Predator is the name used for at least two distinct malware families, but the most widely recognized usage refers to the commercial mobile spyware platform developed by Cytrox and later associated with the Intellexa consortium. This spyware is designed for covert surveillance of mobile devices and has been linked to government customers and politically sensitive targeting, including journalists, politicians, and other public figures. Predator has been documented in campaigns against Android devices using spearphishing emails containing one-time links that redirected targets through attacker-controlled infrastructure and exploited chains of Chrome and Android zero-day vulnerabilities. In the Android intrusions publicly documented from 2021, operators first deployed Alien as a precursor component and then loaded the Predator implant. Reported Predator Android capabilities included recording audio, adding certificate authorities, and hiding applications to reduce visibility on the device. Cytrox was assessed to have packaged and sold exploit capabilities and spyware access to multiple government-backed customers in several countries.
Predator is also described as a highly capable mercenary spyware offering analogous in role to Pegasus, with tooling intended to penetrate both Android and iOS devices for covert data collection and surveillance. It has figured prominently in the Greek spyware scandal, where traces were found on numerous phones and where victims included journalist Thanasis Koukakis and politician Nikos Androulakis. Intellexa and related entities have been publicly associated with the development, distribution, and sale of Predator, and the platform has been the subject of sanctions, litigation, and criminal proceedings tied to alleged abuse.
A separate and unrelated malware family known as Predator the Thief is a Windows information stealer developed by Russian-speaking cybercriminals and sold on Russian-language forums. That malware steals browser credentials and other user data, uses anti-analysis and obfuscation techniques, and has been marketed as a low-cost commodity stealer. Because the supplied name is ambiguous, Predator should be disambiguated carefully in operational use. The dominant industry meaning, however, is the Cytrox/Intellexa mobile spyware platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #3 - Full Android 0-day exploit chain (CVE-2021-38003, CVE-2021-1048). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #2 - Chrome sandbox escape (CVE-2021-37973, CVE-2021-37976). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #3 - Full Android 0-day exploit chain (CVE-2021-38003, CVE-2021-1048). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #2 - Chrome sandbox escape (CVE-2021-37973, CVE-2021-37976). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
The five previously unknown 0-day security vulnerabilities used in these campaigns include: CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 in Chrome and CVE-2021-1048 in Android. Campaign #1 - redirecting to SBrowser from Chrome (CVE-2021-38000). | state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox.
"Intellexa’s Predator spyware can suppress Apple’s built-in camera and microphone indicators on compromised devices."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The commercial surveillance company is the maker of Predator, an implant analogous to that of NSO Group's Pegasus, and is known to have developed tools that enables its clients to penetrate iOS and Android devices.
Huit ressortissants grecs victimes du spyware Predator ont intenté une action en justice civile contre Intellexa, fabricant du logiciel espion... L’utilisation du spyware avait été révélée en 2022, avec des traces de Predator découvertes sur des dizaines de téléphones en Grèce.
Predator is a sophisticated mercenary spyware targeting both Android and iPhone devices and has been active since at least 2019.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Once clicked, the link redirected the target to an attacker-owned domain that delivered the exploits before redirecting the browser to a legitimate website.
at least 87 high-profile Greeks were targeted by Predator spyware via hundreds of SMS messages containing malicious links that exploited Chrome and Android zero-day vulnerabilities
Stealth - техники уровня Rootkit (T1014) для сокрытия артефактов ниже уровня ОС.
Predator’s owners decided to obfuscate most of its code with a number of simple techniques. XOR, Base64, Substitutions, Stack strings and more are being used to hide API methods, Folder paths, Register keys, the C2 server/Admin panel and so on.
Маскировка (T1036, Masquerading) Скрытие иконки, имя «System Service» Инъекция в легитимные процессы
compromise the system by injecting malicious code into privileged processes
Apple также сделала BlastDoor - механизм изоляции и валидации недоверенного контента в сообщениях до его попадания в чувствительные части системы. Это повышает стоимость разработки reliable spyware для iPhone.
Anti-debugging/sandbox checks Predator retains its old techniques for sandbox evasion... a hardcoded list of DLLs that are checked if loaded into memory
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Predator is a data stealer... supports the following list of browser data theft... Location, Games, FTP, VPN, 2FA, Messengers, Webcam, HWID, Clipboard, Specific document files (Grabber), Project filenames, Browsers IE/Edge.
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
The behavior we captured is clearly that of a clipboard stealer. The functionality includes a crawler that checks if the clipboard contains data, grabs it and places it in a dedicated file
the screenshot was transferred to a C2 using a stealer dubbed ‘Predator’... the owners are only selling the builder... optional service to help the customer install the C&C... IP/Domains
770 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
131 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware used to unlawfully surveil targets by compromising phones and violating privacy, communications confidentiality, and personal data.
Spyware mentioned only as a linked previous article; not part of the main NIS2 legal referral story.
Шпионская платформа, упомянутая как отдельный spyware-инструмент, ранее связывавшийся с обвинениями в масштабном использовании греческими властями.
Predator is spyware used to surveil targets by compromising their devices and violating the privacy and confidentiality of their communications and personal data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.