Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
privacy-surveillance-policyenforcement-actiongovernment-diplomatic-threatinitial-access-method

US Treasury Removes Sanctions on Intellexa Predator Spyware Executives

Updated 3mo agoFirst seen Jan 4, 20262 sources

The US Treasury Department, under the Trump administration, has removed three individuals previously sanctioned for their involvement with the Intellexa consortium, the group behind the Predator commercial spyware platform. These individuals—Sara Hamou, Andrea Gambazzi, and Merom Harpaz—were originally sanctioned by the Biden administration in 2024 for their roles in managing and distributing Predator, which has been linked to surveillance activities targeting dissidents, journalists, and political opponents. The Treasury stated that the delistings were part of a normal administrative process following petitions for reconsideration, with each individual demonstrating steps to separate themselves from Intellexa. Despite the removals, concerns remain among researchers and human rights advocates, as recent investigations indicate that Intellexa continues to operate Predator and has expanded its targeting capabilities, including the use of malicious mobile advertisements for infection.

The decision to lift these sanctions signals a shift in US policy toward commercial spyware vendors, with critics warning that it may embolden the use of surveillance tools by authoritarian regimes. The move follows earlier actions by the Trump administration to ease restrictions on other spyware companies, raising questions about the future of US efforts to curb the proliferation of commercial surveillance technology. The Predator spyware remains a significant concern for national security and human rights, as it enables extensive device tracking, data theft, and surveillance operations on infected devices.

Share:
US Treasury Removes Sanctions on Intellexa Predator Spyware Executives
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 2, 20266mo ago

Treasury removes three former Intellexa-linked individuals from sanctions list

The Trump administration removed three Iranians from the U.S. sanctions list after a petition and evidence presented to the Treasury Department indicated they had separated themselves from Intellexa. The delisting reversed sanctions imposed in 2024 over their alleged involvement with the Predator spyware consortium.

Dec 1, 20257mo ago

Investigations find Predator spyware still operating despite sanctions

By late 2025, investigations reported that Intellexa was still operating the Predator spyware platform despite prior U.S. sanctions. The findings fueled continued human rights concerns and criticism over the effectiveness of the sanctions regime.

Jan 1, 20242y ago

Biden administration sanctions three Iranians tied to Intellexa

In 2024, the U.S. government sanctioned three Iranian individuals for their roles in the Intellexa consortium, the commercial spyware operation behind Predator. The sanctions were part of broader U.S. action against spyware actors linked to abuses and surveillance activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Threat actors
2 linked
Malware
2 linked
Organizations
10 linked
IntellexaParagon SolutionsKorean AirOracleXspeederEmurasoftPwn.aiWALSHAM INVESTMENTS LIMITEDKC&DThalestris Limited
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.