Predator is a commercial mobile spyware platform associated with Intellexa and Cytrox and used for covert surveillance of smartphones. It has been publicly linked to targeting of journalists, politicians, civil society members, and other high-profile individuals, including in Greece and multiple other countries. Predator is widely characterized as one of the more capable mercenary spyware offerings and has been deployed in state surveillance contexts.
Predator is designed to compromise mobile devices and extract sensitive data while remaining difficult to detect. Reported capabilities include covert collection and exfiltration of communications and device data, with surveillance of messages, calls, location, microphone, camera, and other sensitive content commonly associated with this class of tooling. Available reporting also describes a two-component architecture in which an initial compromise component, often referred to as Alien, breaches the device and Predator then deploys surveillance modules.
On Android, Predator has been linked to exploit chains involving Chrome and Android zero-day vulnerabilities, and campaigns in Greece were reported to use malicious SMS links to deliver exploitation. Separate reporting states that zero-click delivery has also been implemented through an associated platform referred to as Mars. Predator has been discussed alongside other advanced mobile spyware such as Pegasus and Candiru as part of the commercial surveillance ecosystem.
Predator has been repeatedly associated with Intellexa’s corporate network and with founder Tal Dilian. Public investigations, sanctions activity, court proceedings, and forensic reporting have tied Intellexa-linked entities to the development, distribution, and use of the platform. From 2024 to 2026, evidence was reported of Predator or Candiru deployments in at least sixteen countries, and Amnesty International forensically confirmed Predator targeting of an Angolan journalist in 2026. In Greece, Predator became central to a major political and legal scandal after traces were found on dozens of phones and multiple prominent victims were identified.
Predator primarily targets mobile devices, with direct support in the available facts for Android and broader phone spyware use. It is best understood as a mercenary spyware platform used for covert intelligence collection, post-compromise surveillance, and exfiltration against selected targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android. | Our research specifically looks at two components of this mobile spyware suite known as “ALIEN” and “PREDATOR,” which compose the backbone of the spyware implant.
We assess that QUAILEGGS likely exploits the aforementioned zero-day vulnerability CVE-2021-1048. Based on Google’s root cause analysis, this vulnerability allows code injection into privileged processes... According to the Linux kernel development git logs, the vulnerability was public since August 2020 and patched in September. However, some Google Pixel phones remained vulnerable until March 2021 and Samsung devices until at least October 2021. | Our research specifically looks at two components of this mobile spyware suite known as “ALIEN” and “PREDATOR,” which compose the backbone of the spyware implant.
Our research specifically looks at two components of this mobile spyware suite known as “ALIEN” and “PREDATOR,” which compose the backbone of the spyware implant. | The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android.
The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android. | Our research specifically looks at two components of this mobile spyware suite known as “ALIEN” and “PREDATOR,” which compose the backbone of the spyware implant.
Our research specifically looks at two components of this mobile spyware suite known as “ALIEN” and “PREDATOR,” which compose the backbone of the spyware implant. | The report describes how adversaries exploited five different zero-day vulnerabilities to deliver ALIEN... The vulnerabilities, which were discovered in 2021, are CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003 — all of which affect Google Chrome, and CVE-2021-1048 in Linux and Android.
"Intellexa’s Predator spyware can suppress Apple’s built-in camera and microphone indicators on compromised devices."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Huit ressortissants grecs victimes du spyware Predator ont intenté une action en justice civile contre Intellexa, fabricant du logiciel espion... L’utilisation du spyware avait été révélée en 2022, avec des traces de Predator découvertes sur des dizaines de téléphones en Grèce.
Разбираешь sysdiagnose-дамп через MVT - а оттуда лезут IOC-паттерны Pegasus и Predator... Predator от Cytrox / Intellexa работает двухкомпонентно: Alien ломает устройство, Predator устанавливает модули слежки.
Predator is a sophisticated mercenary spyware targeting both Android and iPhone devices and has been active since at least 2019.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
For instance, as defenders work to eliminate entire classes of vulnerabilities, spyware operators may adapt by targeting alternatives such as cloud backups accessed via stolen credentials or by employing new deployment methods.
SMS messages containing malicious links that exploited Chrome and Android zero-day vulnerabilities
at least 87 high-profile Greeks were targeted by Predator spyware via hundreds of SMS messages containing malicious links that exploited Chrome and Android zero-day vulnerabilities
Stealth - техники уровня Rootkit (T1014) для сокрытия артефактов ниже уровня ОС.
Обфускация (T1027, Obfuscated Files) Минимальная или ProGuard Многослойная: шифрование строк, VM-упаковщик
Маскировка (T1036, Masquerading) Скрытие иконки, имя «System Service» Инъекция в легитимные процессы
For instance, as defenders work to eliminate entire classes of vulnerabilities, spyware operators may adapt by targeting alternatives such as cloud backups accessed via stolen credentials or by employing new deployment methods.
Apple также сделала BlastDoor - механизм изоляции и валидации недоверенного контента в сообщениях до его попадания в чувствительные части системы. Это повышает стоимость разработки reliable spyware для iPhone.
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
FBot is primarily designed for actors to hijack cloud, SaaS, and web services. There is a secondary focus on obtaining accounts to conduct spamming attacks. Actors can use the credential harvesting features to obtain initial access, which they can sell to other parties.
Финальная стадия в терминах MITRE ATT&CK - T1005 (Data from Local System, Collection) → T1041 (Exfiltration Over C2 Channel, Exfiltration).
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
Collection - имплант активирует Keylogging (T1056.001), Screen Capture (T1113), Audio Capture (T1123), Video Capture (T1125).
748 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
125 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware used to unlawfully surveil targets by compromising phones and violating privacy, communications confidentiality, and personal data.
Spyware mentioned only as a linked previous article; not part of the main NIS2 legal referral story.
Шпионская платформа, упомянутая как отдельный spyware-инструмент, ранее связывавшийся с обвинениями в масштабном использовании греческими властями.
Predator is spyware used to surveil targets by compromising their devices and violating the privacy and confidentiality of their communications and personal data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.