Hack-for-Hire Espionage Campaign Targeting MENA Civil Society via Predator/Intellexa Mercenary Spyware

Hack-for-Hire Espionage Campaign Targeting MENA Civil (TL-2026-0333), also tracked as Predator Spyware Campaign, is a high-severity advanced persistent threat campaign, first published 2026-04-08. It is attributed to Intellexa Alliance with high confidence, affects Apple iOS, references 15 CVEs (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993), maps to 25 MITRE ATT&CK techniques (T1005, T1036, T1041), and is covered by 9 detection rules and 46 indicators of compromise.

Key facts for TL-2026-0333

Threat ID
TL-2026-0333
Also known as
Predator Spyware Campaign, Intellexa Leaks, Predator Files, Predator in the Wires, Operation Eagle
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-04-08
Last reviewed
2026-04-08
Attribution
Intellexa Alliance
Attribution confidence
HIGH
Motivation
ESPIONAGE
Target sectors
civil-society, journalism, human-rights, government-opposition, legal, ngo, media
Target regions
Middle East, North Africa, Sub-Saharan Africa, Central Asia, Southeast Asia, Europe, South Asia
Detection rules
9
Indicators of compromise
46

Malware and tooling in Hack-for-Hire Espionage Campaign Targeting MENA Civil

Malware and tooling: Predator, Helios Delivery Studio (HDS), Predator Delivery Studio (PDS)

Active hack-for-hire espionage campaign leveraging Intellexa's Predator mercenary spyware to target journalists, human rights defenders, and government critics across the MENA region and beyond. The campaign employs sophisticated spear phishing via encrypted messaging apps, weaponized OAuth consent phishing, network injection via ISP-level MITM devices, and the novel Aladdin zero-click advertising-based delivery system.

How Hack-for-Hire Espionage Campaign Targeting MENA Civil works

Intellexa Alliance — a consortium of European surveillance companies including Cytrox, Nexa Technologies, WiSpear, and Senpai Technologies, founded by former IDF Unit 81 commander Tal Dilian — operates the Predator commercial spyware platform, which has been deployed against civil society targets across the Middle East and North Africa (MENA) region and globally.

Predator is a sophisticated mobile implant targeting both iOS and Android devices. On iOS, it persists across reboots by abusing the iOS Automations/Shortcuts feature via the siriactionsd process, executing as root-level processes capable of accessing encrypted messaging apps (Signal, WhatsApp), activating microphones and cameras, harvesting credentials, capturing screenshots, recording calls, and exfiltrating GPS coordinates. The spyware employs an intelligent collection strategy that monitors battery level, charger status, and network type to minimize detection through excessive resource consumption.

The campaign utilizes multiple delivery vectors:

1. ONE-CLICK SPEAR PHISHING: Attackers send tailored WhatsApp or SMS messages containing malicious links that redirect through URL shortener infrastructure (e.g., c.betly[.]me) to exploit servers (e.g., sec-flare[.]com). Links are themed with region-specific lures — Egyptian news sites (almasryelyuom[.]com mimicking Al Masry Al Youm), Kazakhstani media (kz-news[.]cc), and Indonesian outlets (kejoranews[.]net). The infection chain triggers browser zero-day exploits and completes within minutes.

2. NETWORK INJECTION (MARS/JUPITER): ISP-level man-in-the-middle attacks using Sandvine PacketLogic middleboxes positioned at telecom boundaries. When targets visit HTTP sites, traffic is intercepted and redirected to exploit infrastructure. This was documented in the Ahmed Eltantawy targeting where a device at the Telecom Egypt/Vodafone Egypt border persistently redirected his mobile traffic to Predator exploit servers.

3. ALADDIN ZERO-CLICK AD DELIVERY: A novel vector developed by 2022 and actively deployed since 2024. Aladdin forces malicious advertisements onto target devices using public IP addresses obtained from domestic mobile operators as targeting identifiers. The advertisement itself triggers infection without user interaction. Infrastructure is operated through shell companies Pulse Advertise and MorningStar TEC.

4. OAUTH CONSENT PHISHING: Documented against Egyptian civil society since 2019, attackers create malicious OAuth applications (e.g., 'Secure Mail') that request account access permissions. This bypasses two-factor authentication because victims authenticate directly through the legitimate service. Targeted accounts included human rights defenders, NGO staff, and media organizations.

Since 2021, Intellexa has burned through 15 unique zero-day exploits across Chrome V8, Safari WebKit, iOS kernel, and Android components. Notable exploit chains include the September 2023 iOS attack on Ahmed Eltantawy using CVE-2023-41991 (certificate validation bypass), CVE-2023-41992 (XNU kernel privilege escalation), and CVE-2023-41993 (WebKit JIT RCE), plus the 2025 chain using CVE-2025-6554 (Chrome V8 type confusion) and CVE-2025-48543 (Android runtime UAF).

The December 2025 Amnesty International 'Intellexa Leaks' investigation exposed internal operations including TeamViewer-based remote access to customer surveillance systems, Elasticsearch logging dashboards, and the PDS/HDS customer dashboard used to add targets and create infection links. Google TAG simultaneously notified hundreds of targeted accounts across Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia, and Tajikistan.

In February 2026, Amnesty confirmed Predator infection on Angolan journalist Teixeira Candido's iPhone, with the May 2024 attack delivered via WhatsApp from a local Angolan number. Access Now's March 2026 webinar documented ongoing spear phishing campaigns against Egyptian journalists and human rights defenders, confirming the campaign remains active despite US OFAC sanctions imposed on Intellexa in 2023.

Confirmed Predator customer nations include Egypt, Greece, Armenia, Indonesia, Madagascar, Oman, Saudi Arabia, Serbia, Kazakhstan, Angola, Democratic Republic of Congo, Pakistan, Mongolia, Sudan, and Botswana. Internal customer codenames include Dragon, Eagle, Falcon, Flamingo, Fox, Glen, Lion, Loco, Phoenix, Rhino, and Demo_Master.

MITRE ATT&CK techniques used in TL-2026-0333

collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection; T1123 Audio Capture; T1125 Video Capture

defense-evasion

T1036 Masquerading; T1070 Indicator Removal

exfiltration

T1041 Exfiltration Over C2 Channel

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071 Application Layer Protocol; T1090 Proxy

discovery

T1082 System Information Discovery

initial-access

T1189 Drive-by Compromise; T1566 Phishing

execution

T1203 Exploitation for Client Execution; T1204 User Execution

credential-access

T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle

persistence

T1547 Boot or Logon Autostart Execution

defense-impairment

T1553 Subvert Trust Controls

resource-development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Hack-for-Hire Espionage Campaign Targeting MENA Civil

  • Apple — iOS
    Vulnerable versions: 14.x; 15.x; 16.x (before 16.7); 17.x (before 17.0.1)
    Fixed in: 16.7+; 17.0.1+
  • Google — Chrome
    Vulnerable versions: All versions before 138.0.7204.96
    Fixed in: 138.0.7204.96+
  • Google — Android
    Vulnerable versions: Multiple versions with unpatched kernel
    Fixed in: Latest security patch level
  • ARM — Mali GPU Driver (Bifrost/Valhall)
    Vulnerable versions: Before r41p0 (Bifrost), r44p1 (Valhall)
    Fixed in: r41p0+; r44p1+
  • Samsung — Exynos Baseband
    Vulnerable versions: Devices with Exynos chipsets susceptible to Triton 2G downgrade
    Fixed in: Unknown

Remediation for Hack-for-Hire Espionage Campaign Targeting MENA Civil

Patches

  • Update all iOS devices to latest version (patches CVE-2023-41991, CVE-2023-41992, CVE-2023-41993)
  • Update Chrome browser to 138.0.7204.96+ (patches CVE-2025-6554)
  • Update Android devices to latest security patch level (patches CVE-2025-48543, CVE-2021-1048)
  • Update ARM Mali GPU drivers (patches CVE-2024-4610)

Immediate actions

  • Deploy Mobile Threat Defense (MTD) solutions on all executive and high-risk user devices
  • Enable Apple Lockdown Mode on all iOS devices for at-risk personnel
  • Block known Predator C2 domains and IPs at perimeter firewalls and DNS resolvers
  • Audit all authorized OAuth/third-party app connections on Google Workspace and Microsoft 365 accounts
  • Revoke any unrecognized third-party application permissions immediately
  • Force HTTPS-only browsing to prevent network injection attacks

Workarounds

  • Use VPN on all mobile connections to prevent ISP-level network injection
  • Avoid clicking links in WhatsApp/SMS from unknown numbers or unexpected contacts
  • Regularly restart iOS devices to clear non-persistent Predator implants
  • Disable JavaScript in mobile browsers when visiting untrusted sites
  • Use Amnesty International MVT toolkit for self-assessment forensic checks

Longer-term hardening

  • Enroll high-risk users in Google Advanced Protection Program to prevent OAuth phishing
  • Deploy certificate transparency monitoring for organizational domains
  • Implement network traffic analysis to detect anomalous redirects indicative of MITM injection
  • Establish regular forensic analysis cadence for high-risk devices using MVT (Mobile Verification Toolkit)
  • Train civil society staff on spear phishing recognition in encrypted messaging apps
  • Implement hardware security keys for all authentication to defeat OAuth phishing

CVEs associated with Hack-for-Hire Espionage Campaign Targeting MENA Civil

Weaknesses (CWE) in Hack-for-Hire Espionage Campaign Targeting MENA Civil

CWE-416, CWE-843, CWE-295, CWE-269, CWE-94

Timeline of Hack-for-Hire Espionage Campaign Targeting MENA Civil

  • Cytrox founded as a North Macedonian startup, beginning development of Predator spyware
  • Amnesty International exposes OAuth consent phishing campaign against Egyptian civil society organizations using fake 'Secure Mail' application
  • Citizen Lab discovers Predator spyware on iPhone of Egyptian opposition politician Ayman Nour, running simultaneously with NSO Pegasus
  • Citizen Lab publishes 'Pegasus vs Predator' report, first public documentation of Cytrox Predator spyware and Intellexa alliance
  • US Treasury OFAC sanctions Intellexa consortium entities and Tal Dilian for proliferation of commercial spyware
  • Citizen Lab and Google TAG reveal Egyptian opposition candidate Ahmed Eltantawy targeted with Predator via Sandvine PacketLogic MITM network injection and three iOS zero-days
  • Amnesty International publishes 'Predator Files' investigation exposing brazen targeting of civil society, politicians, and officials across multiple countries
  • Sekoia TDR discovers new Predator C2 infrastructure in Angola, Madagascar, Indonesia, Kazakhstan, and Egypt built after October 2023 exposure
  • Angolan journalist Teixeira Candido's iPhone infected with Predator via WhatsApp-delivered malicious link from local Angolan number
  • Recorded Future Insikt Group reports Predator infrastructure resurfacing with additional anonymization tier in multi-tiered delivery system, active in DRC and Angola
  • Google TAG delivers government-backed attack warnings to hundreds of targeted accounts across Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia, and Tajikistan
  • Amnesty International Security Lab publishes 'Intellexa Leaks' exposing internal operations, TeamViewer remote access to customer systems, Aladdin ad-based delivery, and 15 zero-days burned since 2021
  • Amnesty International confirms Predator infection on Angolan journalist iPhone, documents 11 re-infection attempts and forensic artifacts
  • Access Now documents ongoing spear phishing campaigns against Egyptian journalists and human rights defenders, confirming active exploitation continues despite sanctions
  • As of 2026-05-29, the Intellexa/Predator mercenary spyware campaign remains actively operational despite OFAC sanctions, with Amnesty confirming a Feb 2026 iPhone infection of an Angolan journalist and Recorded Future tracking Predator activity across 12+ countries. The actor keeps burning fresh zero-days and runs the actively-developed Aladdin zero-click ad delivery, so it stays a live threat.

Sources cited for Hack-for-Hire Espionage Campaign Targeting MENA Civil

Threats related to Hack-for-Hire Espionage Campaign Targeting MENA Civil

Detection coverage for TL-2026-0333

As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0333 across Splunk SPL, Microsoft KQL and Sigma, covering 46 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats