# Intellexa Consortium

> As of 2026-08-20, Intellexa Consortium is a Israel-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, malware. Also known as Intellexa, Cytrox, Nexa Technologies, Senpai Technologies. ATT&CK coverage spans 58 techniques across 19 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1057 (Process Discovery), T1082 (System Information Discovery).

- **Nation:** Israel
- **Tracked threats:** 3
- **Categories:** THREAT_INTEL, MALWARE
- **Also known as:** Intellexa, Cytrox, Nexa Technologies, Senpai Technologies, Thalestris
- **As of:** 2026-08-20

## ATT&CK techniques observed

58 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (10), Collection (5), Defense Evasion (Mobile) (5), Discovery (5), Resource Development (5), Collection (Mobile) (4).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 2 of 3 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 3 tracked threats
- [T1203](https://intel.threadlinqs.com/technique/T1203) Exploitation for Client Execution — Execution — observed in 2 of 3 tracked threats
- [T1404](https://intel.threadlinqs.com/technique/T1404) Exploitation for Privilege Escalation — Privilege Escalation (Mobile) — observed in 2 of 3 tracked threats
- [T1429](https://intel.threadlinqs.com/technique/T1429) Audio Capture — Collection (Mobile) — observed in 2 of 3 tracked threats
- [T1512](https://intel.threadlinqs.com/technique/T1512) Video Capture — Collection (Mobile) — observed in 2 of 3 tracked threats
- [T1587.001](https://intel.threadlinqs.com/technique/T1587.001) Malware — Resource Development — observed in 2 of 3 tracked threats
- [T1630](https://intel.threadlinqs.com/technique/T1630) Indicator Removal on Host — Defense Evasion (Mobile) — observed in 2 of 3 tracked threats
- [T1014](https://intel.threadlinqs.com/technique/T1014) Rootkit — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1037](https://intel.threadlinqs.com/technique/T1037) Boot or Logon Initialization Scripts — Persistence — observed in 1 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 3 tracked threats

## Tracked threats

- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — HIGH
- [Predator Spyware: Undocumented iOS Kernel Exploitation Engine (FDGuardNeonRW, PAC Bypass, RWTransfer)](https://intel.threadlinqs.com/threat/TL-2026-2046) — HIGH
- [Predator Spyware iOS SpringBoard Hook — Intellexa Recording Indicator Bypass via Kernel-Level Sensor Interception](https://intel.threadlinqs.com/threat/TL-2026-0132) — HIGH

## Related CVEs

2 CVEs referenced by tracked Intellexa Consortium activity.

- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Intellexa%20Consortium
