Offensive Cyber as an Asset Class
On October 17, 2025, a U.S. federal judge (N.D. Cal.) issued a permanent injunction barring NSO Group from targeting WhatsApp, the capstone of a six-year suit over the 2019 Pegasus campaign against ~1,400 users — even as the damages were cut to ~$4M on appeal. Weeks earlier, in October 2025, a U.S.-investor group led by film producer Robert Simonds acquired a controlling stake in NSO Group (reported in the tens of millions), installing former U.S. ambassador David Friedman as chairman. The juxtaposition illustrates the asset class: a widely sanctioned spyware vendor, on the U.S. Commerce Entity List since Nov 2021 and enjoined by a U.S. court, was simultaneously being bought by U.S. investors. Offensive cyber — the commercial trade in exploits, intrusion tools, and surveillance capability — is a real, capitalized market. The question is whether it is investable, who the players are, and why most institutional buyers avoid it.
Two distinct markets, often conflated
"Offensive cyber" spans two commercially different things:
- The legitimate offensive-security market — penetration testing, red-teaming, breach-and-attack simulation, autonomous pentest (AEV), and exploit-development sold to defenders and governments for testing. This is a healthy, fundable segment covered on 04f and 20a (Pentera, Horizon3.ai, XBOW, Synack, Bishop Fox). It is defensible offense.
- The commercial surveillance / intrusion-as-a-service market — zero-day brokers and spyware vendors (NSO, Intellexa, Paragon, Candiru, Cytrox, plus exploit acquirers like Zerodium/Crowdfense) that sell intrusion capability to government clients. This is the controversial, sanction-exposed market this page focuses on.
The economic engine of market (2) is the zero-day: an undisclosed vulnerability plus a weaponized exploit. A reliable iOS/Android remote chain commands seven figures from brokers; vendors package chains into turnkey surveillance products and license them per-target or per-deployment to state agencies. Margins are extraordinary; so is the tail risk.
The named landscape and its risk overlay
The cost asymmetry that creates the market
Cyber is the only domain of conflict in which offence is structurally cheaper than defence, and the gap is not marginal — it is several orders of magnitude. The comparison against conventional capability makes the point plainly: a nuclear weapons programme runs to roughly $10B, a US aircraft carrier about $13B, an F-35 roughly $80M per unit, a Tomahawk about $1.9M. NotPetya, assessed by the White House as causing over $10B in global damage — the most destructive cyberattack on record — cost its originator little more than the salaries of a small team over a few months. A phishing campaign costs about $50 to run.
The asymmetry has a structural cause rather than a technological one. Defensive cost scales with attack surface; offensive cost scales with the single entry point the attacker needs to find. Every additional device, account, SaaS tenant, vendor portal and legacy system a defender operates adds cost and adds exposure. The attacker's cost is set by the difficulty of one path in. This means the wealthiest, most digitised economies carry the largest defensive burden precisely because they have the most surface, while a small state with a few thousand focused operators and narrow objectives faces almost none of that cost. The economics favour the weaker party, which is why offensive cyber has become the asymmetric instrument of choice for states that cannot compete conventionally.
Published exploit-broker bounties give the upper bound of the offensive market's input costs. A full-chain, zero-click iOS exploit — a message that fully compromises a device with no user interaction — is publicly bountied at $5–7M; equivalent Android capability up to about $5M; a browser full chain in the $2–3M range. Those are the most expensive tools in the arsenal, and they remain three orders of magnitude below a single conventional strike platform. Zerodium, long the best-known broker, has been largely inactive since its founder paused public operations in early 2025; Crowdfense, based in Abu Dhabi, has effectively taken its place as the principal public acquirer.
The commercial consequence for the defensive industry is the demand engine this wiki returns to repeatedly. Because offence gets cheaper faster than defence does — and AI compresses the attacker's cost further still (AI for Offense) — defensive spend is not a discretionary budget line that can be optimised away. It is the cost of operating attack surface, and it rises with digitisation regardless of the security team's competence. That is the structural floor under the sector's growth, and it is also the reason the bear case on 31 is about where value accrues rather than whether spend continues.
The regulatory wall
What makes the surveillance market structurally hard to capitalize is a thickening lattice of U.S. and allied controls:
- Commerce Entity List — NSO Group and Candiru were added in Nov 2021; Intellexa and Cytrox entities followed in Jul 2023. Listing chokes off U.S. technology and, practically, U.S. capital.
- OFAC sanctions — Treasury designated Intellexa Consortium principals and entities in Mar 2024 and again in Sep 2024; a subset of those designations was partially lifted in late 2025, underscoring how politically reversible — and therefore unpredictable — the regime is.
- The Executive Order on commercial spyware (Mar 2023) restricts U.S. government use of commercial spyware that poses counterintelligence/human-rights risks — cutting off a large potential customer.
- Court action — the NSO/WhatsApp injunction (Oct 17 2025) shows even non-sanction legal exposure can impair the core product.
Against that wall, the Paragon case is the revealing counterexample: in 2024, AE Industrial Partners (a Florida PE firm) acquired Paragon for ~$500M, and the U.S. government later reactivated a Paragon contract — a bet that a "clean," U.S.-aligned, governance-forward surveillance vendor can be a sanctioned-incumbents' replacement. Whether that bet pays depends entirely on the political wind, which the Intellexa sanctions reversal shows can shift without warning.
The investability verdict
For mainstream Western capital, the commercial-surveillance market is largely un-investable — not because the unit economics are bad (they are excellent) but because the risk is uninsurable and non-diversifiable: a single designation, EO, or adverse ruling can zero the enterprise overnight, and LP agreements, banking relationships, and reputational exposure compound the problem. The defensible offensive-security market (market 1) is the opposite — venture-funded, platform-acquired (04f, 20a), and growing as "continuous validation" becomes a budget line. The asset class exists; the capital that can safely touch it is narrow and specialized (state-linked or politically-aligned vehicles like the Paragon buyers, not generalist PE/VC).
The state-aligned exception: government-contract offense
A third path is emerging between the two markets: AI-native offensive cyber built as a sovereign capability for a single government customer rather than a commercial product. In July 2026, Cathedral — a startup co-founded by four former U.S. DOGE staffers (Gavin Kliger, previously the Pentagon's chief data officer; Luke Farritor; Marko Elez; and Jack Stein) — closed a $160 million round at a $1.4 billion valuation, led by Andreessen Horowitz and Sequoia Capital, both of which took board seats. The company aims to win U.S. government contracts for AI-driven military cyber operations spanning both offensive and defensive capabilities against adversaries such as China, and is exploring acquiring or partnering with a data-center provider to secure dedicated compute. Its founders maintain close ties to the Trump administration and the Pentagon.
Cathedral illustrates how generalist venture capital, which avoids the commercial-surveillance cluster, will fund offensive cyber when the customer is the home government and the work is framed as national defense. The economics differ from the spyware market: the risk is not OFAC/Entity-List exposure but government-contract concentration and political reversibility — Cathedral's ties to one administration are also its principal risk if control of Congress or the White House changes. This is the same "politically-aligned vehicle" pattern as the Paragon buyers, now expressed as a domestic, venture-scale, AI-first defense contractor rather than a foreign-surveillance acquisition. The dual-use question — when an AI system built to find and exploit vulnerabilities is a weapon versus a defensive tool — is the same one running through 20a and the Fable/Mythos export debate on 20f.
Twenty is the larger and earlier instance of the same asset class. Founded in 2024 and describing itself as "America's first VC-backed cyber-warfare startup," it builds AI-enabled, end-to-end offensive systems for the U.S. military and Intelligence Community. Following a $100 million Series B at a $1.0 billion valuation led by Accel in June 2026, it raised an additional $30 million from Khosla Ventures in July 2026 at a $1.2 billion valuation, bringing total funding to roughly $168 million; its cap table includes In-Q-Tel, General Catalyst, Point72 Ventures, Caffeinated Capital, and Friends & Family Capital (see 14, 08a). Contemporary reporting describes the Pentagon already using the company's AI to automate cyber operations. Twenty differs from Cathedral in two respects that sharpen the pattern: its backing is anchored by a national-security investor syndicate (In-Q-Tel) rather than generalist funds alone, and its revenue concentration on U.S. government and allied customers is a deliberate design rather than an emerging risk — the same government-contract concentration and political-reversibility exposure applies in equal measure.
Sources: U.S. court permanent injunction vs NSO / WhatsApp (Oct 17 2025) · NSO acquired by U.S. investor group led by Robert Simonds (Oct 2025) · Treasury sanctions on Intellexa Consortium (Mar 2024) · Treasury sanctions on Intellexa enablers (Sep 2024) · State Dept on Intellexa sanctions · Paragon acquired by AE Industrial Partners (~$500M, 2024) — Atlantic Council / Sekoia overview · Cathedral $160M round at $1.4B valuation, a16z + Sequoia (Reuters, Jul 22 2026) · Twenty raises additional $30M from Khosla Ventures at $1.2B valuation (PR Newswire, Jul 20 2026) · The Pentagon Is Using This $1.2 Billion Startup's AI To Automate Cyberwarfare (Forbes, Jul 21 2026) · Entity-List additions (NSO/Candiru Nov 2021; Intellexa/Cytrox Jul 2023) and EO on commercial spyware (Mar 2023) per Commerce/White House records.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.