Home/Threat Actor/Negg Group
Threat Actor

Negg Group

negg_group · italy · active since 2014-01

Negg Group S.r.l. is an Italian commercial surveillance vendor (PSOA) based in Rome operationally significant primarily for development of the Skygofree Android surveillance platform, canonically disclosed by Kaspersky January 16, 2018 and subsequently attributed to Negg Group through Italian investigative journalism (Motherboard / VICE, Il Fatto Quotidiano)

Skygofree's operational distinctiveness is the geofence-triggered audio recording capability (microphone activation automatically when target device enters specific geographic locations), operationally distinguishing from continuous-activation surveillance approaches.

distribution via fake mobile telecom provider service pages impersonating Italian telecom carrier customer service portals and via spearphishing links.

operates within broader Italian commercial surveillance vendor ecosystem alongside RCS Lab / Memento Labs (Hacking Team successor), Cy4Gate, and operationally dissolved eSurv, all curated separately in this corpus.

smaller and less publicly documented market participant than RCS Lab or Cy4Gate; thin public technical documentation relative to flagship PSOA entries.

curated for Italian PSOA ecosystem completeness.

italy confidence: medium 10 aliases
Sigma rules14 YARA rules5 Live IOCs0 CVEs exploited0

Profile

Negg Group S.r.l. is an Italian private sector offensive actor (PSOA), a commercial Android surveillance vendor based in Rome, Italy, operationally significant primarily for its development of the Skygofree Android surveillance platform. The platform was canonically disclosed by Kaspersky in January 2018 and subsequently attributed to Negg Group operations through Italian investigative journalism. The cluster operates within the broader Italian commercial surveillance vendor ecosystem.

Skygofree's operational distinctiveness in the commercial Android surveillance vendor market is the geofence-triggered audio recording capability, Skygofree could be configured to activate microphone recording automatically when the target device entered specific geographic locations, operationally distinguishing the platform from continuous- activation surveillance approaches and providing operational advantages for targeted intelligence collection at specific locations (target home addresses, target workplace locations, target travel itinerary venues). The geofence-triggered capability is one of the operationally-distinctive technical features documented in commercial Android surveillance products and was operationally innovative at the time of Kaspersky's January 2018 disclosure. Negg Group operates within the broader Italian commercial surveillance vendor ecosystem alongside RCS Lab (the former Hacking Team successor entity, curated at hacking_team_memento_labs.yaml), Cy4Gate (curated at cy4gate.yaml), and the operationally dissolved eSurv (curated at esurv.yaml).

The Italian PSOA market is operationally distinctive in the broader European commercial surveillance vendor ecosystem for having multiple competitive vendors operating concurrently. Negg Group operates as one of the smaller market participants and is less publicly documented than RCS Lab or Cy4Gate. The PSOA governance significance of Negg Group, like all commercial surveillance vendors in this curated corpus, is that government clients nominally purchasing Skygofree for lawful interception of criminal suspects have, in the broader PSOA ecosystem pattern, been documented to direct surveillance tools against journalists, human rights defenders, opposition politicians, and civil society members in contexts inconsistent with stated lawful-interception justifications.

No publicly-available technical report has definitively attributed specific Skygofree deployments against named civil society victims with the same evidentiary density as Citizen Lab's Pegasus forensic reports, Negg Group's public attribution footprint is thinner than NSO Group's but analytically significant in the Italian PSOA market context. Negg Group is curated as a thin-documentation entry relative to flagship PSOA entries in this corpus alongside Wintego Systems (wintego_systems.yaml), Mollitiam Industries / Tykelab (mollitiam_tykelab.yaml), and other smaller PSOA market participants. The entry is structurally significant for PSOA ecosystem completeness (providing coverage of the Italian Android surveillance vendor sub-ecosystem distinct from the more public-record-dense Cy4Gate and RCS Lab / Hacking Team / Memento Labs entries) rather than for deep technical tradecraft analysis.

Aliases

10
negg_groupnegg groupnegg group s.r.l.neggnegg srlskygofree_operatorsvbiss_operatorsskygofree spyware vendoritalian-psoa-neggpsoa-negg-group

Notable Campaigns

3
2022-2023European Parliament PEGA Committee, Italian Surveillance Vendor Ecosystem Context (2022-2023)
2018Kaspersky Skygofree Canonical Public Disclosure (January 2018)
2014-2025Negg Group Italian PSOA Market Position

Attribution & Reporting

Attributed by
KasperskyCitizen Lab (University of Toronto Munk School)Motherboard / VICE investigative reportingIl Fatto Quotidiano (Italian investigative journalism)Italian Public Prosecutor offices (selective)European Parliament PEGA CommitteeAccessNowPrivacy International
Key reporting
reportKaspersky Securelist: Skygofree, Following in the Footsteps of HackingTeam (January 16, 2018), canonical Skygofree first-disclosure
reportMotherboard / VICE: Negg Group Skygofree Investigative Reporting
reportIl Fatto Quotidiano: Negg Group Italian Surveillance Vendor Investigative Coverage
reportCitizen Lab: Italian Commercial Surveillance Vendor Research
reportEuropean Parliament PEGA Committee Final Report (May 2023), Italian surveillance vendor ecosystem context
reportMalpedia Actor / Malware Profile: Negg Group / Skygofree

Operational

State sponsor

Negg Group S.r.l. is an Italian private sector offensive actor (PSOA), a commercial surveillance vendor based in Italy (Rome) that develops, markets, and sells mobile surveillance platforms and adjacent intelligence-collection tools to government law enforcement and intelligence clients under a lawful-interception / government-exclusive commercial model. The company is operationally significant in industry analysis primarily for its development of the Skygofree Android surveillance platform, a sophisticated Android surveillance malware family canonically disclosed by Kaspersky in January 2018 and subsequently attributed by Kaspersky researchers and Italian investigative journalism (Motherboard / VICE, Il Fatto Quotidiano) to Negg Group operations. Negg Group operates within the broader Italian commercial surveillance vendor ecosystem that includes RCS Lab (the former Hacking Team successor entity, curated at hacking_team_memento_labs.yaml), Cy4Gate (curated at cy4gate.yaml), eSurv (curated at esurv.yaml, operationally dissolved following Italian criminal prosecution), Tykelab (operationally distinct Spanish PSOA, curated at mollitiam_tykelab.yaml), and selectively additional Italian commercial surveillance vendors.

The company's stated business model is government-exclusive lawful interception. The company does not publicly disclose its client list or deployment jurisdictions. The cluster's operational profile is thinner-documented than flagship Israeli PSOA peers (NSO Group, Intellexa, Paragon Solutions, Candiru) and represents one of the smaller Italian PSOA market participants.

Motivations
commercial_surveillance_vendor, government_mobile_surveillance_tools_sales, android_device_surveillance_product_development, italian_law_enforcement_client_focus, psoa_commercial_operations
Sectors
Regions

Detection Blind Spots

28 techniques
Across this actor’s 28 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)3/28 · 10%
Analytics (MITRE CAR)0/28 · 0%
Runtime / container (Falco)0/28 · 0%
File / malware (YARA)0/28 · 0%
Network (Suricata/Snort)2/28 · 7%
Vuln scan (Nuclei)0/28 · 0%

Atomic Test Plan

3 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SKYGOFREESKYGOFREE ANDROID IMPLANTSKYGOFREE GEOFENCE AUDIO CAPTURE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin