Predator is commercial mobile spyware developed by Cytrox and marketed through the Intellexa consortium for targeted surveillance of Android and iOS devices. It has been deployed by government-backed operators against journalists, political figures, and other high-profile individuals. Documented targets include Egyptian opposition politician Ayman Nour and Greek investigative journalist Thanasis Koukakis. Predator is distinct from the unrelated Windows information stealer known as Predator the Thief.
Documented infection campaigns use targeted emails and SMS messages containing malicious links that lead to browser exploit infrastructure. Exploit chains combine browser code execution, sandbox escapes, and operating-system privilege escalation, including zero-day vulnerabilities capable of compromising fully updated devices. Three Android campaigns in 2021 exploited Chrome and Android vulnerabilities and deployed an Alien component before loading Predator. A Predator-associated iOS exploit chain in 2023 combined Safari remote code execution, kernel privilege escalation, and a CoreTrust certificate-validation bypass through CVE-2023-41993, CVE-2023-41992, and CVE-2023-41991.
Predator supports covert collection of sensitive device information and audio surveillance. Its iOS components include mechanisms for keystroke monitoring, camera access, and VoIP recording. Earlier iOS versions were primarily Python-based and used Shortcuts for persistence; an analyzed 2023 loader was rewritten in native code. That loader downloads and supervises additional components, provides interprocess services backed by kernel read/write access, and conceals execution arguments from process-listing tools. Earlier versions also removed crash logs to reduce forensic visibility. No persistence module was identified in the analyzed 2023 loader.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993 (Apple iOS) — Intellexa/Cytrox (Predator).
CVE-2023-3079 (Google Chrome) — Intellexa/Cytrox (Predator).
Apple patched three vulnerabilities exploited in the wild on September 21, 2023, including “CVE-2023-41991 - Certificate validation issue (CoreTrust).” The CoreTrust vulnerability subsequently appeared in TrollStore v2.
CVE-2023-2033 (Google Chrome) — Intellexa/Cytrox (Predator).
CVE-2023-2136 (Google Chrome) — Intellexa/Cytrox (Predator).
CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993 (Apple iOS) — Intellexa/Cytrox (Predator).
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #3 - Full Android 0-day exploit chain (CVE-2021-38003, CVE-2021-1048). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #2 - Chrome sandbox escape (CVE-2021-37973, CVE-2021-37976). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #3 - Full Android 0-day exploit chain (CVE-2021-38003, CVE-2021-1048). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #2 - Chrome sandbox escape (CVE-2021-37973, CVE-2021-37976). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #1 - redirecting to SBrowser from Chrome (CVE-2021-38000). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
"Intellexa’s Predator spyware can suppress Apple’s built-in camera and microphone indicators on compromised devices."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Leaks show Intellexa burning zero-days to keep Predator spyware running”
The commercial surveillance company is the maker of Predator, an implant analogous to that of NSO Group's Pegasus, and is known to have developed tools that enables its clients to penetrate iOS and Android devices.
Predator is a sophisticated mercenary spyware targeting both Android and iPhone devices and has been active since at least 2019.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Once clicked, the link redirected the target to an attacker-owned domain that delivered the exploits before redirecting the browser to a legitimate website.
at least 87 high-profile Greeks were targeted by Predator spyware via hundreds of SMS messages containing malicious links that exploited Chrome and Android zero-day vulnerabilities
Stealth - техники уровня Rootkit (T1014) для сокрытия артефактов ниже уровня ОС.
Predator’s owners decided to obfuscate most of its code with a number of simple techniques. XOR, Base64, Substitutions, Stack strings and more are being used to hide API methods, Folder paths, Register keys, the C2 server/Admin panel and so on.
Маскировка (T1036, Masquerading) Скрытие иконки, имя «System Service» Инъекция в легитимные процессы
compromise the system by injecting malicious code into privileged processes
Apple также сделала BlastDoor - механизм изоляции и валидации недоверенного контента в сообщениях до его попадания в чувствительные части системы. Это повышает стоимость разработки reliable spyware для iPhone.
Anti-debugging/sandbox checks Predator retains its old techniques for sandbox evasion... a hardcoded list of DLLs that are checked if loaded into memory
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Predator is a data stealer... supports the following list of browser data theft... Location, Games, FTP, VPN, 2FA, Messengers, Webcam, HWID, Clipboard, Specific document files (Grabber), Project filenames, Browsers IE/Edge.
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
The behavior we captured is clearly that of a clipboard stealer. The functionality includes a crawler that checks if the clipboard contains data, grabs it and places it in a dedicated file
the screenshot was transferred to a C2 using a stealer dubbed ‘Predator’... the owners are only selling the builder... optional service to help the customer install the C&C... IP/Domains
773 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
135 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware associated with Intellexa, mentioned only as a headline in a list of malware-news items.
Commercial mobile spyware mentioned as a comparison for the zero-click, radio-layer exploitation profile; it is not identified as exploiting CVE-2026-58704.
Commercial spyware used to unlawfully surveil targets by compromising phones and violating privacy, communications confidentiality, and personal data.
Spyware mentioned only as a linked previous article; not part of the main NIS2 legal referral story.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.