Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Cyberdecks are having a moment, rejecting big tech surveillance with style and substance

A startup, Everand, is now bringing together e-books, audiobooks and book clubs as a challenge to Amazon

Password manager Dashlane says hackers stole some customers’ password vaults

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Anthropic scales Claude Mythos to critical infrastructure in 15+ countries

    2 June 2026

    Florida sues OpenAI’s Sam Altman in first-of-its-kind violent crime lawsuit

    2 June 2026

    The internet is being remade for machines

    1 June 2026

    Understanding the AI ​​psychosis debate

    31 May 2026

    ‘What a joke’: Github Copilot’s new token-based pricing upsets developers

    31 May 2026
  • Apps

    Meta is testing ‘Series’ for episodic Reels on Instagram and Facebook

    2 June 2026

    A new app, The Mall, creates a universal flow for online shopping

    2 June 2026

    DuckDuckGo makes its ‘AI-free’ search engine easier to access as traffic grows

    1 June 2026

    TikTok’s road to becoming a super app

    31 May 2026

    YouTube adds new podcast features, including an AI recommendation tool and ‘Auto Speed’

    30 May 2026
  • Crypto

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026
  • Fintech

    Last 24 hours to save up to $410 on your Disrupt 2026 ticket

    29 May 2026

    2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

    28 May 2026

    Robinhood now allows your AI agents to trade stocks

    28 May 2026

    Disrupt 2026 Early Bird ticket savings expire in 3 days

    27 May 2026

    Disrupt 2026 Early Bird ticket prices end May 29

    26 May 2026
  • Hardware

    Cyberdecks are having a moment, rejecting big tech surveillance with style and substance

    3 June 2026

    Nvidia chases $200 billion CPU market with AI agent computing from Microsoft, Dell and HP

    2 June 2026

    This $300 Pizza Oven Can Easily Help Revive Your Summer Pizza Nights

    30 May 2026

    Kiwibit’s artificial intelligence bird feeder is my new backyard friend

    29 May 2026

    Vertu wants CEOs to run companies from a foldable AI starting at $6,880

    29 May 2026
  • Media & Entertainment

    A startup, Everand, is now bringing together e-books, audiobooks and book clubs as a challenge to Amazon

    2 June 2026

    The two biggest movies of this weekend were both directed by YouTubers

    31 May 2026

    The two biggest movies of this weekend were both directed by YouTubers

    30 May 2026

    YouTube will automatically flag videos with artificial intelligence

    28 May 2026

    Meta launches Instagram, Facebook and WhatsApp subscriptions, with more to follow, including AI plans

    27 May 2026
  • Security

    Password manager Dashlane says hackers stole some customers’ password vaults

    2 June 2026

    Hackers took over Instagram accounts by tricking the Meta AI support chatbot into granting access

    1 June 2026

    Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

    30 May 2026

    Microsoft is under fire for threatening a security researcher with a criminal investigation

    29 May 2026

    A security flaw in prison payphone service Pay Tel exposed publicly the driver’s licenses of more than 300,000 callers

    29 May 2026
  • Startups

    Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

    2 June 2026

    From Stage to Future: Where Are Startup Battlefield Alumni Now?

    2 June 2026

    Revolut offers service to thousands of users in India ahead of wider rollout

    1 June 2026

    The deadline to submit applications for the Startup Battlefield 200 has been extended to June 8

    30 May 2026

    H1 secures $40M from CVS, proving SaaS startups can still attract investment

    30 May 2026
  • Transportation

    Defense tech darling Mach Industries hits $1.8 billion valuation, 4x jump in one year

    2 June 2026

    SpaceX says it may issue ‘significant’ equity in ‘future transactions’

    1 June 2026

    TechCrunch Mobility: It doesn’t matter that people hate the Ferrari Luce

    31 May 2026

    Rivian is under investigation for rear suspension failures on R1 models

    30 May 2026

    Waymo’s newest robotaxi is Chinese-made, built to make money, and is now accepting riders

    30 May 2026
  • Venture

    How Europe’s AI strategy diverges from Silicon Valley’s

    2 June 2026

    How to make the Startup Battlefield Top 20 — and what each company gets regardless

    2 June 2026

    Black founders raise highest quarterly funding since 2022, but there’s a catch

    31 May 2026

    Snap alums reveal Ghost Angels fund

    31 May 2026

    The groupthink explosion: what three top VCs really think about the AI ​​frenzy

    30 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Spyware startup Variston is shedding staff — some say it’s shutting down
Security

Spyware startup Variston is shedding staff — some say it’s shutting down

techtost.comBy techtost.com16 February 202408 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Spyware Startup Variston Is Shedding Staff — Some Say It's
Share
Facebook Twitter LinkedIn Pinterest Email

In July 2021, someone sent Google a bundle of malicious code that could be used to hack Chrome, Firefox, and computers running Microsoft Defender. This code was part of an exploit framework called Heliconia. And at the time, the exploits used to target these apps were zero-day, meaning software makers were unaware of the bugs, according to Google.

More than a year later, in November 2022, the Google Threat Analysis Group, the company’s group that investigates government-sponsored threats, published a blog post analyzing these exploits and the Heliconia framework. Google researchers concluded that the code belonged to Variston, a startup based in Barcelona that was unknown to the public.

“It was a huge crisis at the time, mainly because we had been under the radar for quite some time,” a former Variston employee told TechCrunch. “Everyone thought we would eventually be exposed if we were caught [in the wild]but instead he was a burglar.”

Another former Variston employee said the code was sent to Google by a disgruntled company employee, and that after it happened, Variston’s name and privacy were “burnt.”

Google continued to dig up the Variston malware. In March 2023, the tech giant’s researchers discovered that spyware manufactured by Variston was being used in Kazakhstan, Malaysia and the United Arab Emirates. Last week, Google reported that it found Variston hacking tools being used against iPhone owners in Indonesia.

Over the past year, more than half a dozen Variston employees have left the company, they told TechCrunch on condition of anonymity because they were not authorized to speak to the press due to non-disclosure agreements.

Now, according to four former employees and two people with knowledge of the spyware market, Variston is shutting down.

In the early 2010s, the public began to learn that there was a thriving market where Western-based companies such as Hacking Team, FinFisher and the NSO Group provided surveillance and hacking tools to countries and regimes around the world with dubious or poor human rights records such as Ethiopia, Mexico, Saudi Arabia, the United Arab Emirates and many others.

Since then, digital and human rights organizations such as Citizen Lab and Amnesty International have recorded dozens of cases where government customers of these spyware makers used these tools to hack and spy on journalists, dissidents and human rights defenders.

In recent years, the offensive security industry has become more public and normalized. Some of these spyware makers and exploit developers openly advertise their services online, their employees reveal where they work on social media, and there are some popular security conferences that openly cater to this industry, such as OffensiveCon and HexaCon.

Variston, however, has always tried to fly under the radar.

The only public facing company information is a barebones website where he vaguely describes what he does.

“Our toolset is based on the vast cumulative experience of our consultants. It supports the discovery of digital information from [law enforcement agencies],” says Variston’s website, in its only brief mention of its work as a spyware and exploit developer for government agencies.

Variston banned employees from disclosing where they work, not only on LinkedIn, but also at cybersecurity conferences, according to former employees who spoke to TechCrunch.

Variston’s website. Image Credits: TechCrunch (screenshot)

According to Spanish business records seen by TechCrunch, Variston was founded in Barcelona in 2018, listing Ralf Wegener and Ramanan Jayaraman as founders and directors.

While its website lists another address in the city, Variston recently worked out of an office in Barcelona’s Poblenou neighborhood, inside a co-working space a block from the beach. In October, a spokesperson for the co-working space told TechCrunch that Variston was there and had been for a few years.

When TechCrunch visited Variston’s office this week, a fellow site representative claimed that Variston still works there. The representative offered to leave a message for Variston, saying that he was not there that day, but that he was in the building that week. Neither Wegener nor Jayaraman responded to multiple emails from TechCrunch seeking comment about Variston. An email to Variston’s public email address was not returned.

One of Variston’s first moves in 2018 was an acquisition Real IT, a small zero-day research startup in Italy, according to Italian business filings seen by TechCrunch. Since then, Variston has grown into a company of around one hundred employees. In addition to Heliconia, the company’s exploit framework for targeting Windows devices, Variston has also developed exploit and hacking tools targeting iOS and Android. Variston’s Android product was called Violet Pepper, according to former employees.

Even the founders of Truel IT, who moved to work at Variston, do not disclose Variston as an employer on their LinkedIn profiles.

According to former Variston employees, that level of secrecy also applied to the identity of the company’s customers — except for its special relationship with Protect, a company based in the United Arab Emirates city of Abu Dhabi.

“Variston was a supplier to Protect,” said a person with knowledge of Protect’s operations, who asked to remain anonymous because they were not authorized to speak to the press. “It was an important relationship for both of them for a while.”

The company’s work was “going to the UAE” and that Protect was “de facto the only customer”, according to former Variston employees.

Former employees told TechCrunch that Protect funded all operations at Variston, including the research and development side. A former Variston employee said that once Protect withdrew its development-side funding in early 2023, Protect tried to force Variston employees to relocate. Then, when research funding stopped later in the year, Variston “closed up shop,” the person said.

Contact us

Do you know more about Variston or Protect? From a non-working device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or via email. You can also contact TechCrunch via SecureDrop.

In early 2023, Protect asked all Variston employees to relocate to Abu Dhabi. This is where Variston began to unravel, as most of the Variston staff did not accept the proposal. The former employees said management gave them two options: “move to Abu Dhabi or be fired” and that there would be no exceptions.

Protect accounts as “a leading cybersecurity and forensics company.” Like Variston, Protect says little else on its website about what the company does.

But Google security researchers believe that Protect, also known as Protect Electronic Systems, “combines the spyware it develops with Heliconia’s framework and infrastructure into a complete package that is then offered for sale either to a local broker or directly to a government customer.

This would explain how Variston’s tools allegedly ended up being used in Indonesia, Kazakhstan and Malaysia.

According to Intelligence Onlinea trade publication covering the surveillance and intelligence industry, Protect was launched after DarkMatter, a controversial hacking company based in the United Arab Emirates, it was revealed that he had employed Americans which then helped the UAE government spy on dissidents, political opponents and journalists.

As of 2019, Protect was headed by Awad Al Shamsi and provided UAE government users with discreet access to foreign cyber technology, Intelligence Online reported. It is not known if Al Shamsi is still with Protect, and Al Shamsi did not respond to an email seeking comment. Protect did not respond to several other emails from TechCrunch.

Variston founders Wegener and Jayaraman also appear to have worked at Protect since at least 2016, according to public online files of encryption keys linked to their Protect email addresses seen by TechCrunch.

Wegener is a veteran of the spyware industry. According to Intelligence Online, Wegener runs several other companies, some based in Cyprus and co-owned by Jayaraman. Wegener worked for AGT, or Advanced German Technology, a surveillance provider founded in Berlin in 2001 with an office in Dubai. In 2007, along with Italian spyware maker RCS Lab, AGT worked with the Syrian government to develop a centralized real-time internet monitoring system across the country. according to reports based on leaked documents and research by the non-profit Privacy International. Ultimately, AGT did not provide the system to the Syrian government.

Five years after its founding, Variston is no longer a secretive startup.

Three former employees said Google’s 2022 report blew the lid off Variston’s privacy. One of the employees said that the Google report revealing Variston “may have been the beginning of the end” for the spyware maker.

But another former Variston employee said the company — like other spyware makers — would have been exposed eventually. “It’s bound to happen sooner or later,” the person said. “It’s quite normal.”

Natasha Lomas contributed reporting.

An earlier version of this report incorrectly attributed Google’s discovery of Variston’s tools to Italy, due to an error by the editor. ZW.

Android barista cyber security Google infosec shedding shutting Spyware staff startup surveillance Variston Windows Zero-days
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleKnock takes the pain out of creating notification workflows
Next Article This German non-profit organization is creating an open voice assistant that anyone can use
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Cyberdecks are having a moment, rejecting big tech surveillance with style and substance

3 June 2026

A startup, Everand, is now bringing together e-books, audiobooks and book clubs as a challenge to Amazon

2 June 2026

Password manager Dashlane says hackers stole some customers’ password vaults

2 June 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Cyberdecks are having a moment, rejecting big tech surveillance with style and substance

3 June 2026

A startup, Everand, is now bringing together e-books, audiobooks and book clubs as a challenge to Amazon

2 June 2026

Password manager Dashlane says hackers stole some customers’ password vaults

2 June 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Last 24 hours to save up to $410 on your Disrupt 2026 ticket

29 May 2026

2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

28 May 2026

Robinhood now allows your AI agents to trade stocks

28 May 2026
Startups

Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

From Stage to Future: Where Are Startup Battlefield Alumni Now?

Revolut offers service to thousands of users in India ahead of wider rollout

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.