Intellexa is a commercial spyware vendor and consortium associated with the Predator surveillance platform, a mercenary spyware capability used against Android and iOS devices. Predator has been marketed under multiple names including Helios, Nova, Green Arrow, and Red Arrow, and originated from Cytrox before being managed and distributed through Intellexa-linked entities. Intellexa has been widely identified as one of the most prolific commercial exploit users in recent years, with repeated use or procurement of mobile zero-day exploit chains since 2021. Predator is designed for covert surveillance of mobile devices and can harvest sensitive device data, monitor communications, capture screenshots, collect credentials and other stored information, and remotely activate microphones and cameras. Intellexa-linked operations have used both one-click and zero-click delivery methods, including exploit links delivered through messaging platforms, malicious advertisements in the mobile ad ecosystem, and network-injection capabilities. Reporting also describes additional delivery frameworks and exploit components used to compromise targets through mobile browsers and other device components. Technical analysis of Predator has shown mature anti-analysis, anti-forensics, and operator-support features. These include structured error-code reporting to command-and-control infrastructure, checks for developer mode, jailbreak artifacts, security tools, debugging and logging conditions, geographic restrictions, crash-log monitoring, self-cleanup, and mechanisms to suppress visible recording indicators on compromised iOS devices. The sophistication and standardization of these features have raised concerns that Intellexa retained significant visibility into, or control over, customer deployments and troubleshooting workflows. Investigations have also reported that Intellexa had the ability to remotely access customer surveillance systems and data associated with targeted individuals. Intellexa has been linked to surveillance of journalists, lawyers, opposition figures, human rights defenders, political actors, government personnel, and private-sector targets across multiple regions. Public reporting ties Predator activity to countries in Europe, Africa, the Middle East, Central Asia, and South Asia, and documents use against civil society as well as government and corporate targets. The company has remained active despite U.S. sanctions and broader international scrutiny, and its fragmented network of associated companies and facilitators has complicated attribution, enforcement, and disruption efforts. Known associated names and entities include Predator, Cytrox, and Intellexa-linked front or partner structures involved in distribution, infrastructure, advertising, training, and support. Intellexa is best characterized as a financially motivated commercial surveillance actor whose core capability is the development, acquisition, operationalization, and support of advanced spyware for government customers and other well-resourced buyers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior example of a commercial spyware operator associated with Predator, cited in the context of exploit chains that start with browser UAF vulnerabilities and are chained with sandbox escapes.
Commercial spyware vendor described as owning Predator spyware and (per Jamf’s reverse engineering) potentially operating or tightly controlling standardized, vendor-managed C2/error-reporting infrastructure that collects detailed failure/anti-analysis telemetry from attempted infections to improve future deployments.
Intellexa is a commercial spyware vendor accused of accessing and potentially exposing data from government surveillance operations using its Predator spyware.
Intellexa is known for developing and distributing the Predator commercial spyware tool, which is used for surveillance, device tracking, and data theft. The group has been sanctioned by the US for posing a significant national security threat and enabling authoritarian regimes to spy on dissidents, journalists, and political opponents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.