Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
threat-infrastructure-trackingprivacy-surveillance-policytrade-export-controlgovernment-diplomatic-threat

Ongoing Global Deployment and Corporate Expansion of Intellexa Predator Spyware

Updated 3mo agoFirst seen Dec 4, 20256 sources

Researchers have uncovered continued deployment of the Predator spyware, developed by Intellexa, in multiple countries despite U.S. sanctions and increased scrutiny. New evidence indicates active use in Iraq, with additional operations linked to entities in Pakistan, Saudi Arabia, Kazakhstan, Angola, and Mongolia. Some countries, such as Egypt, Botswana, and Trinidad and Tobago, appear to have ceased communication with Intellexa, though this may reflect changes in infrastructure rather than a halt in activity. The spyware has been used against civil society members, business executives, and other high-value targets, with its costly licensing model suggesting a focus on strategic individuals. Ongoing legal proceedings against former Intellexa executives in Greece highlight the international concern over the company's activities.

Recorded Future’s Insikt Group has mapped a complex global network of individuals and entities associated with Intellexa, including those involved in backend development, infrastructure setup, and product distribution. Export and import data reveal that Intellexa’s products have been shipped to clients in various regions, with new evidence of product imports in Kazakhstan and the Philippines. The network also includes entities in the advertising sector potentially linked to the "Aladdin" ad-based infection vector. The persistent and likely unlawful use of Predator spyware continues to pose significant privacy, legal, and physical security risks, particularly for political opposition, business leaders, and individuals in sensitive roles worldwide.

Share:
Ongoing Global Deployment and Corporate Expansion of Intellexa Predator Spyware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Dec 8, 20257mo ago

Google issues Intellexa-linked spyware warnings to users

Google followed Apple's alerts with warnings affecting several hundred accounts across multiple countries, linking the activity to Intellexa exploit chains. Google said Intellexa continued operating despite sanctions and scrutiny.

Dec 4, 20257mo ago

Researchers uncover Intellexa remote access to customer systems

Investigations by Amnesty International, Google, and Recorded Future found Intellexa retained the ability to remotely access some customer Predator deployments. The finding raised concerns that the vendor could directly access surveillance operations run by its clients.

Dec 3, 20257mo ago

Recorded Future maps Intellexa's global corporate network

Recorded Future's Insikt Group published research detailing Intellexa's web of front companies and facilitators across multiple jurisdictions. The report said Predator operations continued despite sanctions and identified ongoing or recent activity in countries including Iraq, Saudi Arabia, Kazakhstan, Angola, Mongolia, and Mozambique.

Dec 2, 20257mo ago

Apple sends new spyware threat notifications worldwide

Apple sent a new round of threat notifications on December 2 to users it believed may have been targeted by sophisticated spyware operators. The company said it has now notified users in more than 150 countries overall.

Jan 1, 20251y ago

Predator targets a human rights lawyer in Pakistan

A human rights lawyer in Pakistan's Balochistan province was targeted with Predator via a suspicious WhatsApp link. The reporting describes this as the first known Predator infection or civil society targeting documented in Pakistan.

Google disrupts Intellexa-linked ad ecosystem companies

Google identified companies created by Intellexa that had infiltrated the online advertising ecosystem and helped shut them down. The action targeted infrastructure used to support ad-based Predator delivery such as the 'Aladdin' vector.

Jan 1, 20242y ago

U.S. sanctions Intellexa and related executives

Intellexa and several executives, including founder Tal Jonathan Dilian, were subjected to U.S. sanctions and other legal or regulatory actions. The sanctions were repeatedly cited as a major response to the company's spyware business.

Jan 1, 20233y ago

Google begins tracking Intellexa infrastructure with partners

Google said it has worked with partners since at least 2023 to track Intellexa infrastructure, add related domains to Safe Browsing, and notify affected users. This marks an ongoing defensive effort against Predator-linked operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

58 LINKEDOpen in app
Threat actors
3 linked
Malware
2 linked
Affected products
1 linked
Safari
Organizations
37 linked
IntellexaGoogleAppleRecorded FutureReutersTechRepublicWARP PANDAAmnesty InternationalPulse AdvertiseMorningstarMalwarebytesCytroxApolloNSO GroupCitizen LabArmcommerce_deptCitizenLabOOO Seven HillsComWorksRemote GreeceHermes TechnologiesShilo s.r.o.OOO NeoSoftBotswana Directorate of Intelligence and Security (DIS)KrikelNeo-Tech Asia DistributionIANUS ConsultingADDAPP TechnologiesZelus AnalyticsHadastech s.r.o.PULSE FZCOInside StoryHaaretzInside ITZerodiumInternational Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Ongoing Global Deployment and Corporate Expansion of Intellexa Predator Spyware | Mallory