Leaks show Intellexa burning zero-days to keep Predator spyware running


Intellexa is a well-known commercial spyware vendor, servicing governments and large corporations. Its main product is the Predator spyware.

An investigation by several independent parties describes Intellexa as one of the most notorious mercenary spyware vendors, still operating its Predator platform and hitting new targets even after being placed on US sanctions lists and being under active investigation in Greece. The investigation draws on highly sensitive documents and other materials leaked from the company, including internal records, sales and marketing material, and training videos.

Read more…
Source: Malwarebytes Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Google Warns of Android Zero-Day Bug Under Active Attack

    October 4, 2019

    Google is warning of an Android zero-day flaw actively being exploited in the wild, which gives an attacker full control over 18 phone models including its flagship Pixel handset and devices made by Samsung, Huawei and Xiaomi. Google’s Project Zero warned late Thursday that it suspected the vulnerability was being exploited by the controversial Israeli-based NSO ...

  • Masad Spyware Uses Telegram Bots for Command-and-Control

    September 27, 2019

    A freshly discovered commercial spyware dubbed the “Masad Clipper and Stealer” is using Telegram bots as its command-and-control (C2) hub. Masad harvests information from Windows and Android users and also comes with a full cadre of other malicious capabilities, including the ability to steal cryptocurrency from victims’ wallets. According to an analysis from Juniper Threat Labs on ...

  • Poland pressured to say if it bought Israeli phone spyware

    September 4, 2019

    The Polish government is coming under pressure to clarify whether it has purchased sophisticated and potentially illegal phone surveillance technology that has been used to stifle dissent in other countries. Opposition lawmakers asked Prime Minister Mateusz Morawiecki whether the special services bought Pegasus, the spyware produced by NSO Group, an Israeli company. Morawiecki appeared to sidestep the ...

  • Unique Monokle Android Spyware Self-Signs Certificates

    July 24, 2019

    A never-before-publicized mobile spy tool, a mobile surveillanceware remote access trojan (RAT) for Android called Monokle, has been spotted using novel techniques to exfiltrate data. According to the Lookout researchers who discovered Monokle in the wild, the malware has the ability to self-sign trusted certificates to intercept encrypted SSL traffic. It can also record a phone’s ...

  • Android spyware campaign spreads across the Middle East

    June 27, 2019

    A new campaign has been spotted making its way across the Middle East in an effort to steal device and communications data belonging to Android users. According to new research published by Kaspersky on Wednesday, the campaign — dubbed ViceLeaker — has been active since May 2018. “Dozens” of Android devices belonging to Israeli citizens were targeted in the ...

  • Western intelligence hacked ‘Russia’s Google’ Yandex to spy on accounts

    June 27, 2019

    Hackers working for Western intelligence agencies broke into Russian internet search company Yandex in late 2018, deploying a rare type of malware in an attempt to spy on user accounts, four people with knowledge of the matter told Reuters. The malware, called Regin, is known to be used by the “Five Eyes” intelligence-sharing alliance of the ...