logo

Independently Confirming Amnesty Security Lab’s finding of Predator targeting of U.S. & other elected officials on Twitter/X

ID: 8cc95467-f29b-5782-a561-fa9e731f4ac0

STIX ID: report--8cc95467-f29b-5782-a561-fa9e731f4ac0

Feed Name: The Citizen Lab

Threat Score
85/100

Date Published: 2023-10-09

Date Updated: 2026-04-19

Author: Bill Marczak

...
...

This Citizen Lab note documents the REPLYSPY campaign that delivered Cytrox/Predator spyware via reply links on Twitter/X targeting officials, journalists, and civil society; it attributes domains (e.g., southchinapost.net, caavn.org) to Cytrox/Predator, describes prior zero-day exploit use to gain initial access, and reverse-engineers an eight-step installation validation routine designed to evade researchers (locale, developer mode, jailbreak, proxy/MiTM, unsafe processes, etc.).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.