Cyber warfare in the twenty-first century has blurred the lines between nation-states and criminal syndicates; now, it is evolving into yet another dimension: the privatization of cyber warfare. Emerging from this trajectory are Israel's NSO Group, Candiru, and a multitude of newly rising hacker mercenary corporations. Operating under the guise of private entities while executing grey-zone missions that official state intelligence agencies find difficult to bear, they have emerged as the new players in modern cyber warfare.

NSO Group stands as the symbolic emblem of this phenomenon. They developed a strain of spyware dubbed Pegasus and marketed it directly to sovereign governments. While they brandished the pretext of monitoring terrorists and criminal organizations, international condemnation ensued as evidence surfaced that they targeted journalists, human rights activists, and opposition politicians. The critical point is that NSO is not a mere collective of rogue hackers; rather, it established legitimate contracts through corporate entities, delivering cyber warfare capabilities as a service. In essence, cyber warfare has been commodified and commercialized.
Candiru , another Israeli enterprise, belongs to this identical current. Candiru operates with even greater stealth than NSO, supplying tailored spyware to countries not only in the Middle East but also across Europe and Asia. They offer bespoke attacks fitted to the client's desired target, packaging malware delivery mechanisms and zero-day vulnerabilities separately for transaction. Just as arms dealers export missiles to various nations, cyber weaponry has begun to cross sovereign borders through private corporations.
Particularly in recent years, these cyber mercenary companies have been actively utilized by emerging economies and authoritarian regimes. If cyber warfare was once the exclusive playground of superpowers like the United States, China, Russia, and Israel, today even minor Middle Eastern states, African nations, and Southeast Asian countries can procure cyber warfare capabilities provided they possess the funds. This phenomenon—which may be termed the democratization or privatization of cyber warfare—is accelerating instability across the globe.
Furthermore, these mercenary enterprises occasionally adopt mega-corporations or even political factions as clients, reaching beyond mere state consumers. At this juncture, cyber warfare transcends the realm of national security, expanding into a battlefield for private power factions. Aside from NSO and Candiru, similar cyber mercenary startups are surfacing in India, the United Arab Emirates, and Uzbekistan, trading zero-day weapons and targeted spyware via the dark web or informal channels.
The privatization of cyber warfare signifies technological advancement on one hand, yet it betrays a collapse of regulation on the other. Nations face distinct limits in controlling enterprises within their borders, and penalizing these entities operating in a global market has become increasingly elusive. Indeed, although the United States government placed NSO Group on its blacklist, Pegasus continues to be circulated through circuitous routes.
Ultimately, the future of cyber warfare is evolving not into a simple collision between nation-states, but into a complex theater where nations, criminal syndicates, and private mercenary corporations are intricately intertwined. And the rules of this battlefield are increasingly dictated by raw capital and technological prowess. Just as the landscape of conventional military might shifted with the appearance of private military contractors like Blackwater, private corporations bearing names like NSO and Candiru have now begun to dominate the arena of cyber warfare.
As the paradigm of cyber warfare privatizes, its primary ammunition—zero-day vulnerabilities—is naturally becoming commodified. In the past, zero-days were the exclusive domain of state intelligence agencies or elite hackers. Today, however, they have transformed into commodities traded through black markets, the dark web, and even corporate channels wearing the mantle of legitimacy.
A zero-day refers to a security vulnerability in software or systems that the developers or security vendors have not yet recognized. Once a zero-day is weaponized, it becomes possible to neutralize or covertly infiltrate a target system while the defense stands entirely powerless. For this reason, zero-days are frequently analogized to nuclear weapons in cyber warfare. And this very nuclear arsenal is now morphing into a form that anyone can purchase, provided they possess the funds.
The growth of this market is inextricably linked to the rise of cyber mercenary corporations like NSO Group. The primary reason Pegasus spyware was so formidable was that they purchased bundles of zero-day vulnerabilities and weaponized them. Not only NSO, but also Candiru, Cytrox, and emerging Middle Eastern and Eastern European firms maintain networks to procure zero-days. This network operates as an informal arms market, where hacker communities, former state intelligence operatives, and brokers intersect.
Particularly of late, wealthy authoritarian regimes in the Middle East, Southeast Asia, and Eastern Europe are actively participating as buyers of zero-days. As seen in the case of the United Arab Emirates (UAE), state intelligence agencies are increasingly purchasing zero-days through private firms to strike diplomatic and political rivals. They conduct these transactions informally, utilizing special discretionary funds or state-owned enterprise capital rather than official state budgets.
Another defining trait of the zero-day weapons market is the astronomical surge in pricing. While an iPhone zero-day commanded a mere several hundred thousand dollars in the early 2010s, it currently trades at prices exceeding two million dollars per exploit. Certain complex vulnerability chains command upwards of five million dollars, a price point that even a small nation can easily shoulder as part of its national cyber capability. As the black-marketing of zero-days progresses, the asymmetry of cyber warfare has intensified. A structure has been finalized where organizations or nations entirely devoid of technological competence can lay their hands on the world's most cutting-edge weaponry, provided they have the capital.
Intriguingly, this market straddles the boundary between the illicit and the licit. In the United States and Europe, bug bounty platforms such as Zerodium or Crowdfense exist; they acquire zero-days and deliver them to their clients, who are government agencies. While officially a legitimate transaction, these zero-days occasionally find their way into the hands of oppressive regimes in Middle Eastern or African nations. Hence, this market can be described as a grey zone where the white market and the black market converge.
Consequently, the stealthy expansion of the zero-day weapons market is converting cyber warfare from a simple conflict between states into a global arms-trading enterprise. And the links forged through this market construct a sophisticated ecosystem composed of firms like NSO, syndicated hacker groups, and the rulers of emerging nations.
This ecosystem is bound to expand further in the future. From attempts to anonymize zero-day transactions through blockchain technology, to the rise of dark web-based auction platforms, and the commercialization of automated AI vulnerability discovery tools. The marketization of cyber weaponry has become an irreversible current, and these weapons are being deployed ever more covertly, yet with devastating potency, amidst the global struggles for power.