The Predator spyware ecosystem is not dead
ID: ce5510a1-1b8c-574d-b486-98dab4ddb5df
STIX ID: report--ce5510a1-1b8c-574d-b486-98dab4ddb5df
Feed Name: Sekoia.io Blog
Date Published: 2024-02-28
Date Updated: 2026-04-29
Author: Felix Aimé, Maxime A. and TDR (Threat Detection & Research)
Sekoia.io reports that the Predator spyware ecosystem (Lycantrox) remains active despite prior public disclosures: analysts found new malicious domains and command-and-control infrastructure created after the Predator Files publications, indicating ongoing use across multiple countries (including Angola, Madagascar, Indonesia, Kazakhstan, Egypt, Botswana, Mongolia, and Sudan). The post documents operational security changes aimed at plausible deniability, associates specific typosquatted and mimicked domains with likely customers, and encourages NGOs to share indicators for defensive action.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
