Intellexa
   HOME

TheInfoList



OR:

Cytrox is a company established in 2017 that makes
malware Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
used for
cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
s and covert surveillance. Its Predator
spyware Spyware (a portmanteau for spying software) is any malware that aims to gather information about a person or organization and send it to another entity in a way that harms the user by violating their privacy, endangering their device's securit ...
was used to target Egyptian politician
Ayman Nour Ayman Abd El Aziz Nour (, ; born 5 December 1964) is an Egyptian politician, a former member of the Egyptian Parliament, founder and chairman of the El Ghad party. Nour was the first person to compete against President Hosni Mubarak in the 20 ...
in 2021 and to spy on 92 phones belonging to businessmen, journalists, politicians, government ministers and their associates in Greece. In 2023, the
U.S. Department of Commerce The United States Department of Commerce (DOC) is an executive department of the U.S. federal government. It is responsible for gathering data for business and governmental decision making, establishing industrial standards, catalyzing econo ...
added the Cytrox companies Cytrox AD in North Macedonia, and Cytrox Holdings Zrt in Hungary to its
Entity List The Entity List is a trade restriction list published by the United States Department of Commerce's Bureau of Industry and Security (BIS), consisting of certain foreign persons, entities, or governments. It is published as Supplement 4 of Part ...
and on March 5, 2024, the
U.S. Department of Treasury The Department of the Treasury (USDT) is the national treasury and finance department of the federal government of the United States. It is one of 15 current U.S. government departments. The department oversees the Bureau of Engraving and ...
imposed sanctions upon Cytrox AD of
North Macedonia North Macedonia, officially the Republic of North Macedonia, is a landlocked country in Southeast Europe. It shares land borders with Greece to the south, Albania to the west, Bulgaria to the east, Kosovo to the northwest and Serbia to the n ...
and the Intellexa Consortium, which is the parent firm of Cytrox AD, "for trafficking in cyber exploits used to gain access to information systems, threatening the privacy and security of individuals and organizations worldwide."


History

Cytrox was established in 2017, reportedly as a startup in
North Macedonia North Macedonia, officially the Republic of North Macedonia, is a landlocked country in Southeast Europe. It shares land borders with Greece to the south, Albania to the west, Bulgaria to the east, Kosovo to the northwest and Serbia to the n ...
and received initial funding from Israel Aerospace Industries. Its
Crunchbase Crunchbase is a company that provides information about businesses. Their content includes investment and funding information, individuals in leadership positions, and corporate news. History Crunchbase was founded in 2007 by Michael Arring ...
article describes it as providing an "operational cyber solution" to governments, including gathering information from devices and cloud services. Cytrox's CEO is Ivo Malinkovski. A review of corporate registry documents by the
University of Toronto The University of Toronto (UToronto or U of T) is a public university, public research university whose main campus is located on the grounds that surround Queen's Park (Toronto), Queen's Park in Toronto, Ontario, Canada. It was founded by ...
's
Citizen Lab The Citizen Lab is an interdisciplinary laboratory based at the Munk School of Global Affairs at the University of Toronto, Canada. It was founded by Ronald Deibert in 2001. The laboratory studies information controls that impact the openness an ...
indicated that Cytrox has a presence in Israel and Hungary. In 2019, ''
Forbes ''Forbes'' () is an American business magazine founded by B. C. Forbes in 1917. It has been owned by the Hong Kong–based investment group Integrated Whale Media Investments since 2014. Its chairman and editor-in-chief is Steve Forbes. The co ...
'' reported that Cytrox was rescued by Tal Dilian, a former commander of the
Israel Defense Forces The Israel Defense Forces (IDF; , ), alternatively referred to by the Hebrew-language acronym (), is the national military of the State of Israel. It consists of three service branches: the Israeli Ground Forces, the Israeli Air Force, and ...
(IDF), who acquired the company for under $5 million. Dilian served in the IDF for 25 years prior to his departure, following accusations that he had unlawfully enriched himself. Dilian demonstrated the company's surveillance kit to ''Forbes'' by hacking into a
Huawei Huawei Technologies Co., Ltd. ("Huawei" sometimes stylized as "HUAWEI"; ; zh, c=华为, p= ) is a Chinese multinational corporationtechnology company in Longgang, Shenzhen, Longgang, Shenzhen, Guangdong. Its main product lines include teleco ...
device and obtaining its
WhatsApp WhatsApp (officially WhatsApp Messenger) is an American social media, instant messaging (IM), and voice-over-IP (VoIP) service owned by technology conglomerate Meta. It allows users to send text, voice messages and video messages, make vo ...
messages without clicks from the victim. The
Citizen Lab The Citizen Lab is an interdisciplinary laboratory based at the Munk School of Global Affairs at the University of Toronto, Canada. It was founded by Ronald Deibert in 2001. The laboratory studies information controls that impact the openness an ...
said in 2021 that Cytrox was part of an alliance known as Intellexa, which it called "a marketing label for a range of mercenary surveillance vendors that emerged in 2019." Dilian founded the Intellexa Group in 2018; the Intellexa Alliance combines the Intellexa Group and Nexa, a group of surveillance companies that operates mainly in France. In December 2021,
Meta Platforms Meta Platforms, Inc. is an American multinational technology company headquartered in Menlo Park, California. Meta owns and operates several prominent social media platforms and communication services, including Facebook, Instagram, Threads ...
announced that Cytrox and six other surveillance-for-hire groups had been banned from using its platforms to target other users, in response to the Citizen Lab's findings about Cytrox's Predator
spyware Spyware (a portmanteau for spying software) is any malware that aims to gather information about a person or organization and send it to another entity in a way that harms the user by violating their privacy, endangering their device's securit ...
being used to target two Egyptian dissidents in June. Meta also announced it had removed over 1,500
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
and
Instagram Instagram is an American photo sharing, photo and Short-form content, short-form video sharing social networking service owned by Meta Platforms. It allows users to upload media that can be edited with Social media camera filter, filters, be ...
accounts associated with the seven companies, which it said were used to conduct social engineering, reconnaissance and sending malicious links to victims in over 100 countries. In July 2023, the
U.S. Department of Commerce The United States Department of Commerce (DOC) is an executive department of the U.S. federal government. It is responsible for gathering data for business and governmental decision making, establishing industrial standards, catalyzing econo ...
added the Cytrox companies Cytrox AD in North Macedonia, and Cytrox Holdings Zrt in Hungary to its
Entity List The Entity List is a trade restriction list published by the United States Department of Commerce's Bureau of Industry and Security (BIS), consisting of certain foreign persons, entities, or governments. It is published as Supplement 4 of Part ...
, after determining that they posed a threat to the U.S.'s national security and foreign policy interests.


Predator

Predator is
spyware Spyware (a portmanteau for spying software) is any malware that aims to gather information about a person or organization and send it to another entity in a way that harms the user by violating their privacy, endangering their device's securit ...
developed by Cytrox that targets the Android and
iOS Ios, Io or Nio (, ; ; locally Nios, Νιός) is a Greek island in the Cyclades group in the Aegean Sea. Ios is a hilly island with cliffs down to the sea on most sides. It is situated halfway between Naxos and Santorini. It is about long an ...
operating systems. In May 2022, researchers at
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
's Threat Analysis Group (TAG) reported that Predator bundled five zero-day exploits in one package and sold it to several government-backed actors, who used it in three separate campaigns. According to the researchers, Predator worked closely with a component named Alien, which "lives inside multiple privileged processes and receives commands from Predator." An analysis of the spyware conducted by Cisco Talos in May 2023 revealed that the spyware's Alien component actively implements the low-level functionality required by Predator to surveil its targets, instead of merely acting as a loader for Predator as was previously understood. In Talos's sample, Alien exploited five vulnerabilities, four of which affected
Google Chrome Google Chrome is a web browser developed by Google. It was first released in 2008 for Microsoft Windows, built with free software components from Apple WebKit and Mozilla Firefox. Versions were later released for Linux, macOS, iOS, iPadOS, an ...
and the last of which affected
Linux Linux ( ) is a family of open source Unix-like operating systems based on the Linux kernel, an kernel (operating system), operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically package manager, pac ...
and Android, to infect the targeted devices. After infecting a device, Predator has full access to its microphone, camera and user data such as contacts and text messages. Additionally, Predator has access to a device's location services and messaging apps such as WhatsApp,
Telegram Telegraphy is the long-distance transmission of messages where the sender uses symbolic codes, known to the recipient, rather than a physical exchange of an object bearing the message. Thus flag semaphore is a method of telegraphy, whereas pi ...
and
Signal A signal is both the process and the result of transmission of data over some media accomplished by embedding some variation. Signals are important in multiple subject fields including signal processing, information theory and biology. In ...
. It also allows hackers to intercept and falsify messages. An October 2023 investigation conducted by news organisations led by the
European Investigative Collaborations The European Investigative Collaborations (EIC) network is a European collaborative hybrid project of transnational investigative journalism.NRC Handelsblad, Netherlands EIC was established in the fall of 2015 with founding members, including '' ...
network, known as the Predator Files, found that Predator has been sold to at least 25 countries, including Austria, Germany, Switzerland, the Democratic Republic of the Congo, Jordan, Kenya, Oman, Pakistan, Qatar, Singapore, the United Arab Emirates and Vietnam. Reportedly it was also sold to the
Rapid Support Forces The Rapid Support Forces (RSF; ) is a paramilitary force formerly operated by the government of Sudan. The RSF grew out of, and is primarily composed of, the Janjaweed militias which previously fought on behalf of the Sudanese government. RSF ...
in the
Sudan Sudan, officially the Republic of the Sudan, is a country in Northeast Africa. It borders the Central African Republic to the southwest, Chad to the west, Libya to the northwest, Egypt to the north, the Red Sea to the east, Eritrea and Ethiopi ...
. In March 2024, a number of individuals and legal entities associated with the Intellexa Consortium were named by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) for their involvement in the development, operation and distribution of commercial spyware. According to OFAC, the Intellexa Consortium was acting as a marketing label for numerous malicious cyber companies, enabling targeted and mass surveillance through the provision of commercial spyware and surveillance tools packaged in the Predator spyware suite. In September 2024, the U.S. Treasury announced five further sanctions targets, including senior executives and associates at Intellexa. The targets of the sanctions are alleged to have been involved in the sale of "Predator" to authoritarian governments:
– Felix Bitzios, the owner of an Intellexa consortium company alleged to have sold Predator to an unnamed foreign government;
– Merom Harpaz and Panagiota Karaoli, named by the Treasury as senior Intellexa executives;
– Andrea Nicola Constantino Hermes Gambazzi, who according to the Treasury processed transactions for companies within the Intellexa consortium;
– Aliada Group, a company based in the British Virgin Islands and a member of the Intellexa group, alleged to have enabled tens of millions of dollars in transactions for the consortium.


High-profile targets


Egypt

In December 2021, the Citizen Lab reported that Predator was used to hack the devices of two individuals, Egyptian opposition politician
Ayman Nour Ayman Abd El Aziz Nour (, ; born 5 December 1964) is an Egyptian politician, a former member of the Egyptian Parliament, founder and chairman of the El Ghad party. Nour was the first person to compete against President Hosni Mubarak in the 20 ...
and an unnamed exiled journalist, in June. As a result, Apple was forced to release a
software update A patch is data that is intended to be used to modify an existing software resource such as a program or a file, often to fix bugs and security vulnerabilities. A patch may be created to improve functionality, usability, or performance. A pa ...
for iOS to close the zero-day exploits used to perform the attack. In September 2023, researchers at the Citizen Lab and the TAG reported that Egyptian opposition politician
Ahmed Tantawi Ahmed Mohamed Ramadan Tantawi known as Ahmed Tantawi also: Al-Tantawy (; born 25 July 1979) is an Egyptian politician and journalist. , he was the former head of the Dignity Party and a former member of the Egyptian House of Representatives ...
was targeted using Predator after announcing his presidential bid. The Citizen Lab said the effort likely failed due to Tantawi having his phone in "lockdown mode", which is recommended by
Apple An apple is a round, edible fruit produced by an apple tree (''Malus'' spp.). Fruit trees of the orchard or domestic apple (''Malus domestica''), the most widely grown in the genus, are agriculture, cultivated worldwide. The tree originated ...
for
iPhone The iPhone is a line of smartphones developed and marketed by Apple that run iOS, the company's own mobile operating system. The first-generation iPhone was announced by then–Apple CEO and co-founder Steve Jobs on January 9, 2007, at ...
users at high risk. It also said it had " high confidence" that the attack was conducted by the Egyptian government. Apple subsequently issued security updates to patch the vulnerabilities exploited by Predator.


Greece

During the 2022 Greek wiretapping scandal, it was revealed that Predator was being used to surveil several politicians (including opposition politician
Nikos Androulakis Nikos Androulakis (; born 7 February 1979) is a Greek politician who serves as president of the PASOK – Movement for Change since 2021. He served also as Member of the European Parliament from 2014 to 2023. He was elected as member of the Hell ...
) and journalists, with the Greek government reportedly being implicated in buying and utilising Predator. The Greek government admitted to spying on journalist Thanasis Koukakis, but denied using Predator or maintaining any association with Intellexa. In October 2022, Koukakis sued Intellexa and its executive for breach of privacy. In March 2023, ''
The New York Times ''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'' reported that Artemis Seaford, a dual U.S.-Greek national and former security policy manager at Meta, had her phone infected with Predator while in Greece. In July 2023, the investigation team of the Hellenic Data Protection Authority announced that it had found 220 text messages containing a link polluted with Predator, that had been sent to 92 telephone numbers in order to turn them into spying devices. The news website ''Inside Story'' published the content of many of them, which had been sent mostly in 2021. Their recipients included many politicians, ministers and their associates, including associates of the Prime Minister (e.g.
Dimitris Avramopoulos Dimitris Avramopoulos (; born 6 June 1953) is a Greek politician of the conservative New Democracy party, and former career diplomat. He has served in various high-level cabinet posts, including Minister for Foreign Affairs and Minister for Nat ...
, Giorgos Patoulis, Giorgos Gerapetritis,
Kostis Hatzidakis Konstantinos (Kostis) Hatzidakis (; born 20 April 1965 in Rethymno) is a Greek politician who currently serves as Deputy Prime Minister and Minister of State in the Second Cabinet of Kyriakos Mitsotakis. He also serves as Vice President of New ...
, Thanos Plevris, Michalis Chrysochoidis,
Adonis Georgiadis Spyridon-Adonis Georgiadis (; born 6 November 1972), commonly known as Adonis Georgiadis, is a Greek politician, author, publisher and former telemarketer. Often described as being on the far right of the political spectrum, he currently serves ...
,
Nikos Dendias Nikolaos "Nikos" Dendias (; born 7 October 1959) is a Greek lawyer and politician of the conservative New Democracy (Greece), New Democracy party who has been serving as Minister for National Defence (Greece), Minister for National Defence in th ...
, Christos Spirtzis), businessmen (e.g. ), journalists, EYP cadres, at least one bishop and the editor of the newspaper ''
Kathimerini ( Greek: Η Καθημερινή, ; ) is a daily, political and financial morning newspaper published in Piraeus, Athens. Its first edition was printed on 15 September 1919. is considered a newspaper of record and the leading right-wing newspape ...
'', Alexis Papachelas. These names had been included in a list of persons alleged to have been spied upon by EYP and Predator, which had been published in November 2022 by the ''Documento'' newspaper.


United States

In October 2023, various American lawmakers were targeted by
Vietnam Vietnam, officially the Socialist Republic of Vietnam (SRV), is a country at the eastern edge of mainland Southeast Asia, with an area of about and a population of over 100 million, making it the world's List of countries and depende ...
using Predator, including Representative Michael McCaul (R-TX) and Senators
John Hoeven John Henry Hoeven III ( ; born March 13, 1957) is an American banker and politician serving as the senior U.S. senator from North Dakota, a seat he has held since 2011. A member of the Republican Party, Hoeven served as the 31st governor of N ...
(R-ND),
Chris Murphy Christopher Scott Murphy (born August 3, 1973) is an American lawyer, author, and politician serving as the junior United States senator from the state of Connecticut since 2013. A member of the Democratic Party, he previously served in the U ...
(D-CT) and
Gary Peters Gary Charles Peters (born December 1, 1958) is an American lawyer, politician, and former military officer serving as the Seniority in the United States Senate, senior United States Senate, United States senator from Michigan, a seat he has hel ...
(D-MI). Experts on Asia at various think tanks and several journalists, including
CNN Cable News Network (CNN) is a multinational news organization operating, most notably, a website and a TV channel headquartered in Atlanta. Founded in 1980 by American media proprietor Ted Turner and Reese Schonfeld as a 24-hour cable ne ...
's lead national security reporter
Jim Sciutto James Ernest Sciutto (born March 10, 1970) is an American news anchor and former government official who has been the chief national security correspondent for CNN since September 2013. In this role he provides analysis on a variety of topics con ...
, were also targeted.


Sanctions

On March 5, 2024, the United States Department of Treasury's
Office of Foreign Assets Control The Office of Foreign Assets Control (OFAC) is a financial intelligence and enforcement agency of the United States Department of the Treasury, United States Treasury Department. It administers and enforces economic and trade economic sanctions, ...
(OFAC) imposed sanctions against five entities and two individuals it described as key enablers of the Intellexa Consortium and Predator spyware by placing them on OFAC's Specially Designated Nationals (SDN) List: * the Intellexa Consortium; * its founder Tal Jonathan Dilian, who the Treasury described as the architect behind its spyware tools; * the Intellexa Consortium's corporate off shoot specialist Sara Aleksandra Fayssal Hamou; * the Greece-based firm Intellexa S.A.; * the Hungary-based Cytrox Holdings Zartkoruen Mukodo Reszvenytarsasag (Cytrox Holdings ZRT), which the Treasury described as having originally developed Predator before the consortium moved its software production to Cytrox AD of North Macedonia; * the Ireland-based Intellexa Limited; * the Ireland-based Thalestris Limited; * and the North Macedonia-based Cytrox AD.


See also

*
Pegasus Pegasus (; ) is a winged horse in Greek mythology, usually depicted as a white stallion. He was sired by Poseidon, in his role as horse-god, and foaled by the Gorgon Medusa. Pegasus was the brother of Chrysaor, both born from Medusa's blood w ...
*
NSO Group NSO Group Technologies (NSO standing for Niv, Shalev and Omri, the names of the company's founders) is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click surveillance ...


Notes


References

{{Hacking in the 2020s Spyware companies Hacking in the 2020s