Threadlinqs IntelligenceStart free

Threat actorIsraelTracked since 2026-02

Intellexa Consortium

Also known as:IntellexaCytroxNexa TechnologiesSenpai TechnologiesThalestris

As of 2026-08-20, Intellexa Consortium is a Israel-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware. Also known as Intellexa, Cytrox, Nexa Technologies, Senpai Technologies. ATT&CK coverage spans 58 techniques across 19 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1057 (Process Discovery), T1082 (System Information Discovery).

Tracked threats
33 high
First seen
2026-02-22
Last seen
2026-08-14
ATT&CK techniques
58across 3 of 3 threats
Related CVEs
2Referenced by its activity
Attribution
IsraelNation or origin
Nation: Israel · 3 tracked threat(s) · Categories: THREAT_INTEL, MALWARE

Activity timeline

Intellexa Consortium appears in 3 tracked threats between and ; the busiest month was 2026-02 with 1 report.

ATT&CK techniques observed

58 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (10), Collection (5), Defense Evasion (Mobile) (5), Discovery (5), Resource Development (5), Collection (Mobile) (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1113 Screen Capture — Collectionobserved in 2 of 3 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 3 tracked threats
  • T1203 Exploitation for Client Execution — Executionobserved in 2 of 3 tracked threats
  • T1404 Exploitation for Privilege Escalation — Privilege Escalation (Mobile)observed in 2 of 3 tracked threats
  • T1429 Audio Capture — Collection (Mobile)observed in 2 of 3 tracked threats
  • T1512 Video Capture — Collection (Mobile)observed in 2 of 3 tracked threats
  • T1587.001 Malware — Resource Developmentobserved in 2 of 3 tracked threats
  • T1630 Indicator Removal on Host — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
  • T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 3 tracked threats
  • T1037 Boot or Logon Initialization Scripts — Persistenceobserved in 1 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 1 of 3 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked Intellexa Consortium activity