A technical reference mapping known mobile surveillance tactics, techniques, and procedures against the resilience posture of the hardware intelligence layer. No proprietary implementation is disclosed; only externally observable properties are described.
The mobile threat landscape is dominated by actors who depend on software vulnerabilities to gain and maintain access. Their effectiveness is bounded by how quickly vendors patch. The hardware intelligence layer exists outside that economy — it does not rely on the vulnerabilities these actors exploit.
Nation-State · Advanced
Targets: Journalists, dissidents, executives, government officials
Deploys zero-day exploit chains (e.g. Pegasus-class) targeting iMessage, WhatsApp, and browser stacks. Relies on software vulnerabilities that vendors patch.
Private Sector · Advanced
Targets: High-value individuals, litigation adversaries, corporate intelligence
Sells exploit licenses to authorized and unauthorized buyers. Software-only delivery; efficacy degrades as OS vendors close the exploited vulnerabilities.
Financially Motivated · Moderate–High
Targets: Banking credentials, MFA tokens, corporate email
Uses banking trojans and overlay attacks inside the OS. Detectable by mainstream EDR and Play Protect once signatures exist.
Authorized Access · Low–Moderate
Targets: Employer devices, shared corporate handsets
Operates with device access; software implants can be discovered by routine device audits.
Each row maps a recognized mobile tactic to how it fares against the OS layer (the defender's domain) and against the hardware intelligence layer.
The hardware layer's resilience is not a single property but a set of independent guarantees. This summary states the verdict for each class of defensive action a target or defender might take.
Hardware layer does not use OS exploits to deploy.
No software artifact exists for a signature to match.
Persistence is architectural, below the OS data domain.
Isolated storage is not addressable from the OS image.
Out-of-band C2 is invisible to the monitored user's network stack.
SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.