Google's Threat Analysis Group said Cytrox's Predator spyware was deployed in three 2021 campaigns that chained five zero-day vulnerabilities across Chrome and Android to compromise fully updated Android devices, including Samsung phones. The attacks used one-time spear-phishing links sent by email, redirected victims through attacker-controlled domains, and then forwarded them to legitimate websites after exploitation. Google said the exploit chains included Chrome sandbox escapes, Android privilege-escalation flaws, and in some cases a Samsung browser pivot, allowing operators to install the Alien malware first and then load the Predator implant.
Google assessed with high confidence that Cytrox, a North Macedonian spyware vendor, packaged the exploits and sold them to multiple government-backed customers linked to Egypt, Armenia, Greece, Madagascar, Côte d'Ivoire, Serbia, Spain, and Indonesia. The campaigns were described as limited in scale, targeting only tens of users, but the spyware gave operators extensive surveillance access, including the ability to record audio, add CA certificates, and hide apps. Google's findings aligned with earlier Citizen Lab reporting that identified Predator on the phone of exiled Egyptian politician Ayman Nour, underscoring the growing commercial market for mercenary spyware and delayed patching risks such as CVE-2021-1048.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Google's Threat Analysis Group announced that state-backed actors used five zero-day vulnerabilities across Chrome and Android in three 2021 campaigns to install Cytrox's Predator spyware on fully updated Android devices. Google said Cytrox packaged the exploits and sold them to multiple government-backed customers linked to Egypt, Armenia, Greece, Madagascar, Côte d'Ivoire, Serbia, Spain, and Indonesia.
Meta disclosed in December 2021 that it removed about 300 Facebook and Instagram accounts used by Cytrox in compromise campaigns.
Citizen Lab published a report in December 2021 finding Cytrox's Predator spyware on exiled Egyptian politician Ayman Nour's phone, in findings later said to align with Google's investigation.
In October 2021, Google detected a campaign against an up-to-date Samsung phone that chained CVE-2021-38003 and CVE-2021-1048 to escape the sandbox, compromise the system, and inject code into privileged processes.
In September 2021, a second intrusion targeted a fully updated Samsung Galaxy S10 using CVE-2021-37973 and CVE-2021-37976 to escape the Chrome sandbox, followed by privilege escalation and backdoor deployment.
In August 2021, attackers used a phishing link and CVE-2021-38000 to pivot from Chrome to Samsung Internet on a Samsung Galaxy S21, beginning one of the Android exploitation campaigns tied to Cytrox's Predator spyware.
Google said the vulnerability later tracked as CVE-2021-1048 was fixed in the Linux kernel in September 2020, but the fix was not initially marked as a security issue and was not promptly backported to Android.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcethehackernews.com
Open sourceblog.google
Open sourcecitizenlab.ca
Open sourcechromereleases.googleblog.com
Open sourcechromium.googlesource.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.