Amnesty International reported that the iPhone of Angolan journalist and press freedom advocate Teixeira Cândido was infected with Intellexa’s Predator spyware after he received multiple malicious links via WhatsApp in 2024. According to the investigation, Cândido was messaged from an unknown Angolan number over several weeks; he clicked one link on May 4, 2024, after which Predator was installed, and the spyware was later removed the same day when the device was restarted. Amnesty described this as the first documented Predator case in Angola, and said attribution remains unclear, though the activity is consistent with use by a government customer.
The reporting underscores continued alleged abuse of commercial spyware against civil society despite international pressure on Intellexa. Intellexa and associated individuals have faced U.S. actions including placement on the Entity List and subsequent sanctions (with later changes to some designations noted in coverage), yet Predator has been repeatedly linked to targeting of journalists and officials in multiple countries. Amnesty’s findings add to prior public reporting on Predator’s use in places such as Greece, Egypt, and Vietnam, reinforcing the ongoing risk posed by link-based mobile spyware delivery through common messaging platforms like WhatsApp.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Amnesty International publicly reported that Predator had been used to infect the iPhone of Angolan journalist Teixeira Cândido in May 2024, calling it the first documented use of the spyware in Angola and attributing it to a government customer of Intellexa.
In September 2024, the U.S. imposed sanctions on Intellexa executives and consultants, escalating pressure on the company and its leadership over spyware-related concerns.
A reboot a few hours after the compromise on 2024-05-04 removed the spyware from Cândido's device, limiting the duration of the infection.
On 2024-05-04, Teixeira Cândido clicked a malicious WhatsApp-delivered link from an unknown Angolan number, after which Intellexa's Predator spyware was installed on his iPhone. Amnesty later identified forensic traces and infrastructure consistent with Predator.
An operator posing as students reportedly spent weeks building trust with Angolan journalist Teixeira Cândido over WhatsApp before sending multiple malicious links, indicating a targeted surveillance effort.
The U.S. government added Intellexa to the Entity List, a move later cited as part of the ongoing scrutiny surrounding the spyware vendor's continued operations.
Amnesty found Predator-linked domains used in Angola, with the earliest infrastructure deployed as far back as March 2023, suggesting testing or operational setup in the country had begun by then.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcesecuritylab.amnesty.org
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.