CyberSecurity news

FlagThis

Cynthia B@Metacurity //
Despite US sanctions, Intellexa's Predator spyware continues to operate, adapting to setbacks and surfacing in new locations with innovative techniques to evade detection. Security firm Recorded Future revealed they had linked Intellexa infrastructure to new locations. Their findings suggest Intellexa, also known as the Intellexa Consortium, is actively responding to the challenges posed by sanctions and public exposure and is likely to continue adapting its methods. This highlights the ongoing struggle to effectively curb the proliferation of sophisticated surveillance tools.

Recorded Future's Insikt Group has identified a previously unknown customer in Mozambique, a connection to a Czech entity, and activity linked to an Eastern European country. The Eastern European activity, though brief, suggests possible development or testing of the spyware. The discovery of the Mozambique customer is consistent with the already known high level of Predator activity across Africa. Intellexa has also adopted strategies such as using fake websites, including counterfeit login pages and sites claiming association with conferences, to mask its operations.

Julian-Ferdinand Vögele, a threat researcher with Recorded Future, stated that “Intellexa’s Predator remains active and adaptive, relying on a vast network of vendors, subsidiaries, and other companies.” While Predator activity has declined since sanctions and public exposure, the spyware maker is still finding ways to keep the spyware active and available to customers. The report from Recorded Future warns that "Sanctions and other pressures are likely to drive efforts to increase the complexity of corporate structures, making operations harder to trace and disrupt," emphasizing the importance of continued vigilance and proactive measures to counter the evolving threat posed by Predator.
Original img attribution: https://www.metacurity.com/content/images/2025/06/predatorspyare.png
ImgSrc: www.metacurity.

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • Risky.Biz: Risky Bulletin: Predator spyware alive despite US sanctions
  • Metacurity: Customers keep buying Predator spyware despite US sanctions
  • Risky Business Media: Risky Bulletin: Predator spyware alive despite US sanctions
  • cyberscoop.com: Predator spyware activity surfaces in new places with new tricks
Classification:
  • HashTags: #spyware #sanctions #surveillance
  • Company: Intellexa
  • Attacker: Intellexa
  • Product: Predator
  • Feature: Continued Operation
  • Malware: Predator
  • Type: Spyware
  • Severity: Major