6 March 2024

US sanctions Predator spyware vendor for targeting officials and journalists


US sanctions Predator spyware vendor for targeting officials and journalists

The US authorities slapped sanctions on two individuals and five entities associated with the Intellexa Consortium for their role in developing, operating, and distributing commercial spyware used to target government officials, journalists, and policy experts.

The Department of the Treasury’s Office of Foreign Assets Control (OFAC) said in a statement that the Intellexa Alliance, which includes several companies such as Nexa Technologies, WiSpear/Passitora, Senpai and the Predator spyware developer Cytrox, has served as a marketing entity for numerous offensive cyber firms specializing in commercial spyware and surveillance solutions.

Predator is a suite of software designed for targeted and mass surveillance operations. Utilizing zero-click attacks, the Predator spyware can infiltrate a wide array of electronic devices without requiring any user interaction. Once installed, the spyware grants unauthorized access to sensitive data, enables geolocation tracking, and provides access to various applications and personal information stored on the compromised device.

The US sanctions targeted five companies in the Intellexa consortium, as well as the company’s founder, Tal Jonathan Dilian (Dilian), and one of the group’s top managers, Sara Aleksandra Fayssal Hamou (Hamou), who were sanctioned as individuals. The sanctioned companies are Greece-based Intellexa S.A., Ireland-based Intellexa Limited, North Macedonia-based Cytrox AD, Hungary-based Cytrox Holdings Zartkoruen Mukodo Reszvenytarsasag (Cytrox Holdings ZRT), and Ireland-based Thalestris Limited.

In July 2023, the US State Department added Cytrox and Intellexa to an economic blocklist for engaging in activities contrary to the national security or foreign policy interests of the United States. In early February, the US announced visa restrictions for individuals involved in the misuse of commercial spyware.

Back to the list

Latest Posts

Cyber Security Week in Review: July 26, 2024

Cyber Security Week in Review: July 26, 2024

In brief: A North Korean hacker indicted for ransomware attacks, French police dismantle the PlugX botnet, and more.
26 July 2024
Stargazer Goblin launch malware distribution-as-a-service via GitHub

Stargazer Goblin launch malware distribution-as-a-service via GitHub

The operation is using over 3,000 fake GitHub accounts.
25 July 2024
North Korean APT45 expanding into financially-motivated operations

North Korean APT45 expanding into financially-motivated operations

The threat actor has been observed targeting critical infrastructure more frequently than other North Korean hackers.
25 July 2024