Hack-for-Hire Espionage Campaign Targeting MENA Civil Society via Predator/Intellexa Mercenary Spyware — Threadlinqs Intelligence
As of 2026-05-30, Hack-for-Hire Espionage Campaign Targeting MENA Civil Society via Predator/Intellexa Mercenary Spyware is a high-severity apt threat attributed to Intellexa Alliance (Multiple (Israel/EU-based vendor; Egypt, Saudi Arabia, Kazakhstan primary MENA operators)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 46 indicators of compromise.
Threat ID: TL-2026-0333 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Intellexa Alliance · Multiple (Israel/EU-based vendor; Egypt, Saudi Arabia, Kazakhstan primary MENA operators) · ESPIONAGE
Active hack-for-hire espionage campaign leveraging Intellexa's Predator mercenary spyware to target journalists, human rights defenders, and government critics across the MENA region and beyond. The
Intellexa Alliance — a consortium of European surveillance companies including Cytrox, Nexa Technologies, WiSpear, and Senpai Technologies, founded by former IDF Unit 81 commander Tal Dilian — operates the Predator commercial spyware platform, which has been deployed against civil society targets across the Middle East and North Africa (MENA) region and globally.
Predator is a sophisticated mobile implant targeting both iOS and Android devices. On iOS, it persists across reboots by abusing the iOS Automations/Shortcuts feature via the siriactionsd process, executing as root-level processes capable of accessing encrypted messaging apps (Signal, WhatsApp), activating microphones and cameras, harvesting credentials, capturing screenshots, recording calls, and exfiltrating GPS coordinates. The spyware employs an intelligent collection strategy that monitors battery level, charger status, and network type to minimize detection through excessive resource consumption.
The campaign utilizes multiple delivery vectors:
1. ONE-CLICK SPEAR PHISHING: Attackers send tailored WhatsApp or SMS messages containing malicious links that redirect through URL shortener infrastructure (e.g., c.betly[.]me) to exploit servers (e.g., sec-flare[.]com). Links are themed with region-specific lures — Egyptian news sites (almasryelyuom[.]com mimicking Al Masry Al Youm), Kazakhstani media (kz-news[.]cc), and Indonesian outlets (kejoranews[.]net). The infection chain triggers browser zero-day exploits and completes within minutes.
2. NETWORK INJECTION (MARS/JUPITER): ISP-level man-in-the-middle attacks using Sandvine PacketLogic middleboxes positioned at telecom boundaries. When targets visit HTTP sites, traffic is intercepted and redirected to exploit infrastructure. This was documented in the Ahmed Eltantawy targeting where a device at the Telecom Egypt/Vodafone Egypt border persistently redirected his mobile traffic to Predator exploit servers.
3. ALADDIN ZERO-CLICK AD DELIVERY: A novel vector developed by 2022 and actively deployed since 2024. Aladdin forces malicious advertisements onto target devices using public IP addresses obtained from domestic mobile operators as targeting identifiers. The advertisement itself triggers infection without user interaction. Infrastructure is operated through shell companies Pulse Advertise and MorningStar TEC.
4. OAUTH CONSENT PHISHING: Documented against Egyptian civil society since 2019, attackers create malicious OAuth applications (e.g., 'Secure Mail') that request account access permissions. This bypasses two-factor authentication because victims authenticate directly through the legitimate service. Targeted accounts included human rights defenders, NGO staff, and media organizations.
Since 2021, Intellexa has burned through 15 unique zero-day exploits across Chrome V8, Safari WebKit, iOS kernel, and Android components. Notable exploit chains include the September 2023 iOS attack on Ahmed Eltantawy using CVE-2023-41991 (certificate validation bypass), CVE-2023-41992 (XNU kernel privilege escalation), and CVE-2023-41993 (WebKit JIT RCE), plus the 2025 chain using CVE-2025-6554 (Chrome V8 type confusion) and CVE-2025-48543 (Android runtime UAF).
The December 2025 Amnesty International 'Intellexa Leaks' investigation exposed internal operations including TeamViewer-based remote access to customer surveillance systems, Elasticsearch logging dashboards, and the PDS/HDS customer dashboard used to add targets and create infection links. Google TAG simultaneously notified hundreds of targeted accounts across Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia, and Tajikistan.
In February 2026, Amnesty confirmed Predator infection on Angolan journalist Teixeira Candido's iPhone, with the May 2024 attack delivered via WhatsApp from a local Angolan number. Access Now's March 2026 webinar documented ongoing spear phishing campaigns against Egyptian journalists and human rights defenders, confirming the cam
Weaknesses (CWE)
CWE-416, CWE-843, CWE-295, CWE-269, CWE-94
Target sectors: civil-society, journalism, human-rights, government-opposition, legal, ngo, media
Target regions: Middle East, North Africa, Sub-Saharan Africa, Central Asia, Southeast Asia, Europe, South Asia
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 46 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2023-41991, CVE-2023-41992, CVE-2023-41993, CVE-2023-4762, CVE-2023-3079, CVE-2023-2136, CVE-2023-2033, CVE-2021-38003, CVE-2021-38000, CVE-2021-37976, T1589, T1583, T1583, T1587, T1588, T1566, T1189, T1203, T1204, T1547