Independently Confirming Amnesty Security Lab’s finding of Predator targeting of U.S. & other elected officials on Twitter/X
ID: 8cc95467-f29b-5782-a561-fa9e731f4ac0
STIX ID: report--8cc95467-f29b-5782-a561-fa9e731f4ac0
Feed Name: The Citizen Lab
This Citizen Lab note documents the REPLYSPY campaign that delivered Cytrox/Predator spyware via reply links on Twitter/X targeting officials, journalists, and civil society; it attributes domains (e.g., southchinapost.net, caavn.org) to Cytrox/Predator, describes prior zero-day exploit use to gain initial access, and reverse-engineers an eight-step installation validation routine designed to evade researchers (locale, developer mode, jailbreak, proxy/MiTM, unsafe processes, etc.).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
