logo

Predator spyware uses new infection vector for zero-click attacks

ID: 38ae4ae6-3d3f-5cb6-a4bf-22e912d02232

STIX ID: report--38ae4ae6-3d3f-5cb6-a4bf-22e912d02232

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report reveals that Intellexa's Predator spyware uses a novel zero-click ad-based delivery mechanism called 'Aladdin' that can infect targeted mobile devices simply by serving weaponized ads to identified public IPs via a global ad-tech chain; the findings are drawn from leaked Intellexa internal documents and corroborated by Amnesty International, Google, and Recorded Future, and also note other vectors (Triton, Thor, Oberon) and zero-day baseband exploits affecting Samsung Exynos—mitigations suggested include blocking ads and enabling platform hardening features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.