The Olam
Cybersecurity

QuaDream

By The Olam Editorial Team · Jul 20, 2026

QuaDream

Defunct Israeli offensive-cyber firm behind REIGN spyware. Founded circa 2016 by ex-NSO alumni. Shut down April 2023 after Citizen Lab+Microsoft joint disclosure and Israeli MoD denial of a Morocco export license — the category's canonical licensing-system termination.

QuaDream is a defunct Israeli offensive-cyber company that developed the REIGN mobile-device interception platform. Founded circa 2016 by figures drawn from NSO Group alumni and from Israeli intelligence, QuaDream operated as a lower-profile competitor to Pegasus until an April 2023 joint disclosure by the Citizen Lab and Microsoft exposed its client base and technical infrastructure. Within days, the firm shut its offices and dismissed its workforce; subsequent Haaretz reporting attributed the closure to the Israeli Ministry of Defense's denial of an export license for a QuaDream sale to Morocco. QuaDream is the category's canonical case of an offensive-cyber vendor terminated by the Israeli export-licensing system rather than by product failure or US civil litigation.

Dabelstein, ex-NSO alumni, and QuaDream's founding

QuaDream was founded circa 2016. The reported founder cohort includes Ilan Dabelstein and additional former NSO employees, with backing drawn from figures in the Israeli offensive-cyber capital pool. The founding thesis was direct product substitution against Pegasus for customers whom NSO would not or could not serve — a bet on the segment of the demand curve that Pegasus's customer-vetting layer had explicitly declined. QuaDream's founding is the reference case for the industry's post-founding spinout dynamic: senior NSO alumni carrying zero-click iOS exploit expertise into a new corporate vehicle at a discount vetting posture, on the assumption that Israeli MoD licensing would clear at each individual sale.

REIGN product architecture

REIGN is a mobile-device interception platform focused on iPhone compromise via zero-click exploit chains. Microsoft described REIGN in its April 2023 disclosure as "a suite of exploits, malware, and infrastructure designed to exfiltrate data from mobile devices," including real-time call recording, front and back camera activation, and microphone activation — capabilities disclosed in a QuaDream sales brochure recovered by the Citizen Lab. The signature exploit, ENDOFDAYS (Microsoft's designation: KingsPawn), abused a flaw in iOS's handling of iCloud calendar invites to deliver a zero-click payload without generating any user-visible notification. Apple patched the underlying flaw in iOS 14.4.2 (March 2021).

The April 2023 Citizen Lab and Microsoft joint disclosure

On April 11, 2023, the Citizen Lab and Microsoft published simultaneous reports on REIGN. Citizen Lab identified malicious servers linked to REIGN in ten countries — Bulgaria, the Czech Republic, Hungary, Ghana, Israel, Mexico, Romania, Singapore, the United Arab Emirates, and Uzbekistan — and documented traces on at least five compromised devices belonging to journalists, opposition figures, and one non-governmental-organization worker. The client-country list overlapped materially with jurisdictions that would not have cleared a strict democracies-only filter, positioning REIGN inside the same regulatory-risk profile that Israel's 2023 export tightening was subsequently designed to address.

The Morocco license denial and the shutdown

On April 16, 2023 — five days after the joint disclosure — Haaretz reported that QuaDream had called all employees to a pre-termination hearing. Within days, Calcalist reported that operations had ceased and the board was seeking a buyer for the company's intellectual property; only two employees remained on site to look after equipment. In May 2023, Haaretz reported that the immediate trigger for the closure was the Israeli Ministry of Defense's denial of an export license for a sale to Morocco — a deal QuaDream had brought to closure but that the MoD, in the fallout from earlier NSO Group public scandals, declined to authorize. The five-source Haaretz account is the definitive public record of an Israeli offensive-cyber vendor shut down by a single denied license.

The Cyprus-to-Saudi Arabia shell routing

QuaDream is also the reference case for the industry's use of shell-company structures to reach customers whom the Israeli MoD would not directly license. Haaretz reported in June 2021 that QuaDream had sold REIGN to Saudi Arabia via a Cyprus-registered shell company — a routing that has since been read across to a set of subsequent Israeli offensive-cyber transactions, and that materially informed the 2023 Israeli export-policy tightening. Whether the Cyprus routing survived the MoD's post-2023 licensing filter is one of the category's live empirical questions and one of the most-watched compliance topics for successor Israeli offensive-cyber vendors.

The Reuters and Haaretz corroboration record

Reuters reporting in 2022 confirmed that QuaDream had independently developed an iOS exploit comparable to NSO's Pegasus, exploiting a flaw in iMessage that Apple patched in September 2021. The Reuters–Haaretz–Citizen Lab–Microsoft record on QuaDream is one of the most technically corroborated case files in the commercial-spyware category — and it exists, uniquely, on a firm that has already been terminated. That makes QuaDream the category's cleanest available case study in what an offensive-cyber vendor's technical, customer, and licensing profile looks like at the moment of shutdown.

QuaDream's place in the cohort

QuaDream is the cohort's terminated case: the vendor whose product was viable, whose customer pipeline was signed, and whose exit was foreclosed by the Israeli licensing system rather than by product failure or civil litigation. Its shutdown is the strongest single piece of public-record evidence that Israeli MoD export licensing is a live, binding, and terminating constraint on the category — not merely a formal filter. For every Israeli offensive-cyber vendor now weighing US private-equity acquisition (Paragon), civil litigation posture (NSO Group), corporate opacity (Candiru), or acceptance of the MoD's post-2023 country restrictions, QuaDream is the reference outcome for what non-compliance looks like at the terminal stage.

Primary Sources

Citizen Lab, "Sweet QuaDreams: A First Look at Spyware Vendor QuaDream's Exploits, Victims, and Customers" (April 11, 2023). Microsoft Threat Intelligence Center report on KingsPawn (April 11, 2023). Haaretz reporting on the QuaDream shutdown (April 16, 2023) and the Morocco license denial (May 2023). Calcalist reporting on operational cessation. Reuters reporting on QuaDream's iMessage exploit (2022). Israeli MoD licensing decisions under DECA / SIBAT.

Related Olam Coverage

Unit 8200 · NSO Group · Paragon Solutions · Candiru · Israel's 2007 Defense Export Control Law · Cyber-export 102-to-37 tightening · SIBAT — Israel's weapons salesman

Crypto & Digital Assets

View all →