Intellexa is a commercial spyware vendor and consortium of affiliated companies best known for the Predator surveillance platform, originally associated with Cytrox. It is widely characterized as a mercenary spyware provider that sells advanced intrusion and monitoring capabilities to government customers and other well-resourced buyers. Intellexa has been linked to surveillance operations in numerous countries and has faced sanctions, export-control actions, and sustained scrutiny over human rights abuses and national security risks, yet its operations have continued through a distributed corporate and technical network. Predator is an Android and iOS spyware platform capable of covert device compromise, data theft, persistent monitoring, and remote activation of microphones and cameras. Reporting has tied Intellexa to both one-click and zero-click delivery methods, including exploit links, malicious advertising-based delivery, and other tailored infection vectors. Predator has also been marketed under alternate names including Helios, Nova, Green Arrow, and Red Arrow. Public research indicates Intellexa has been one of the most prolific commercial users of zero-day exploits in recent years, with at least 15 iOS and Android zero-days attributed to Predator activity since 2021. Its exploit development and procurement have included mobile browser and browser-engine targets as well as broader mobile platform components. Intellexa’s activity has repeatedly been associated with targeting journalists, lawyers, opposition figures, human rights defenders, political actors, government personnel, and other high-value individuals. Public investigations have linked Predator deployments to abuses in Europe, Africa, the Middle East, and Asia, including surveillance of civil society and political targets. The company has also been associated with infrastructure and operational support spanning multiple jurisdictions, with front and partner entities reportedly involved in logistics, advertising technology, backend development, infrastructure setup, and customer enablement. Technical analysis of Predator shows a mature and highly evasive spyware framework with extensive anti-analysis, anti-forensics, and operational telemetry features. Documented capabilities include environment checks for jailbreaks, developer mode, security tooling, debugging, locale restrictions, crash monitoring, self-cleanup, and concealment of recording indicators on iOS. Researchers have also highlighted structured error reporting and troubleshooting mechanisms that suggest centralized oversight or tightly controlled deployment support. Separate investigations have raised concerns that Intellexa retained remote access or visibility into customer surveillance environments, implying a deeper operational role than a simple software supplier. Known associated names and structures include Intellexa, Intellexa Consortium, Intellexa Alliance, Cytrox, and a broader network of linked entities used to support Predator operations and delivery. Intellexa is regarded as a significant commercial spyware actor whose continued access to zero-days, adaptable infrastructure, and global customer base make it a persistent threat to civil society, government targets, and the broader mobile ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior example of a commercial spyware operator associated with Predator, cited in the context of exploit chains that start with browser UAF vulnerabilities and are chained with sandbox escapes.
Commercial spyware vendor described as owning Predator spyware and (per Jamf’s reverse engineering) potentially operating or tightly controlling standardized, vendor-managed C2/error-reporting infrastructure that collects detailed failure/anti-analysis telemetry from attempted infections to improve future deployments.
Intellexa is a commercial spyware vendor accused of accessing and potentially exposing data from government surveillance operations using its Predator spyware.
Intellexa is known for developing and distributing the Predator commercial spyware tool, which is used for surveillance, device tracking, and data theft. The group has been sanctioned by the US for posing a significant national security threat and enabling authoritarian regimes to spy on dissidents, journalists, and political opponents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.