Skip to main content
Mallory
MalwareUsed by 1 actor

Aladdin

Aladdin is a zero-click mobile malware delivery mechanism associated with Intellexa and used to deploy Predator spyware. First deployed in 2024 and believed to remain operational and under active development, it leverages commercial mobile advertising systems to deliver weaponized ads to specific targets identified by public IP address and other identifiers. The ads are served through the ad-tech ecosystem, including Demand Side Platform (DSP) infrastructure, on participating websites. A targeted device can be infected simply by viewing the malicious advertisement, with no user interaction required. Reporting cited in the source material states that the ads fingerprint and redirect targeted visitors to Intellexa exploit delivery servers, where zero-day exploit chains are used to install Predator. The activity is linked to Intellexa, a commercial spyware vendor whose customers are described as governments and large corporations, and whose operations have been corroborated by investigations involving Amnesty International, Google TAG, and Recorded Future. The supporting infrastructure has been reported across multiple countries and obscured through shell companies. High-confidence defensive notes mentioned in the content are that ad blocking and hiding public IP addresses may provide partial mitigation, although mobile operators may still leak identifying information.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Intellexa

First deployed in 2024 and believed to still be operational and actively developed, Aladdin leverages the commercial mobile advertising system to deliver malware. The mechanism forces weaponized ads onto specific targets identified by their public IP address and other identifiers, instructing the platforms via the Demand Side Platform (DSP) to serve it on any website participating in the ad network.

via bleeping computerbleepingcomputer.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.