#Predator #spyware kan skjule kamera- og mikrofon-indikatorer på en iPhones skærm for at muliggøre lydløs optagelse

I modsætning til tidligere open source-exploits, der opnåede det samme resultat, kan Predator deaktivere indikatorerne, mens resten af skærmens brugergrænseflade forbliver aktiv

Spywaren er udviklet af et firma kaldet #Intellexa tidligere #Cytrox
https://www.jamf.com/blog/predator-spyware-ios-recording-indicator-bypass-analysis/

How Predator Spyware Defeats iOS Recording Indicators

An analysis documenting how a commercial spyware sample, Predator, operates post-compromise.

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits

Predator spyware's has advanced anti-forensics and anti-detection capabilities, and can learn from its own failures.

SecurityWeek
Everyone is a Target: Targeted Mercenary Spyware & the Rise of Commercial Surveillance

From Pegasus to Paragon, inside the privatized surveillance networks reshaping power, privacy, and control in the 21st century.

Stephano Pereira

Since 2020 in #Greece, the national intelligence agency #EYP has been implicated in using Israeli-made " #Cytrox #Predator " #spyware to target journalists, opposition and activists (having full access to its WhatsApp etc). This scandal led to significant resignations:

* Panagiotis Kontoleon, the head of Greek agency EYP, stepped down in August 2022.
* G. Voulgarakis, a senior aide to Prime Minister Kyriakos Mitsotakis, also resigned.

more in english: https://www.dnews.gr/eidhseis/news-in-english/522954/predator-spyware-intellexa-and-the-greek-surveillance-scandal-head-back-to-courtabout

#privacy

Predator Spyware, Intellexa, and the Greek Surveillance Scandal Head Back to Court - Dnews

The trial over the illegal use of Predator spyware in Greece, one of the country’s most significant surveillance scandals in recent history, is set to resume on April 23 at the Athens Single-Member Misdemeanor Court.

Dnews
Predators for Hire: A Global Overview of Commercial Surveillance Vendors

Explore the 2025 landscape of Adversary-in-the-Middle phishing threats with data, trends, and top detection insights.

Sekoia.io Blog
US sanctions Predator spyware makers for targeting gov’t officials

The U.S. government announced sanctions on Tuesday against two people and five entities tied to Predator spyware, just days after the company behind the tool took down infrastructure in response to new research about its operations.

Intellexa and Cytrox: From fixer-upper to Intel Agency-grade spyware - By Mike Gentile, Asheer Malhotra and Vitor Ventura.Editor’s note: This blog post i... https://blog.talosintelligence.com/intellexa-and-cytrox-intel-agency-grade-spyware/ #threatspotlight #mercenaryapt #intellexa #topstory #features #cytrox #psoa #apt
Intellexa and Cytrox: From fixer-upper to Intel Agency-grade spyware

Talos revealed that rebooting an iOS or Android device may not remove the Predator spyware produced by Intellexa. Intellexa knows if their customers intend to perform surveillance operations on foreign soil.

Cisco Talos Blog

Would-be president pwned by President: #AhmedTantawy had phone hacked; #CitizenLab says Egyptian govt did it.

Fingered: @VodafoneEgypt, @Sandvine and #Cytrox itself. In today’s #SBBlogwatch, we rethink seeing pyramids. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/09/ios-zero-cytrox-predator-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc

More iOS Zero Days, More Mercenary Spyware — This Time: Cytrox Predator

Apple Scrambled to Fix 3 More CVEs: Egyptian opposition presidential candidate Ahmed Eltantawy targeted “by the government.

Security Boulevard

#Cybersecurity #Egypt #Spyware #Predator #Cytrox: "- Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox’s Predator spyware via links sent on SMS and WhatsApp. The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections.

- In August and September 2023, Eltantawy’s Vodafone Egypt mobile connection was persistently selected for targeting via network injection; when Eltantawy visited certain websites not using HTTPS, a device installed at the border of Vodafone Egypt’s network automatically redirected him to a malicious website to infect his phone with Cytrox’s Predator spyware.

- During our investigation, we worked with Google’s Threat Analysis Group (TAG) to obtain an iPhone zero-day exploit chain (CVE-2023-41991, CVE-2023-41992, CVE-2023-41993) designed to install Predator on iOS versions through 16.6.1. We also obtained the first stage of the spyware, which has notable similarities to a sample of Cytrox’s Predator spyware we obtained in 2021. We attribute the spyware to Cytrox’s Predator spyware with high confidence.

- Given that Egypt is a known customer of Cytrox’s Predator spyware, and the spyware was delivered via network injection from a device located physically inside Egypt, we attribute the network injection attack to the Egyptian government with high confidence.

- Eltantawy’s phone was additionally infected with Cytrox’s Predator spyware two years prior, in November 2021, via a text message containing a link to a Predator website."

https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/

PREDATOR IN THE WIRES: Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions - The Citizen Lab

Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox's Predator spyware via links sent on SMS and WhatsApp after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections. As Egypt is a known customer of Cytrox's Predator spyware, and the spyware was delivered via network injection from a device located physically inside Egypt, we attribute the attack to the Egyptian government with high confidence.

The Citizen Lab
US government adds two more #spyware makers to denylist
The U.S. government put #Intellexa and #Cytrox, two European spyware makers, on an economic denylist. The addition of the two companies, based in Greece and Hungary, as well as two related entities in Ireland and North Macedonia, is part of a wider effort from the Biden administration against makers of malware that is sold exclusively to #lawenforcement and intelligence agencies.
https://techcrunch.com/2023/07/18/us-government-adds-two-more-spyware-makers-on-deny-list/ #surveillance #privacy #NSOGroup
TechCrunch is part of the Yahoo family of brands