Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Exaforce Raises $125M Series B to Build AI to Catch and Stop Cyberattacks as They Happen

Potholes are costing cities millions: This company uses artificial intelligence and trucks to fix them

Anthropic warns investors against secondary platforms offering access to its shares

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Medicare’s new payment model is designed for artificial intelligence, and most of the tech world has no idea

    13 May 2026

    Dessn raises $6 million for production-focused design tool

    12 May 2026

    Riding on an AI rally, Robinhood is preparing its second retail IPO

    12 May 2026

    There aren’t enough rockets for space data centers. Cowboy Space raised $275 million to build them.

    11 May 2026

    We’re feeling cynical about xAI’s big deal with Anthropic

    11 May 2026
  • Apps

    Everything Google announced at its Android Expo, from Googlebooks to vibe-encoded widgets

    13 May 2026

    TikTok now wants to be the place where you book that trip you just saw on TikTok

    12 May 2026

    Discord Launches Nitro Rewards, Giving Subscribers Access to Xbox Game Pass Base Level at No Extra Cost

    11 May 2026

    Etsy launches its ChatGPT app as it continues its AI push

    10 May 2026

    Tinder Match Group owner slows hiring to pay for increased use of AI tools

    10 May 2026
  • Crypto

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025
  • Fintech

    Venmo’s biggest makeover in years comes at a very interesting time

    11 May 2026

    Fintech startup Parker files for bankruptcy

    10 May 2026

    Robinhood’s venture fund IPO attracted 150,000+ private investors, CEO says

    7 May 2026

    PayPal says it’s “becoming a tech company again” — that’s AI

    6 May 2026

    Stripe introduces Link, a digital wallet that autonomous AI agents can also use

    1 May 2026
  • Hardware

    Google unveils Googlebook, a new line of laptops with native artificial intelligence

    13 May 2026

    The Instax Wide 400 takes the simplicity of instant photography and expands it, literally

    10 May 2026

    Google Unveils Fitbit Air Without Whoop-like Display

    8 May 2026

    Google’s $9.99 per month AI health plan launches on May 19

    8 May 2026

    Apple to pay $250 million to settle lawsuit over Siri’s lagging AI features

    7 May 2026
  • Media & Entertainment

    Digg is trying again, this time as an AI news aggregator

    12 May 2026

    Bravo creates unscripted mini-dramas for the Peacock app

    11 May 2026

    The hottest place for startups to strike a deal? The F1 mantra

    10 May 2026

    Netflix delays Greta Gerwig’s ‘Narnia’ for big theatrical push to 2027

    2 May 2026

    Roku’s $3 streaming service Howdy hits 1 million subscribers, per recent report

    29 April 2026
  • Security

    Exaforce Raises $125M Series B to Build AI to Catch and Stop Cyberattacks as They Happen

    13 May 2026

    Google launches new Android security feature to help uncover spyware attacks

    12 May 2026

    US healthcare marketplaces shared citizenship and race data with ad tech giants

    11 May 2026

    Some kids bypass age verification checks with a fake moustache

    10 May 2026

    Police arrest crew that sent malicious messages to thousands across Toronto

    10 May 2026
  • Startups

    Korea’s biggest manufacturers support Config, TSMC robot data

    11 May 2026

    China’s Moonshot AI Raises $2B in $20B Valuation as Demand for Open Source AI Soars

    10 May 2026

    Could Lovable’s automatic 10% pay rise be the cure for toxic cultures?

    9 May 2026

    Gusto hits $1 billion in revenue, moves closer to public markets

    9 May 2026

    Learn what it takes to raise a Series A in 2027 at Disrupt 2026

    8 May 2026
  • Transportation

    Potholes are costing cities millions: This company uses artificial intelligence and trucks to fix them

    13 May 2026

    Waymo issues recall to address a flooding issue

    12 May 2026

    GM just laid off hundreds of IT workers to hire people with stronger AI skills

    12 May 2026

    TechCrunch Mobility: Lime’s IPO bet

    11 May 2026

    Uber always wanted to be more than a ride. now he has reason to hurry

    11 May 2026
  • Venture

    Anthropic warns investors against secondary platforms offering access to its shares

    13 May 2026

    Mother Ventures looks at moms as the ‘economic engine’

    9 May 2026

    2 days left: Get 50% off a second Disrupt 2026 pass

    7 May 2026

    All your M&A questions will be answered at Disrupt 2026

    6 May 2026

    ElevenLabs lists BlackRock, Jamie Foxx and Eva Longoria as new investors

    6 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Spyware startup Variston is shedding staff — some say it’s shutting down
Security

Spyware startup Variston is shedding staff — some say it’s shutting down

techtost.comBy techtost.com16 February 202408 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Spyware Startup Variston Is Shedding Staff — Some Say It's
Share
Facebook Twitter LinkedIn Pinterest Email

In July 2021, someone sent Google a bundle of malicious code that could be used to hack Chrome, Firefox, and computers running Microsoft Defender. This code was part of an exploit framework called Heliconia. And at the time, the exploits used to target these apps were zero-day, meaning software makers were unaware of the bugs, according to Google.

More than a year later, in November 2022, the Google Threat Analysis Group, the company’s group that investigates government-sponsored threats, published a blog post analyzing these exploits and the Heliconia framework. Google researchers concluded that the code belonged to Variston, a startup based in Barcelona that was unknown to the public.

“It was a huge crisis at the time, mainly because we had been under the radar for quite some time,” a former Variston employee told TechCrunch. “Everyone thought we would eventually be exposed if we were caught [in the wild]but instead he was a burglar.”

Another former Variston employee said the code was sent to Google by a disgruntled company employee, and that after it happened, Variston’s name and privacy were “burnt.”

Google continued to dig up the Variston malware. In March 2023, the tech giant’s researchers discovered that spyware manufactured by Variston was being used in Kazakhstan, Malaysia and the United Arab Emirates. Last week, Google reported that it found Variston hacking tools being used against iPhone owners in Indonesia.

Over the past year, more than half a dozen Variston employees have left the company, they told TechCrunch on condition of anonymity because they were not authorized to speak to the press due to non-disclosure agreements.

Now, according to four former employees and two people with knowledge of the spyware market, Variston is shutting down.

In the early 2010s, the public began to learn that there was a thriving market where Western-based companies such as Hacking Team, FinFisher and the NSO Group provided surveillance and hacking tools to countries and regimes around the world with dubious or poor human rights records such as Ethiopia, Mexico, Saudi Arabia, the United Arab Emirates and many others.

Since then, digital and human rights organizations such as Citizen Lab and Amnesty International have recorded dozens of cases where government customers of these spyware makers used these tools to hack and spy on journalists, dissidents and human rights defenders.

In recent years, the offensive security industry has become more public and normalized. Some of these spyware makers and exploit developers openly advertise their services online, their employees reveal where they work on social media, and there are some popular security conferences that openly cater to this industry, such as OffensiveCon and HexaCon.

Variston, however, has always tried to fly under the radar.

The only public facing company information is a barebones website where he vaguely describes what he does.

“Our toolset is based on the vast cumulative experience of our consultants. It supports the discovery of digital information from [law enforcement agencies],” says Variston’s website, in its only brief mention of its work as a spyware and exploit developer for government agencies.

Variston banned employees from disclosing where they work, not only on LinkedIn, but also at cybersecurity conferences, according to former employees who spoke to TechCrunch.

Variston’s website. Image Credits: TechCrunch (screenshot)

According to Spanish business records seen by TechCrunch, Variston was founded in Barcelona in 2018, listing Ralf Wegener and Ramanan Jayaraman as founders and directors.

While its website lists another address in the city, Variston recently worked out of an office in Barcelona’s Poblenou neighborhood, inside a co-working space a block from the beach. In October, a spokesperson for the co-working space told TechCrunch that Variston was there and had been for a few years.

When TechCrunch visited Variston’s office this week, a fellow site representative claimed that Variston still works there. The representative offered to leave a message for Variston, saying that he was not there that day, but that he was in the building that week. Neither Wegener nor Jayaraman responded to multiple emails from TechCrunch seeking comment about Variston. An email to Variston’s public email address was not returned.

One of Variston’s first moves in 2018 was an acquisition Real IT, a small zero-day research startup in Italy, according to Italian business filings seen by TechCrunch. Since then, Variston has grown into a company of around one hundred employees. In addition to Heliconia, the company’s exploit framework for targeting Windows devices, Variston has also developed exploit and hacking tools targeting iOS and Android. Variston’s Android product was called Violet Pepper, according to former employees.

Even the founders of Truel IT, who moved to work at Variston, do not disclose Variston as an employer on their LinkedIn profiles.

According to former Variston employees, that level of secrecy also applied to the identity of the company’s customers — except for its special relationship with Protect, a company based in the United Arab Emirates city of Abu Dhabi.

“Variston was a supplier to Protect,” said a person with knowledge of Protect’s operations, who asked to remain anonymous because they were not authorized to speak to the press. “It was an important relationship for both of them for a while.”

The company’s work was “going to the UAE” and that Protect was “de facto the only customer”, according to former Variston employees.

Former employees told TechCrunch that Protect funded all operations at Variston, including the research and development side. A former Variston employee said that once Protect withdrew its development-side funding in early 2023, Protect tried to force Variston employees to relocate. Then, when research funding stopped later in the year, Variston “closed up shop,” the person said.

Contact us

Do you know more about Variston or Protect? From a non-working device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or via email. You can also contact TechCrunch via SecureDrop.

In early 2023, Protect asked all Variston employees to relocate to Abu Dhabi. This is where Variston began to unravel, as most of the Variston staff did not accept the proposal. The former employees said management gave them two options: “move to Abu Dhabi or be fired” and that there would be no exceptions.

Protect accounts as “a leading cybersecurity and forensics company.” Like Variston, Protect says little else on its website about what the company does.

But Google security researchers believe that Protect, also known as Protect Electronic Systems, “combines the spyware it develops with Heliconia’s framework and infrastructure into a complete package that is then offered for sale either to a local broker or directly to a government customer.

This would explain how Variston’s tools allegedly ended up being used in Indonesia, Kazakhstan and Malaysia.

According to Intelligence Onlinea trade publication covering the surveillance and intelligence industry, Protect was launched after DarkMatter, a controversial hacking company based in the United Arab Emirates, it was revealed that he had employed Americans which then helped the UAE government spy on dissidents, political opponents and journalists.

As of 2019, Protect was headed by Awad Al Shamsi and provided UAE government users with discreet access to foreign cyber technology, Intelligence Online reported. It is not known if Al Shamsi is still with Protect, and Al Shamsi did not respond to an email seeking comment. Protect did not respond to several other emails from TechCrunch.

Variston founders Wegener and Jayaraman also appear to have worked at Protect since at least 2016, according to public online files of encryption keys linked to their Protect email addresses seen by TechCrunch.

Wegener is a veteran of the spyware industry. According to Intelligence Online, Wegener runs several other companies, some based in Cyprus and co-owned by Jayaraman. Wegener worked for AGT, or Advanced German Technology, a surveillance provider founded in Berlin in 2001 with an office in Dubai. In 2007, along with Italian spyware maker RCS Lab, AGT worked with the Syrian government to develop a centralized real-time internet monitoring system across the country. according to reports based on leaked documents and research by the non-profit Privacy International. Ultimately, AGT did not provide the system to the Syrian government.

Five years after its founding, Variston is no longer a secretive startup.

Three former employees said Google’s 2022 report blew the lid off Variston’s privacy. One of the employees said that the Google report revealing Variston “may have been the beginning of the end” for the spyware maker.

But another former Variston employee said the company — like other spyware makers — would have been exposed eventually. “It’s bound to happen sooner or later,” the person said. “It’s quite normal.”

Natasha Lomas contributed reporting.

An earlier version of this report incorrectly attributed Google’s discovery of Variston’s tools to Italy, due to an error by the editor. ZW.

Android barista cyber security Google infosec shedding shutting Spyware staff startup surveillance Variston Windows Zero-days
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleKnock takes the pain out of creating notification workflows
Next Article This German non-profit organization is creating an open voice assistant that anyone can use
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Exaforce Raises $125M Series B to Build AI to Catch and Stop Cyberattacks as They Happen

13 May 2026

Everything Google announced at its Android Expo, from Googlebooks to vibe-encoded widgets

13 May 2026

Google unveils Googlebook, a new line of laptops with native artificial intelligence

13 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Exaforce Raises $125M Series B to Build AI to Catch and Stop Cyberattacks as They Happen

13 May 2026

Potholes are costing cities millions: This company uses artificial intelligence and trucks to fix them

13 May 2026

Anthropic warns investors against secondary platforms offering access to its shares

13 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Venmo’s biggest makeover in years comes at a very interesting time

11 May 2026

Fintech startup Parker files for bankruptcy

10 May 2026

Robinhood’s venture fund IPO attracted 150,000+ private investors, CEO says

7 May 2026
Startups

Korea’s biggest manufacturers support Config, TSMC robot data

China’s Moonshot AI Raises $2B in $20B Valuation as Demand for Open Source AI Soars

Could Lovable’s automatic 10% pay rise be the cure for toxic cultures?

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.