Hack-for-Hire Espionage Campaign Targeting MENA Civil Society via Predator/Intellexa Mercenary Spyware
Hack-for-Hire Espionage Campaign Targeting MENA Civil (TL-2026-0333), also tracked as Predator Spyware Campaign, is a high-severity advanced persistent threat campaign, first published 2026-04-08. It is attributed to Intellexa Alliance with high confidence, affects Apple iOS, references 15 CVEs (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993), maps to 25 MITRE ATT&CK techniques (T1005, T1036, T1041), and is covered by 9 detection rules and 46 indicators of compromise.
Key facts for TL-2026-0333
- Threat ID
- TL-2026-0333
- Also known as
- Predator Spyware Campaign, Intellexa Leaks, Predator Files, Predator in the Wires, Operation Eagle
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-04-08
- Last reviewed
- 2026-04-08
- Attribution
- Intellexa Alliance
- Attribution confidence
- HIGH
- Motivation
- ESPIONAGE
- Target sectors
- civil-society, journalism, human-rights, government-opposition, legal, ngo, media
- Target regions
- Middle East, North Africa, Sub-Saharan Africa, Central Asia, Southeast Asia, Europe, South Asia
- Detection rules
- 9
- Indicators of compromise
- 46
Malware and tooling in Hack-for-Hire Espionage Campaign Targeting MENA Civil
Malware and tooling: Predator, Helios Delivery Studio (HDS), Predator Delivery Studio (PDS)
Active hack-for-hire espionage campaign leveraging Intellexa's Predator mercenary spyware to target journalists, human rights defenders, and government critics across the MENA region and beyond. The campaign employs sophisticated spear phishing via encrypted messaging apps, weaponized OAuth consent phishing, network injection via ISP-level MITM devices, and the novel Aladdin zero-click advertising-based delivery system.
How Hack-for-Hire Espionage Campaign Targeting MENA Civil works
Intellexa Alliance — a consortium of European surveillance companies including Cytrox, Nexa Technologies, WiSpear, and Senpai Technologies, founded by former IDF Unit 81 commander Tal Dilian — operates the Predator commercial spyware platform, which has been deployed against civil society targets across the Middle East and North Africa (MENA) region and globally.
Predator is a sophisticated mobile implant targeting both iOS and Android devices. On iOS, it persists across reboots by abusing the iOS Automations/Shortcuts feature via the siriactionsd process, executing as root-level processes capable of accessing encrypted messaging apps (Signal, WhatsApp), activating microphones and cameras, harvesting credentials, capturing screenshots, recording calls, and exfiltrating GPS coordinates. The spyware employs an intelligent collection strategy that monitors battery level, charger status, and network type to minimize detection through excessive resource consumption.
The campaign utilizes multiple delivery vectors:
1. ONE-CLICK SPEAR PHISHING: Attackers send tailored WhatsApp or SMS messages containing malicious links that redirect through URL shortener infrastructure (e.g., c.betly[.]me) to exploit servers (e.g., sec-flare[.]com). Links are themed with region-specific lures — Egyptian news sites (almasryelyuom[.]com mimicking Al Masry Al Youm), Kazakhstani media (kz-news[.]cc), and Indonesian outlets (kejoranews[.]net). The infection chain triggers browser zero-day exploits and completes within minutes.
2. NETWORK INJECTION (MARS/JUPITER): ISP-level man-in-the-middle attacks using Sandvine PacketLogic middleboxes positioned at telecom boundaries. When targets visit HTTP sites, traffic is intercepted and redirected to exploit infrastructure. This was documented in the Ahmed Eltantawy targeting where a device at the Telecom Egypt/Vodafone Egypt border persistently redirected his mobile traffic to Predator exploit servers.
3. ALADDIN ZERO-CLICK AD DELIVERY: A novel vector developed by 2022 and actively deployed since 2024. Aladdin forces malicious advertisements onto target devices using public IP addresses obtained from domestic mobile operators as targeting identifiers. The advertisement itself triggers infection without user interaction. Infrastructure is operated through shell companies Pulse Advertise and MorningStar TEC.
4. OAUTH CONSENT PHISHING: Documented against Egyptian civil society since 2019, attackers create malicious OAuth applications (e.g., 'Secure Mail') that request account access permissions. This bypasses two-factor authentication because victims authenticate directly through the legitimate service. Targeted accounts included human rights defenders, NGO staff, and media organizations.
Since 2021, Intellexa has burned through 15 unique zero-day exploits across Chrome V8, Safari WebKit, iOS kernel, and Android components. Notable exploit chains include the September 2023 iOS attack on Ahmed Eltantawy using CVE-2023-41991 (certificate validation bypass), CVE-2023-41992 (XNU kernel privilege escalation), and CVE-2023-41993 (WebKit JIT RCE), plus the 2025 chain using CVE-2025-6554 (Chrome V8 type confusion) and CVE-2025-48543 (Android runtime UAF).
The December 2025 Amnesty International 'Intellexa Leaks' investigation exposed internal operations including TeamViewer-based remote access to customer surveillance systems, Elasticsearch logging dashboards, and the PDS/HDS customer dashboard used to add targets and create infection links. Google TAG simultaneously notified hundreds of targeted accounts across Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia, and Tajikistan.
In February 2026, Amnesty confirmed Predator infection on Angolan journalist Teixeira Candido's iPhone, with the May 2024 attack delivered via WhatsApp from a local Angolan number. Access Now's March 2026 webinar documented ongoing spear phishing campaigns against Egyptian journalists and human rights defenders, confirming the campaign remains active despite US OFAC sanctions imposed on Intellexa in 2023.
Confirmed Predator customer nations include Egypt, Greece, Armenia, Indonesia, Madagascar, Oman, Saudi Arabia, Serbia, Kazakhstan, Angola, Democratic Republic of Congo, Pakistan, Mongolia, Sudan, and Botswana. Internal customer codenames include Dragon, Eagle, Falcon, Flamingo, Fox, Glen, Lion, Loco, Phoenix, Rhino, and Demo_Master.
MITRE ATT&CK techniques used in TL-2026-0333
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection; T1123 Audio Capture; T1125 Video Capture
defense-evasion
T1036 Masquerading; T1070 Indicator Removal
exfiltration
T1041 Exfiltration Over C2 Channel
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1090 Proxy
discovery
T1082 System Information Discovery
initial-access
T1189 Drive-by Compromise; T1566 Phishing
execution
T1203 Exploitation for Client Execution; T1204 User Execution
credential-access
T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle
persistence
T1547 Boot or Logon Autostart Execution
defense-impairment
resource-development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
reconnaissance
Affected products and versions in Hack-for-Hire Espionage Campaign Targeting MENA Civil
- Apple — iOS
Vulnerable versions: 14.x; 15.x; 16.x (before 16.7); 17.x (before 17.0.1)
Fixed in: 16.7+; 17.0.1+ - Google — Chrome
Vulnerable versions: All versions before 138.0.7204.96
Fixed in: 138.0.7204.96+ - Google — Android
Vulnerable versions: Multiple versions with unpatched kernel
Fixed in: Latest security patch level - ARM — Mali GPU Driver (Bifrost/Valhall)
Vulnerable versions: Before r41p0 (Bifrost), r44p1 (Valhall)
Fixed in: r41p0+; r44p1+ - Samsung — Exynos Baseband
Vulnerable versions: Devices with Exynos chipsets susceptible to Triton 2G downgrade
Fixed in: Unknown
Remediation for Hack-for-Hire Espionage Campaign Targeting MENA Civil
Patches
- Update all iOS devices to latest version (patches CVE-2023-41991, CVE-2023-41992, CVE-2023-41993)
- Update Chrome browser to 138.0.7204.96+ (patches CVE-2025-6554)
- Update Android devices to latest security patch level (patches CVE-2025-48543, CVE-2021-1048)
- Update ARM Mali GPU drivers (patches CVE-2024-4610)
Immediate actions
- Deploy Mobile Threat Defense (MTD) solutions on all executive and high-risk user devices
- Enable Apple Lockdown Mode on all iOS devices for at-risk personnel
- Block known Predator C2 domains and IPs at perimeter firewalls and DNS resolvers
- Audit all authorized OAuth/third-party app connections on Google Workspace and Microsoft 365 accounts
- Revoke any unrecognized third-party application permissions immediately
- Force HTTPS-only browsing to prevent network injection attacks
Workarounds
- Use VPN on all mobile connections to prevent ISP-level network injection
- Avoid clicking links in WhatsApp/SMS from unknown numbers or unexpected contacts
- Regularly restart iOS devices to clear non-persistent Predator implants
- Disable JavaScript in mobile browsers when visiting untrusted sites
- Use Amnesty International MVT toolkit for self-assessment forensic checks
Longer-term hardening
- Enroll high-risk users in Google Advanced Protection Program to prevent OAuth phishing
- Deploy certificate transparency monitoring for organizational domains
- Implement network traffic analysis to detect anomalous redirects indicative of MITM injection
- Establish regular forensic analysis cadence for high-risk devices using MVT (Mobile Verification Toolkit)
- Train civil society staff on spear phishing recognition in encrypted messaging apps
- Implement hardware security keys for all authentication to defeat OAuth phishing
CVEs associated with Hack-for-Hire Espionage Campaign Targeting MENA Civil
Weaknesses (CWE) in Hack-for-Hire Espionage Campaign Targeting MENA Civil
CWE-416, CWE-843, CWE-295, CWE-269, CWE-94
Timeline of Hack-for-Hire Espionage Campaign Targeting MENA Civil
- Cytrox founded as a North Macedonian startup, beginning development of Predator spyware
- Amnesty International exposes OAuth consent phishing campaign against Egyptian civil society organizations using fake 'Secure Mail' application
- Citizen Lab discovers Predator spyware on iPhone of Egyptian opposition politician Ayman Nour, running simultaneously with NSO Pegasus
- Citizen Lab publishes 'Pegasus vs Predator' report, first public documentation of Cytrox Predator spyware and Intellexa alliance
- US Treasury OFAC sanctions Intellexa consortium entities and Tal Dilian for proliferation of commercial spyware
- Citizen Lab and Google TAG reveal Egyptian opposition candidate Ahmed Eltantawy targeted with Predator via Sandvine PacketLogic MITM network injection and three iOS zero-days
- Amnesty International publishes 'Predator Files' investigation exposing brazen targeting of civil society, politicians, and officials across multiple countries
- Sekoia TDR discovers new Predator C2 infrastructure in Angola, Madagascar, Indonesia, Kazakhstan, and Egypt built after October 2023 exposure
- Angolan journalist Teixeira Candido's iPhone infected with Predator via WhatsApp-delivered malicious link from local Angolan number
- Recorded Future Insikt Group reports Predator infrastructure resurfacing with additional anonymization tier in multi-tiered delivery system, active in DRC and Angola
- Google TAG delivers government-backed attack warnings to hundreds of targeted accounts across Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia, and Tajikistan
- Amnesty International Security Lab publishes 'Intellexa Leaks' exposing internal operations, TeamViewer remote access to customer systems, Aladdin ad-based delivery, and 15 zero-days burned since 2021
- Amnesty International confirms Predator infection on Angolan journalist iPhone, documents 11 re-infection attempts and forensic artifacts
- Access Now documents ongoing spear phishing campaigns against Egyptian journalists and human rights defenders, confirming active exploitation continues despite sanctions
- As of 2026-05-29, the Intellexa/Predator mercenary spyware campaign remains actively operational despite OFAC sanctions, with Amnesty confirming a Feb 2026 iPhone infection of an Angolan journalist and Recorded Future tracking Predator activity across 12+ countries. The actor keeps burning fresh zero-days and runs the actively-developed Aladdin zero-click ad delivery, so it stays a live threat.
Sources cited for Hack-for-Hire Espionage Campaign Targeting MENA Civil
- Intellexa Leaks Expose Predator Spyware Operations - Amnesty International Security Lab
- Amnesty Finds Predator Spyware on Angolan Journalist iPhone
- Access Now Digital Security Webinar - Spear Phishing Against Civil Society
- Predator vs Pegasus - Citizen Lab Initial Discovery
- Predator in the Wires - Ahmed Eltantawy Targeted - Citizen Lab
- 0-days Exploited by Commercial Surveillance Vendor in Egypt - Google TAG
- Intellexa Zero-Day Exploits Continue - Google Cloud Threat Intelligence
- The Predator Spyware Ecosystem Is Not Dead - Sekoia TDR
- Predator Spyware Infrastructure Returns Following Sanctions - Recorded Future
- Predators for Hire - Global Overview of Commercial Surveillance Vendors - Sekoia
- CyberScoop - Intellexa Remotely Accessed Customer Systems
- Phishing Attacks Using Third-Party Applications Against Egyptian Civil Society - Amnesty
- Predator Files Spyware Scandal - Amnesty International
- Intellexa Predator Used to Hack Angolan Journalist iPhone - TechCrunch
Threats related to Hack-for-Hire Espionage Campaign Targeting MENA Civil
- Coruna iOS Exploit Kit — 23 Exploits Across 5 Chains Targeting iOS 13-17.2.1 (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 + 20 More)
- Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader Persistence (CVE-2026-22104, CVE-2026-22107, CVE-2026-22112)
- Pegasus Spyware Re-Targets EU Parliamentarian: Stelios Kouloglou Hacked via PWNYOURHOME Zero-Click Chain While Investigating Spyware Abuse on PEGA Committee
Detection coverage for TL-2026-0333
As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0333 across Splunk SPL, Microsoft KQL and Sigma, covering 46 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.