Intellexa is an Israel-associated commercial surveillance consortium that supplies the Predator spyware platform and supporting exploitation infrastructure to government and other well-resourced customers. Greece has served as a central operational and training hub, with development personnel also based in North Macedonia. Predator was originally developed by the North Macedonian company Cytrox, which subsequently came under Intellexa's control. The platform has also been marketed as Helios, Nova, Green Arrow, and Red Arrow. Predator compromises Android and iOS devices through one-click and zero-click exploit chains. Its deployments have targeted journalists, human rights defenders, lawyers, opposition figures, government personnel, and private-sector individuals across numerous countries. Documented cases include surveillance of activists in Egypt, journalists and political figures in Greece, and a human rights lawyer in Pakistan. Intellexa has procured or developed at least 15 exploited zero-day vulnerabilities since 2021, including vulnerabilities in Chrome, Safari, and underlying mobile operating-system components. Delivery methods include messaging links, network-injection systems, and Aladdin, an advertising-based mechanism that delivers exploits through malicious advertisements without requiring a click. Predator collects messages, emails, calls, passwords, device locations, and screenshots, and can remotely activate microphones and cameras. Its anti-analysis and anti-forensics mechanisms detect research tools, developer settings, jailbreak artifacts, and interception configurations; report deployment failures; remove forensic artifacts; and suppress iOS recording indicators through SpringBoard injection and hooking. Intellexa has retained remote-access capabilities to customer surveillance systems, although operation of individual command-and-control deployments cannot be universally attributed to the vendor. Intellexa operates through a fragmented international network of affiliated and front companies. It has continued supplying spyware and adapting its exploitation and delivery infrastructure despite U.S. sanctions imposed on associated entities and executives in 2024 and investigations in Greece.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Apple patched three vulnerabilities exploited in the wild on September 21, 2023, including “CVE-2023-41991 - Certificate validation issue (CoreTrust).” The CoreTrust vulnerability subsequently appeared in TrollStore v2.
CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993 (Apple iOS) — Intellexa/Cytrox (Predator).
CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993 (Apple iOS) — Intellexa/Cytrox (Predator).
CVE-2023-2033 (Google Chrome) — Intellexa/Cytrox (Predator).
CVE-2023-2136 (Google Chrome) — Intellexa/Cytrox (Predator).
1 more CVE tied to this actor tracked in Mallory.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior example of a commercial spyware operator associated with Predator, cited in the context of exploit chains that start with browser UAF vulnerabilities and are chained with sandbox escapes.
Commercial spyware vendor described as owning Predator spyware and (per Jamf’s reverse engineering) potentially operating or tightly controlling standardized, vendor-managed C2/error-reporting infrastructure that collects detailed failure/anti-analysis telemetry from attempted infections to improve future deployments.
Intellexa is a commercial spyware vendor accused of accessing and potentially exposing data from government surveillance operations using its Predator spyware.
Intellexa is known for developing and distributing the Predator commercial spyware tool, which is used for surveillance, device tracking, and data theft. The group has been sanctioned by the US for posing a significant national security threat and enabling authoritarian regimes to spy on dissidents, journalists, and political opponents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.