logo

Leaks show Intellexa burning zero-days to keep Predator spyware running

ID: 8f66e4be-f0e0-5e3f-b871-e1e125224637

STIX ID: report--8f66e4be-f0e0-5e3f-b871-e1e125224637

Feed Name: Malwarebytes Blog

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-04-28

...
...

The report describes Intellexa's Predator spyware operations: a mercenary vendor that purchases and burns zero-day vulnerabilities (including multiple mobile/browser zero-days) to perform targeted, zero-click infections via one-time links and malicious advertising (‘Aladdin’). Independent reviews of leaked internal records and public analysis by Google TAG and Amnesty/CitizenLab confirm active exploitation in the wild and document techniques, scale, and mitigation advice such as using ad blockers, keeping software updated, and running real-time anti-malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.