Predator is a mercenary mobile spyware platform associated with the Intellexa Consortium. It is designed for covert surveillance of high-value targets and has been linked to operations against high-profile individuals, including journalists and other politically sensitive targets. Public reporting has tied the development and distribution of Predator to Intellexa-linked entities and individuals, including sanctions action by the United States. Predator is part of the commercial spyware ecosystem rather than a conventional state APT or financially motivated cybercrime group. Its operators and customers have been associated with targeted surveillance activity in multiple regions, including documented infrastructure activity in Central and Southern Africa. The spyware has remained active despite public exposure, sanctions, and policy interventions, indicating continued operational support and demand. Predator should be distinguished from unrelated malware families that share the same name in other contexts. In cloud-crime reporting, “Predator” has also been used to refer to a separate malware family associated with Androxgh0st-derived credential-scraping code; that usage is distinct from the Intellexa-linked mobile spyware platform. Known aliasing in security reporting includes Predator spyware operators and Intellexa Consortium-linked Predator operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud attack tool family that uses Androxgh0st-derived credential scraping logic to obtain cloud and SaaS credentials.
Predator is a mobile spyware platform that has seen renewed activity despite international scrutiny and sanctions. The content does not specify recent targeting or techniques, only that its use continues.
Operators linked to the Intellexa Consortium are responsible for developing and distributing Predator spyware, which has been used to target high-profile individuals in multiple countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.