate (cy4gate.yaml) entries.

Aliases

11
mollitiam_industriesmollitiam industries s.l.tykelab_sltykelab s.l.tykelabinvisible_man_operatorsreal_fighter_operatorsinvisible man vendorspanish-psoa-mollitiampsoa-mollitiam-tykelabhacking_y_lucha_libre

Notable Campaigns

3
2022-2023European Parliament PEGA Committee, Spanish Surveillance Vendor Ecosystem Context (2022-2023)
2022EL PAIS Investigative Disclosure, Mollitiam Industries Spanish Spyware Vendor (February 2022)
2022Citizen Lab Technical Analysis, Mollitiam / Tykelab Infrastructure and Implant Characteristics (2022)

Attribution & Reporting

Attributed by
Citizen Lab (University of Toronto Munk School)EL PAIS (investigative reporting)Lookout SecurityGoogle TAG (Threat Analysis Group)European Parliament PEGA CommitteeAccessNowAmnesty International Tech LabRecorded Future
Key reporting
reportEL PAIS: La Empresa Española que Vende Spyware para Móviles (February 8, 2022), canonical first-disclosure
reportCitizen Lab: Mollitiam Industries / Tykelab Technical Analysis (2022)
reportEuropean Parliament PEGA Committee Final Report (May 2023), Spanish surveillance vendor ecosystem context
reportLookout Security: Commercial Android Spyware Vendor Analysis
reportMalpedia Actor Profile: Mollitiam Industries

Operational

State sponsor

Mollitiam Industries S.L. / Tykelab S.L. is a Spanish private sector offensive actor (PSOA), a commercial surveillance vendor that develops and markets Android and potentially iOS mobile surveillance platforms (Invisible Man, Real Fighter) to government law enforcement and intelligence clients under a commercial lawful-interception model. The company is based in Spain and came to public attention primarily through a February 2022 investigative reporting disclosure by the Spanish newspaper EL PAIS and subsequent technical analysis by Citizen Lab (University of Toronto Munk School). Mollitiam Industries S.L. appears to have subsequently restructured or rebranded under the Tykelab S.L. corporate designation, with the exact corporate continuity and restructuring timeline being partially unclear in public reporting.

The company marketed its Invisible Man Android surveillance platform with capabilities described in leaked product catalogues as providing comprehensive Android device surveillance including location tracking, microphone activation, message interception, and anti-forensics capabilities, marketed explicitly as a tool for governments, law enforcement agencies, and intelligence services. The company has not publicly disclosed its client list or deployment jurisdictions. The Mollitiam / Tykelab surveillance ecosystem occupies a smaller market position than Spanish peer PSOA Variston (curated at variston_heliconia.yaml) and Italian PSOA peers RCS Lab (curated at hacking_team_memento_labs.yaml), Cy4Gate (curated at cy4gate.yaml), NSO Group (curated at nso_group_pegasus.yaml), and Intellexa / Predator (curated at intellexa_predator.yaml), but represents a documented European PSOA market participant with reported government client operations.

No government cybersecurity authority has sanctioned Mollitiam / Tykelab.

Motivations
commercial_surveillance_vendor, government_mobile_surveillance_tools_sales, android_device_surveillance_product_development, psoa_commercial_operations, lawful_interception_commercial_model
Sectors
Regions

Detection Blind Spots

25 techniques
Across this actor’s 25 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)3/25 · 12%
Analytics (MITRE CAR)0/25 · 0%
Runtime / container (Falco)0/25 · 0%
File / malware (YARA)0/25 · 0%
Network (Suricata/Snort)2/25 · 8%
Vuln scan (Nuclei)0/25 · 0%

Atomic Test Plan

3 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MOLLITIAM IOS CAPABILITY
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin